The FBI reported a sharp increase in ATM jackpotting in the US, a cyber-physical attack in which criminals compromise ATMs and use malware to force cash dispensing without bank authorization. Since 2020, the FBI has tracked more than 1,900 incidents, including 700+ in 2025, with losses exceeding $20 million; the activity is described as increasing and often difficult to detect until after cash is removed.
The FBI said attackers commonly gain access by opening the ATM cabinet with widely available generic keys, then installing malware by removing the hard drive to copy the payload or swapping in a preloaded drive/device. Reported malware includes Ploutus, which abuses the eXtensions for Financial Services (XFS) API layer used by ATM applications to interface with hardware; by issuing their own XFS commands, attackers can bypass bank authorization and directly control cash-out functions. The FBI noted the technique can work across different ATM manufacturers with minimal code changes, leveraging the underlying Windows environment during compromise.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
12 events from the most recent confirmed update back to the earliest known activity.
In the same Feb. 19, 2026 FLASH alert, the FBI released technical indicators of compromise and prevention guidance for Ploutus-style ATM attacks. Recommendations included stronger physical locks, tamper detection, gold-image validation, device controls, logging, and reporting suspicious activity to FBI field offices or IC3.
On Feb. 19, 2026, the FBI issued FLASH-20260219-001 warning U.S. banks and ATM operators about a nationwide increase in malware-enabled ATM jackpotting. The alert said roughly 1,900 incidents had been reported since 2020, including more than 700 in 2025 with losses exceeding $20 million.
The U.S. Department of Justice announced indictments against 54 people accused of participating in a malware-based ATM theft and money-laundering conspiracy linked by prosecutors to the Tren de Aragua network. The case concerned a Ploutus-based jackpotting scheme that allegedly stole millions from U.S. ATMs.
The Ploutus-based theft spree cited by the Justice Department continued through December 2025. By the end of the campaign, the group had allegedly stolen at least $5.4 million from 63 ATMs.
The FBI reported that more than 700 jackpotting incidents occurred in 2025 alone, causing over $20 million in losses. The attacks used physical access and malware such as Ploutus to force ATMs to dispense cash without authorization.
A Ploutus-based jackpotting ring targeted credit-union ATMs and stole at least $5.4 million from 63 machines. Prosecutors said the thefts occurred between February 2024 and December 2025.
According to Justice Department figures cited in the reporting, total losses tied to ATM jackpotting reached approximately $40.7 million since 2021. The figure reflects the broader financial impact of U.S. jackpotting activity over multiple years.
The FBI said it has tracked roughly 1,900 ATM jackpotting incidents in the United States since 2020. This marks the start of the reporting period used in the agency's 2026 warning.
Diebold Nixdorf published further warnings on Ploutus activity the following year, underscoring continued concern about ATM malware abuse. The alerts highlighted the persistence of jackpotting risks to ATM operators.
ATM vendor Diebold Nixdorf issued alerts about Ploutus-related threats affecting ATMs. These vendor warnings reflected the malware's growing relevance across ATM manufacturers.
Symantec first detected the Ploutus malware family, which became one of the best-known ATM jackpotting tools. Early deployments were reported in Mexico before the malware spread more broadly.
Security researcher Barnaby Jack publicly demonstrated ATM jackpotting in an on-stage Black Hat presentation, showing how ATMs could be manipulated to dispense cash. The demonstration is cited as an early milestone in the evolution of jackpotting techniques.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
11 references tracked. Mallory keeps watching after this page renders.
infosecwriteups.com
Open sourcescworld.com
Open sourcetomshardware.com
Open sourcecybersecuritynews.com
Open sourcebankinfosecurity.com
Open sourcetherecord.media
Open sourcetechcrunch.com
Open sourcego.theregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.