Jackpotting ATM attacks arrive in the US

midian182

Posts: 9,738   +121
Staff member

Hackers likely associated with international crime syndicates have recently stolen more than $1 million from ATMs in the US using “jackpotting” attacks, said a Secret Service official speaking to Reuters.

The technique involves gaining physical access to a machine and using malware, specialized electronics, or both to take control and make it dispense hundreds of dollars at a time. The name jackpotting comes from the way the ATM’s are likened to slot machines paying out winnings.

Back in 2010, renowned hacker Barnaby Jack, who passed away in 2013, demonstrated jackpotting on an ATM at the Black Hat conference. It had until now been a problem in Europe, Asia, and Mexico, but security researcher Brian Krebs reports that the US Secret Service has started warning financial institutions that jackpotting attacks are taking place in the United States.

Attacks have been spotted across the country, ranging from the Pacific Northwest to the Gulf region to New England. There have been around six successful jackpotting incidents in the last few days.

The secret service alert says that hackers typically use an endoscope—the same kind physicians use—to locate the part of the ATM where they can attach their laptop. They then swap the machine’s hard drive with one infected with the Ploutus.D jackpotting malware. Once rebooted, the ATM appears out of service to customers but the criminals can remotely control it, forcing it to dispense cash that is then collected by other members of the gang.

Thieves appear to be targeting Opteva 500 and 700 series Diebold ATMs, which are said to be particularly vulnerable to jackpotting attacks, as are machines still running Windows XP.

Permalink to story.

 
With the all money running around financial institution and still can't wrap their head around the fact that their ATM is running vulnerable OS. I'm sure the financial ATM manufacture can't be that stupid.
 
"... machines still running Windows XP."

It's truly amazing just how stupid the financial sector is.
It's 2018 for crying out loud ...

This is only surprising to outsiders. Plenty of military and voting operations are still using Windows XP embedded.
 
"... machines still running Windows XP."

It's truly amazing just how stupid the financial sector is.
It's 2018 for crying out loud ...

As a Level II server engineer working in the financial industry, I'm sad to say how many servers are still running Server 2008 32bit due to legacy software. This stuff talks to a mainframe via SNA for cryin' out loud. Yes it costs money, a lot of it, to completely overhaul an entire infrastructure that "just works" but we're getting to the tipping point.
 
"... machines still running Windows XP."

It's truly amazing just how stupid the financial sector is.
It's 2018 for crying out loud ...

They make BILLIONS. It is cheaper for them to get hacked than to upgrade every machine. They arent stupid, its just not worth the upgrade to lose a million here or there. Eventually when the ROI is worth it, they will upgrade.
 
They make BILLIONS. It is cheaper for them to get hacked than to upgrade every machine. They arent stupid, its just not worth the upgrade to lose a million here or there. Eventually when the ROI is worth it, they will upgrade.

It's also worth getting data breach or compromise and lend it in the wrong hand.
 
Back