Full Report
Five Venezuelan nationals pleaded guilty to attempting to empty automated teller machines (ATMs) using malware in a series of ATM jackpotting attacks. [...]
Analysis Summary
# Incident Report: Multi-State ATM Jackpotting Attempt
## Executive Summary
Five Venezuelan nationals pleaded guilty to conspiracy to commit bank larceny following a series of "jackpotting" attacks in Kansas. The group attempted to use specialized malware to force ATMs to dispense cash but were unsuccessful due to physical security triggers and surveillance. All five suspects were apprehended, with one already sentenced and four awaiting sentencing.
## Incident Details
- **Discovery Date:** December 2025
- **Incident Date:** December 2025
- **Affected Organization:** Unspecified banks in Wamego and Manhattan, Kansas
- **Sector:** Financial Services / Banking
- **Geography:** Kansas, USA
## Timeline of Events
### Initial Access
- **Date/Time:** December 2025
- **Vector:** Physical Breach
- **Details:** The attackers gained physical access to the internal components of the ATM units to interface with the internal computer.
### Lateral Movement
- **Details:** Movement was localized to the ATM hardware; attackers attempted to interface between the internal computer and the cash dispenser unit via peripheral ports.
### Data Exfiltration/Impact
- **Impact:** Financial loss was attempted but not realized in these specific instances. The physical integrity of the ATMs was compromised during the malware installation attempt.
### Detection & Response
- **Detection:** An alarm was triggered during the attempted malware installation at the Wamego site.
- **Response Actions:** Law enforcement responded to the alarm. Surveillance footage from both sites was reviewed to identify the suspects, leading to their arrest a few days later.
## Attack Methodology
- **Initial Access:** Physical tampering with ATM housing to access internal ports.
- **Persistence:** Not applicable; the attack is designed for immediate "jackpotting" (cash dispensing).
- **Privilege Escalation:** Use of malware to bypass standard ATM software controls.
- **Defense Evasion:** Use of specialized malware (e.g., Ploutus or similar variants) designed to leave minimal traces and operate independently of the bank's network.
- **Credential Access:** Not required; malware directly commands the dispenser.
- **Discovery:** Physical reconnaissance of ATM models and locations.
- **Lateral Movement:** Connection of external peripherals (USB keyboards/PIN pads) to the internal ATM computer.
- **Collection:** Attempted command of the money storage cassette.
- **Exfiltration:** Attempted physical theft of dispensed cash.
- **Impact:** Physical damage to ATM units and attempted larceny.
## Impact Assessment
- **Financial:** Minimal (Physical repair costs only); the $20 million cited in the context refers to the broader national surge in these attacks.
- **Data Breach:** None reported; objective was cash, not cardholder data.
- **Operational:** Temporary out-of-service status for targeted ATMs.
- **Reputational:** Minimal, though the incident contributes to broader concerns regarding ATM security.
## Indicators of Compromise
- **Network indicators:** N/A (Attacks are typically offline/local).
- **File indicators:** Presence of known ATM malware families: `Ploutus`, `ATMii`, `ATMitch`, `GreenDispenser`, `Alice`, `RIPPER`, `Skimer`, or `SUCEFUL`.
- **Behavioral indicators:** Physical tampering with ATM fascia, unauthorized opening of the "top hat" (electronics) section, or attachment of unauthorized USB devices.
## Response Actions
- **Containment:** Alarms successfully deterred the attackers at one location.
- **Eradication:** Law enforcement (FBI/Local Police) identified and arrested the five-man cell.
- **Recovery:** Inspection and cleaning/re-imaging of affected ATM internal computers.
## Lessons Learned
- **Physical Security:** The triggering of the alarm in Wamego was the primary factor in preventing the theft and initiating the response.
- **Surveillance:** High-quality surveillance footage was critical in the identification and subsequent guilty pleas of the suspects.
- **Regional Coordination:** The group moved between cities (Wamego to Manhattan), highlighting the need for rapid information sharing between local jurisdictions.
## Recommendations
- **Physical Hardening:** Strengthen locks and enclosures on the ATM "top hat" to prevent unauthorized access to USB ports and the internal computer.
- **Encryption:** Implement end-to-end encryption between the ATM computer and the cash dispenser to prevent unauthorized "dispense" commands.
- **Firmware Security:** Enable BIOS passwords, disable booting from external media, and utilize Trusted Platform Modules (TPM) to ensure software integrity.
- **Monitoring:** Deploy vibration or tilt sensors and ensure silent alarms are integrated with local law enforcement dispatch.