The FBI says ATM jackpotting incidents increased sharply in 2025. In a February 19, 2026 FLASH alert, the agency reported approximately 1,900 incidents in the United States since 2020, including more than 700 incidents and losses exceeding $20 million in 2025 alone. These attacks primarily target the ATM itself and the cash stored inside it—not customers’ bank accounts.
Criminals may gain physical or software access to an ATM, install malware such as the Ploutus family, and issue unauthorized commands that make the machine dispense cash without a normal card transaction or bank authorization.
As an Amazon Associate I earn from qualifying purchases.
What the FBI reported
The FBI’s February 19, 2026 alert describes an increase in malware-enabled ATM jackpotting across the United States.
- Approximately 1,900 reported incidents since 2020
- More than 700 reported incidents in 2025
- More than $20 million in reported 2025 losses
- Malware from the Ploutus family was identified in the alert
The figures show that 2025 accounted for a substantial share of the FBI’s reported incidents since 2020. However, the alert does not provide enough detail to calculate a reliable percentage increase, the probability that a particular ATM will be attacked, or the number of unique machines involved. The totals should be understood as reported incident and loss figures—not a complete national census.
#1 Best Overall
- 1080P HD USB Camera with CMOS IMX323 Sensor: This USB industrial camera features a 1920×1080 resolution CMOS IMX323 sensor, delivering sharp images and accurate color reproduction for industrial inspection and PCB repair. With 30fps high frame rate, it supports MJPEG/YUY2/H.264 compression formats. The H.264 compression of this USB camera reduces bandwidth usage by 50% for smooth live streaming (Windows software for H.264 capture is provided).
- Manual Zoom Lenses for USB Industrial Camera: Equipped with a 2.8-12mm CS mount varifocal lens, this industrial USB camera offers flexible manual zoom control—easily adjust focal length to switch between wide-angle views (for large-area inspections) and close-up precision (for tiny PCB components).
- 0.01Lux Low Light USB Camera Performance: As a professional industrial inspection camera, it adopts a 2MP 1/2.9 IMX323 Color CMOS sensor, enabling it to capture clear images even in 0.01Lux low light conditions. This low light USB camera is ideal for various dim environments in industrial applications.
- Plug-and-Play USB Camera with Wide Compatibility: This mini USB camera is plug-and-play, requiring no driver installation. With a 4pin to USB connector, it easily connects to PCs and is compatible with Linux, Windows, Android, and Mac OS. Suitable for various devices like kiosks, vending machines, and computers for video conference.
- Versatile Applications of 1080P USB Camera: The 1080P USB camera is widely used in industrial settings such as video surveillance system, industrial inspection, PCB repair, ATM monitoring, and robotic vision. It also works well for live streaming, video conference, dashcam, and applications needing gesture tracking, iris recognition, depth and motion detection, thanks to its 0.01Lux low-light sensitivity and low distortion lens.
What is ATM jackpotting?
ATM jackpotting is the unauthorized manipulation of an ATM so that it dispenses the cash held inside it. The criminal does not necessarily need a customer’s card, PIN, or bank account information. Instead, the target is the machine’s operating system, software, dispenser controls, hardware, or communications path.
In a normal withdrawal, the ATM and the bank or processor coordinate to approve a customer transaction before cash is dispensed. In a jackpotting attack, criminals may manipulate the ATM locally and cause it to release cash outside that ordinary authorization flow.
How Ploutus fits into the attack
The FBI says Ploutus can abuse XFS, or eXtensions for Financial Services. XFS is a software layer that allows ATM applications to communicate with devices such as cash dispensers. If attackers gain sufficient access to the ATM’s software environment, they may use that layer to issue unauthorized dispenser commands.
Recommended Free Tools
The attack is therefore both physical and digital. It is not simply a remote banking-account hack, and describing it only as a “cyberattack” can obscure the importance of cabinet security and technician access.
How criminals get access
According to the FBI, reported methods include opening the ATM’s exterior or top hat, removing or replacing its hard drive, connecting storage to another computer to introduce malware, and using an external device to execute malicious software.
Rank #2
- H.265/H.264 5MP POE IP Security mini ip Camera, POE(Power Over Ethernet),Resolution: 5MP@25fps;4MP@25Fps,3MP@30Fps
- POE Function,Power Over Ethernet,One Cable Transfer Data&Power
- Plug&Play,O-N-V-I-F,Motion Detect&Email Alert,FTP
- Remotely View By Free Mobile Phone App: XMEYE, Support smart mobile phone app,Tablet PC
These methods are described here to clarify the defensive problem—not as instructions for carrying out an attack. The central lesson for operators is that an ATM with weak physical access controls can be vulnerable even when its bank network and customer-authentication systems are functioning normally.
Jackpotting is not the same as skimming
ATM-related crimes are often grouped together, but they have different targets and different responses.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstall| Crime | Primary target | Typical result |
|---|---|---|
| Jackpotting | ATM software, middleware, dispenser, or local hardware | The machine dispenses the institution’s cash |
| Skimming | Card data and PIN entry | Criminals capture credentials for later fraudulent use |
| Cash trapping | Cash outlet or card slot | A customer’s cash or card is physically intercepted |
| Host spoofing | ATM-to-processor communications | A fraudulent approval may cause a dispense |
| Transaction-reversal fraud | Cash-transport mechanism | Notes are extracted through mechanical manipulation |
| Physical robbery | ATM safe or cabinet | The machine is damaged or removed to reach cash |
The U.S. Secret Service’s skimming guidance concerns devices that capture card information or PINs. That is related ATM fraud, but it is not the same mechanism as malware-enabled jackpotting. Likewise, NCR Atleos describes transaction-reversal fraud as a separate attack involving manipulation of the cash path.
Why traditional transaction controls may not be enough
Bank authorization remains an important security layer, but jackpotting can attack the ATM below or outside the ordinary transaction flow. A local compromise may cause the dispenser to release cash without a legitimate customer withdrawal appearing in the usual way.
Effective protection must therefore cover multiple layers:
Rank #3
- Samsung by Hanwha XNB-H6241A
- Physical access to the cabinet, computer components, and storage
- Operating-system and application integrity
- XFS and other ATM middleware
- USB and removable-media controls
- Network segmentation and authenticated communications
- Cash-module authorization
- Tamper alarms and real-time monitoring
- Cash reconciliation and incident response
Network encryption alone does not necessarily protect against a local attack on the ATM and its dispenser. Conversely, a physical alarm has limited value if nobody responds quickly.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Who bears the loss?
The immediate cash loss generally falls on the bank, credit union, independent ATM deployer, or other ATM owner whose cash was dispensed. The precise allocation of liability depends on ownership, processor and service contracts, insurance, jurisdiction, and the security controls in place.
Additional costs may include emergency removal from service, investigation and forensic work, cash replenishment, reconciliation, downtime, customer confusion, and reputational damage. The FBI’s reported figure of more than $20 million does not necessarily include all of those broader economic effects.
What ordinary ATM users should know
For consumers, the main risk described in the FBI warning is usually not direct drainage of a personal checking account. Jackpotting primarily targets the ATM’s stored cash. A customer may instead encounter a machine that has been taken out of service or appears damaged.
Consumers remain exposed to separate risks such as skimming, card theft, phishing, and ordinary account fraud. Use these precautions:
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Rank #4
- Do not use an ATM with an open cabinet, visible damage, unusual messages, or suspicious people working around it.
- Do not open the machine, inspect internal components, remove a device, or confront anyone.
- Report a suspicious machine to the bank, ATM operator, property owner, or local law enforcement.
- Use another ATM if the machine behaves unexpectedly or fails to complete a transaction normally.
- Check your account and contact your card issuer promptly if a withdrawal or balance is incorrect.
- For suspected skimming, stop using the terminal and follow the card issuer’s instructions and the Secret Service guidance.
What banks, credit unions, and ATM operators should do
1. Harden physical access
- Replace or reinforce generic locks and keys.
- Restrict access to the top hat, cabinet, hard drive, and USB ports.
- Use tamper sensors and alarms, and ensure alerts reach someone who can act.
- Review lighting, cameras, ATM placement, and response coverage.
- Require documented technician access and verify maintenance work.
Physical access is a key precursor identified by the FBI. A patched ATM can still be exposed if an attacker can freely reach its storage or internal ports.
2. Protect the endpoint
- Keep the ATM operating system and applications supported and patched.
- Use application allowlisting or equivalent controls to block unauthorized executables.
- Disable or restrict unused USB and removable-media paths.
- Protect boot settings, BIOS, firmware, and local administrator access.
- Encrypt storage where the platform supports it.
- Maintain secure, validated recovery images.
- Alert on unauthorized services, executables, configuration changes, and unexpected reboots.
Vendor materials from Diebold Nixdorf describe controls such as physical protection, alarms, monitoring, updates, and cash-dispense security. Those materials identify available technologies, but they are not independent proof that one product prevents every jackpotting method.
3. Secure the network and host connection
- Segment ATM networks from general corporate networks.
- Restrict administrative access and use strong authentication.
- Use authenticated and encrypted communications.
- Validate certificates and approved endpoints.
- Monitor ATM-to-host traffic for unusual patterns.
- Correlate physical tamper events with software and cash-dispense events.
Diebold Nixdorf discusses TLS and certificate-authority validation in the context of host-spoofing defenses. Host spoofing is related to, but distinct from, the malware-enabled jackpotting described by the FBI.
4. Consider authenticated cash dispensing
End-to-end cash authentication is designed to authenticate dispense requests at the host level and reduce reliance on local ATM defenses. It is not a universal plug-in fix. Implementation may require compatible ATM applications, dispensers, host systems, processors, and standards.
Operators should confirm exactly which parts of their fleet are covered, what happens when connectivity is lost, and whether the control blocks unauthorized local dispense commands or merely strengthens host authorization. It should be treated as one layer of defense in depth.
Best Value
- 2MP FHD Auto IR Night Vision with Wide Viewing Angle: 2MP Super HD USB camera with 24pcs IR led lights,up to 90 degree wide viewing angle,capture more clearer and sharper images and video,great fit for driveway,hallways,indoor outdoor dog pet baby security monitoring etc.
- High Speed 480P@100fps Dome Camera:Usb camera with 480P 100fps high frame rate,recording more smoothly and stable,easy setup with plug and play,free driver,waterproof camera with Aluminum box housing fit for indoor and outdoor,residential areas retail store, business. Dome camera mini webcam with wide application for use in ATM machine,kiosk,vending machine,simple security system,teaching system,interactive.
- Experience Magnificent Full-HD 1080P with CMOS OV2710 Image Sensor. This USB Webcam comes with enhanced capability utilizing the 1/2.7” CMOS OV2710 image sensor. Wide 90 degree viewing angle,Android,PC Windows,Linux,Raspeberry Pi and Mac.Waterproof and durable,it could be widely applicable to indoor/outdoors.store,home,office,school,bus,taxi in snowy/rainy/sunny days.
- Dome Camera Full HD 1080P USB Webcam:Desktop Laptop Computer Web Camera,High Speed 100fps Indoor Outdoor Security Camera,Audio IR Night Vision Web Cam,Plug&Play,Dome Webcam for Windows/Android/Mac.High speed 2 megapixel dome usb camera 640X480@100fps,Max resolution:1920X1080.
- USB 2.0/Plug&Play/Free Driver usb dome camera.This usb dome camera is plug and play,free driver,Platform Compatibility:Skype,Youtube,Yahoo!@Messenger,MSN,Zoom,instant messaging applications.We want to ensure the safety of our customers,their loved ones,homes,and businesses and you’ll receive a full 1-year US Warranty and Lifetime Support provided directly from Webcamer_usb.
5. Improve detection and recovery
A practical monitoring program should alert on:
- Top-hat or cabinet openings
- Unexpected storage, USB, boot, or application changes
- Unusual reboots or service activity
- Abnormal cash-dispense patterns
- Dispenses that lack a corresponding authorized transaction
Operators should also have a documented process to isolate the ATM, preserve logs and video, reconcile cash, notify law enforcement and relevant partners, restore from a known-good image, validate the machine, and review the wider fleet for similar indicators. An apparent cash shortage should not automatically be attributed to malware; ordinary reconciliation errors and mechanical failures must also be considered.
What the criminal cases show
Federal prosecutors announced additional indictments in January and February 2026 related to an alleged international ATM-jackpotting conspiracy. The February announcement said the number of charged defendants had reached 93. Prosecutors alleged that the scheme used Ploutus variants and recruited teams to access ATMs across the United States.
Those are allegations unless and until proved in court. In July 2026, prosecutors in Nevada separately alleged that two men installed a digital device on an ATM and stole approximately $76,000. That case, too, should not be treated as proof that every jackpotting incident involved the same people, group, or technique.
Free tools Windows power users keep installed
One-click scans. No signup required.
The cases reinforce the FBI’s warning that these attacks combine organized criminal activity with physical access and specialized ATM malware. They do not establish the probability that any particular consumer will encounter a compromised machine.
What the FBI statistics do—and do not—prove
The reported numbers support the conclusion that ATM jackpotting deserves attention from financial institutions and ATM operators, especially because more than 700 incidents were reported in 2025. But they do not show:
- The risk per ATM or per consumer
- The number of unique compromised machines
- A complete year-by-year national trend
- That every ATM manufacturer or model is vulnerable
- That consumers’ bank accounts are directly exposed whenever jackpotting occurs
The appropriate response is not panic at every ATM. It is layered protection for the machines, cash modules, software, communications, monitoring systems, and response processes that operators control.
Bottom line for ATM operators
The FBI’s warning describes a serious ATM-fleet and cash-loss problem, not a new reason to assume that every ATM withdrawal exposes a customer’s bank account. Banks, credit unions, deployers, and processors should prioritize physical access controls, endpoint integrity, removable-media restrictions, network authentication, authenticated cash dispensing where compatible, continuous monitoring, and rapid recovery.
For consumers, the sensible response is simple: avoid visibly tampered machines, report suspicious activity, use another ATM, and contact the card issuer about any incorrect transaction.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




