Surprising fact: one concerted run once emptied machines for roughly $1.5 million in just a few hours. That scale shocked security teams and put independent owners on notice.
This guide shows what that threat looks like without sharing abuse steps. We define the core idea, outline who is at risk, and point to the controls defenders can use.
What to expect: criminals often gain physical access to a terminal’s top box, then use malware or a rogue device to force it to dispense cash until empty. Targets are usually retail locations with quieter foot traffic and simple locks.
These attacks differ from bank-level cash-out schemes because they focus on the machine and its technology, not the bank’s core systems. For a deep technical read and past incidents, see this coverage on the topic by Wired: how researchers documented real-world attacks.
Key Takeaways
- Scale matters: single incidents can net millions in hours, so prevention is critical.
- Physical access is central: top-box entry and impersonation are common tactics.
- Protect machines: hardened locks, monitoring, and software controls reduce threats.
- Owners learn late: many only notice when a terminal reports “out of cash.”
- U.S. context: retail and independent operators in the United States face the greatest immediate risk.
ATM jackpotting explained: what it is, why it matters, and the United States context
Attackers often open a terminal’s top box and either load malware or attach a black box to run the dispenser. This allows criminals to make a machine release cash directly, and the losses usually hit owners, not customers.
Attackers gain physical access to the service compartment of atms and install software-based malware or a rogue device. That setup sends commands to the dispenser so it releases bills on demand.
How this differs from cash-out
Cash-out attacks tamper with bank authorization data and limits at the issuer. By contrast, jackpotting manipulates the terminal itself. These are different types of crime that require different defenses.
Quick facts and trends
- EAST tracked 202 successful attacks in 2020 with about €1.24M lost (≈US$1.4M).
- Typical amounts inside a machine range from a few thousand up to $50,000, depending on location.
- Standalone retail units and older hardware are common targets in the United States.

| Metric | Typical Range | Who Pays | Notes |
|---|---|---|---|
| Cash on site | $2,000 – $50,000 | ATM owners | Higher in busy retail or casino locations |
| Incidents (EAST 2020) | 202 attacks | Operators | Underreporting in the U.S. clouds totals |
| Primary defenses | Physical locks, monitoring | Operators | Layered cybersecurity and alerts reduce threats |
Treat each terminal like a networked computer with cash attached. Basic cybersecurity, timely patching, strong locks, and active monitoring cut the risk of this threat.
How jackpotting attacks actually work: from physical access to black box and malware techniques
A clear map of how intruders move from entry to payout makes detection and response far more effective.
Physical entry to the service box is the usual pivot. Attackers target retail terminals with weak locks, common keys, or by posing as a legitimate service tech. Once inside they can access cabling and the dispenser interface.

How malware on the hard drive is used
Malware families like Ploutus and Anunak/Carbanak infect the terminal hard drive or system and issue commands to the cash dispenser. Some variants accept keyboard or remote triggers to make the terminal dispense on cue. Monitor for unexpected software changes and unknown input devices.
What black box device attacks look like
In black box scenarios a rogue device connects directly to the dispenser or inline on the network, bypassing host software. These controllers often leave few logs, so hardware checks and cable audits are essential.
Money mules, triggers, and defender telltales
- Money mules collect cash after keypad or sequence triggers.
- Typical signs: sudden “out-of-cash” alerts, unusual terminal states, or re-routed dispenser cabling inside the top box.
- Defenses: verify technician IDs, log all top-box access, and pair software monitoring with physical sensors.
black box research offers deeper context for defenders seeking technical background.
Real-world impact and risk: who’s targeted, where attacks happen, and what’s at stake
Real incidents show how vulnerable retail terminals and standalone machines can be to coordinated cash thefts. Data and case studies prove the threat is practical, not theoretical.

EAST tracked 202 successful attacks in 2020 with about €1.24M lost (≈US$1.4M). That represented a 44% jump in incidents and a 14% rise in losses versus 2019. A single coordinated attack once drained roughly $1.5M in hours across multiple locations.
Targets concentrate where physical vulnerabilities and thin on-site monitoring meet: standalone retail units and older machines. Cash amounts inside units range from a few thousand up to $50,000, which shapes criminal incentives and operator risk.
Historic waves show scale: the Ploutus campaign in Mexico hit about 450 units (~$40M), Latin America saw waves in 2017, and Carbanak-related incidents appeared in Ukraine (2015) and Taiwan (2016). In the U.S., a 2018 Secret Service alert led vendors like NCR and Diebold Nixdorf to publish guidance.
| Metric | Detail | Impact |
|---|---|---|
| Incidents (EAST 2020) | 202 attacks; €1.24M lost | Rising frequency and loss totals |
| Typical cash on site | $2,000 – $50,000 | Drives attacker targeting choices |
| Notable campaigns | Ploutus (Mexico), Carbanak cases | Large-scale cross-region thefts |
Practical takeaway: treat the terminal as both a piece of hardware and a networked system. Combine physical hardening, active monitoring, and vendor advisories — see the operator guidance in this security brief — to reduce your exposure to these attacks.
Conclusion
A clear, final step is to turn knowledge of these schemes into simple, repeatable defenses.
Recap: a jackpotting attack blends physical access, malware, or a rogue black box to force an atm to dispense its cash. Protect both the box and the host system.
Defend in depth: strengthen top-box locks and access controls, keep software and OS patches current, and disable unsafe boot options. Hardening reduces easy wins for criminals.
Increase visibility: add cameras, motion sensors, tamper alarms, and instrument the terminal and hardware paths so unusual device connections or dispenser activity stand out.
Operational steps: verify every service visit, restrict keys, audit entries, test alarms, and confirm insurance and response plans. Small changes stop most successful jackpotting attacks.
Act now: schedule a fleet risk review this quarter, and review vendor guidance — for a practical operator brief see operator guidance on atm jackpotting. One corrected control often prevents a costly incident.