How Do Hackers Make ATMs Give Them Money? A Simple Guide to “Jackpotting”

Surprising fact: one concerted run once emptied machines for roughly $1.5 million in just a few hours. That scale shocked security teams and put independent owners on notice.

Table of contents

An expert take by Ethan Cross, HakTechs.com Lead Analyst

This guide shows what that threat looks like without sharing abuse steps. We define the core idea, outline who is at risk, and point to the controls defenders can use.

What to expect: criminals often gain physical access to a terminal’s top box, then use malware or a rogue device to force it to dispense cash until empty. Targets are usually retail locations with quieter foot traffic and simple locks.

These attacks differ from bank-level cash-out schemes because they focus on the machine and its technology, not the bank’s core systems. For a deep technical read and past incidents, see this coverage on the topic by Wired: how researchers documented real-world attacks.

Key Takeaways

  • Scale matters: single incidents can net millions in hours, so prevention is critical.
  • Physical access is central: top-box entry and impersonation are common tactics.
  • Protect machines: hardened locks, monitoring, and software controls reduce threats.
  • Owners learn late: many only notice when a terminal reports “out of cash.”
  • U.S. context: retail and independent operators in the United States face the greatest immediate risk.

ATM jackpotting explained: what it is, why it matters, and the United States context

Attackers often open a terminal’s top box and either load malware or attach a black box to run the dispenser. This allows criminals to make a machine release cash directly, and the losses usually hit owners, not customers.

Attackers gain physical access to the service compartment of atms and install software-based malware or a rogue device. That setup sends commands to the dispenser so it releases bills on demand.

How this differs from cash-out

Cash-out attacks tamper with bank authorization data and limits at the issuer. By contrast, jackpotting manipulates the terminal itself. These are different types of crime that require different defenses.

  • EAST tracked 202 successful attacks in 2020 with about €1.24M lost (≈US$1.4M).
  • Typical amounts inside a machine range from a few thousand up to $50,000, depending on location.
  • Standalone retail units and older hardware are common targets in the United States.

A dimly lit ATM booth, the screen displaying a cascading sequence of dollar bills, as if the machine has been hacked to dispense cash without authorization. In the foreground, a hooded figure leans intently over the ATM, fingers deftly manipulating the keypad. The scene is bathed in an eerie, bluish glow, creating an atmosphere of clandestine activity. The background is obscured, suggesting a secluded location, away from prying eyes. The image conveys the technical sophistication and illicit nature of ATM jackpotting, a growing threat that challenges the security of financial infrastructure in the United States.

Metric Typical Range Who Pays Notes
Cash on site $2,000 – $50,000 ATM owners Higher in busy retail or casino locations
Incidents (EAST 2020) 202 attacks Operators Underreporting in the U.S. clouds totals
Primary defenses Physical locks, monitoring Operators Layered cybersecurity and alerts reduce threats

Treat each terminal like a networked computer with cash attached. Basic cybersecurity, timely patching, strong locks, and active monitoring cut the risk of this threat.

How jackpotting attacks actually work: from physical access to black box and malware techniques

A clear map of how intruders move from entry to payout makes detection and response far more effective.

Physical entry to the service box is the usual pivot. Attackers target retail terminals with weak locks, common keys, or by posing as a legitimate service tech. Once inside they can access cabling and the dispenser interface.

A sleek, metallic black box sits atop a steel table, casting a subtle shadow on the surface. The device's casing is a smooth, glossy finish, hinting at the complex internal components and advanced technology within. Dramatic lighting illuminates the box from an angle, creating dramatic shadows and highlights that accentuate its angular, minimalist design. The surrounding environment is a dimly lit, industrial workspace, with concrete walls and a sense of technical precision. The overall mood is one of mystery and technological intrigue, suggesting the box's potential for both malicious and beneficial applications.

How malware on the hard drive is used

Malware families like Ploutus and Anunak/Carbanak infect the terminal hard drive or system and issue commands to the cash dispenser. Some variants accept keyboard or remote triggers to make the terminal dispense on cue. Monitor for unexpected software changes and unknown input devices.

What black box device attacks look like

In black box scenarios a rogue device connects directly to the dispenser or inline on the network, bypassing host software. These controllers often leave few logs, so hardware checks and cable audits are essential.

Money mules, triggers, and defender telltales

  • Money mules collect cash after keypad or sequence triggers.
  • Typical signs: sudden “out-of-cash” alerts, unusual terminal states, or re-routed dispenser cabling inside the top box.
  • Defenses: verify technician IDs, log all top-box access, and pair software monitoring with physical sensors.

black box research offers deeper context for defenders seeking technical background.

Real-world impact and risk: who’s targeted, where attacks happen, and what’s at stake

Real incidents show how vulnerable retail terminals and standalone machines can be to coordinated cash thefts. Data and case studies prove the threat is practical, not theoretical.

A dimly lit ATM vestibule, the shadows cast by neon signage lending an ominous atmosphere. In the foreground, a hacker's hands deftly manipulate the ATM's internals, extracting cash as if coaxing a jackpot. The machine's display flashes error messages, while the hacker's face remains obscured, shrouded in the anonymity of the crime. In the background, a sense of unease lingers, hinting at the far-reaching consequences of this "jackpotting" attack on the banking infrastructure and unsuspecting victims.

EAST tracked 202 successful attacks in 2020 with about €1.24M lost (≈US$1.4M). That represented a 44% jump in incidents and a 14% rise in losses versus 2019. A single coordinated attack once drained roughly $1.5M in hours across multiple locations.

Targets concentrate where physical vulnerabilities and thin on-site monitoring meet: standalone retail units and older machines. Cash amounts inside units range from a few thousand up to $50,000, which shapes criminal incentives and operator risk.

Historic waves show scale: the Ploutus campaign in Mexico hit about 450 units (~$40M), Latin America saw waves in 2017, and Carbanak-related incidents appeared in Ukraine (2015) and Taiwan (2016). In the U.S., a 2018 Secret Service alert led vendors like NCR and Diebold Nixdorf to publish guidance.

Metric Detail Impact
Incidents (EAST 2020) 202 attacks; €1.24M lost Rising frequency and loss totals
Typical cash on site $2,000 – $50,000 Drives attacker targeting choices
Notable campaigns Ploutus (Mexico), Carbanak cases Large-scale cross-region thefts

Practical takeaway: treat the terminal as both a piece of hardware and a networked system. Combine physical hardening, active monitoring, and vendor advisories — see the operator guidance in this security brief — to reduce your exposure to these attacks.

operator security guidance

Conclusion

A clear, final step is to turn knowledge of these schemes into simple, repeatable defenses.

Recap: a jackpotting attack blends physical access, malware, or a rogue black box to force an atm to dispense its cash. Protect both the box and the host system.

Defend in depth: strengthen top-box locks and access controls, keep software and OS patches current, and disable unsafe boot options. Hardening reduces easy wins for criminals.

Increase visibility: add cameras, motion sensors, tamper alarms, and instrument the terminal and hardware paths so unusual device connections or dispenser activity stand out.

Operational steps: verify every service visit, restrict keys, audit entries, test alarms, and confirm insurance and response plans. Small changes stop most successful jackpotting attacks.

Act now: schedule a fleet risk review this quarter, and review vendor guidance — for a practical operator brief see operator guidance on atm jackpotting. One corrected control often prevents a costly incident.

FAQ

What is cash-dispensing malware and how does it differ from card-based cash-out schemes?

Cash-dispensing malware is software installed on a machine’s internal computer or hard drive that issues direct commands to the cash dispenser, forcing it to release bills. It differs from card-based cash-out schemes that rely on cloned or stolen card data and account manipulation; malware attacks control the terminal itself rather than abusing customer accounts.

How do black-box attacks work and why are they effective?

Black-box attacks use a rogue hardware device that connects to the cash dispenser or the terminal’s service port. The device emulates legitimate command protocols so the dispenser accepts instructions to release cash. They’re effective because they bypass the machine’s operating system and software protections, communicating directly with the dispenser hardware.

Do attackers need physical access to a machine to perform these attacks?

Physical access is common but not always mandatory. Many successful incidents began with criminals opening the top service compartment, often using stolen or generic keys or posing as technicians. Once inside, they can attach a black box or access the hard drive to install malware. Remote attacks are rarer but possible when networks are exposed.

Which pieces of malware have been used to force cash dispensers to pay out?

Known families include Ploutus and variants tied to the Anunak/Carbanak campaigns. These toolsets provide attackers with teller-like control over dispensers, voucher generation, and remote or local command execution. Vendor advisories and CVE entries document several related vulnerabilities leveraged in past incidents.

How much money do these attacks typically yield and who are the targets?

Payouts vary widely — from a few thousand dollars to tens or hundreds of thousands in coordinated campaigns. Targets tend to be unattended terminals, retail-located machines, and older models with weak physical and software controls. Regions such as Latin America, Eastern Europe, and parts of Asia have reported waves of incidents; U.S. advisories peaked around 2018 but risks persist.

What role do money mules and accomplices play after cash is dispensed?

Money mules collect and launder the physical cash quickly, reducing detection risk for the operators. Other accomplices may provide logistics, lookouts, or swap hardware. This division of labor helps criminals convert payouts into usable funds while distancing core operators from direct handling of cash.

Can monitoring systems detect a forced payout or black-box connection in real time?

Detection depends on monitoring maturity. Effective systems log unexpected dispenser commands, anomalous service-port activity, and unusual cash-flow patterns. Many deployed terminals lack robust telemetry or real-time alerts, so attacks can go unnoticed until cash is collected or inventory reconciliation highlights discrepancies.

What preventive measures can owners and operators take to reduce risk?

Harden service access with modern locks, tamper-evident seals, and verified technician credentials. Segment and secure networks, disable unused service ports, apply vendor security patches, and use endpoint protection on terminal PCs. Add remote monitoring for dispenser commands and reconcile cash inventories frequently. Combine physical and cyber controls for best protection.

How important are vendor advisories and CVE patches in reducing exposure?

Very important. Manufacturers and software vendors publish advisories and Common Vulnerabilities and Exposures (CVE) entries that describe exploitable flaws. Applying patches promptly and following vendor hardening guides closes many remote and local attack paths. Regularly reviewing advisories is a core element of risk management.

Are newer terminal models immune to these techniques?

No model is completely immune, but newer machines with secure boot, encrypted communications, hardened OS images, and locked-down service ports raise the bar. Threat actors often target older hardware and poorly maintained terminals first. Continuous maintenance and layered defenses remain essential.

What are common indicators of compromise I should watch for?

Look for unexpected dispenser commands, frequent service-door openings outside business windows, unlogged maintenance entries, sudden mass voucher printing, and inventory mismatches. Network anomalies such as unknown devices on the terminal subnet or unusual outbound connections also warrant investigation.

How do attackers evade monitoring and law enforcement after a payout?

Tactics include rapid collection by money mules, staged lookouts to delay detection, disabling or tampering with cameras, and using prepaid or anonymous transport for cash. Criminal groups often split proceeds and move funds through multiple channels to complicate tracing.

Should banks and retailers replace older machines or retrofit them with security upgrades?

Both strategies are valid. Replacing legacy units with modern, hardened terminals provides long-term security gains. When replacement isn’t feasible, retrofits—such as stronger locks, sealed service ports, tamper sensors, and network segmentation—significantly reduce attack surface at lower immediate cost.

Where can I find verified data and incident reports to validate these risks?

Consult vendor security bulletins, CERT advisories, the U.S. Cybersecurity and Infrastructure Security Agency (CISA), and CVE/NVD databases for technical details. Peer-reviewed reporting from security firms and law enforcement advisories also provide validated incident timelines and recommended mitigations.

Ethan Cross

Ethan Cross is a cybersecurity analyst and tech journalist with over a decade of experience in ethical hacking, malware analysis, and digital forensics. At HakTechs.com, he delivers in-depth reports, security tips, and expert analysis to help readers stay ahead of emerging cyber threats.