Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»Over $20 million stolen in surge of ATM malware attacks in 2025
    Cybersecurity

    Over $20 million stolen in surge of ATM malware attacks in 2025

    adminBy adminFebruary 22, 2026No Comments3 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Bank ATM
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Bank ATM

    The FBI warned that Americans lost more than $20 million last year amid a massive surge in ATM “jackpotting” attacks, in which criminals use malware to force cash machines to dispense money.

    According to a Thursday FBI flash alert, more than 700 ATM jackpotting incidents were reported last year alone in a significant spike compared to the roughly 1,900 total incidents reported across the United States since 2020.

    These attacks can be carried out in minutes and target the software layer controlling an ATM’s physical hardware, using malicious tools such as the Ploutus malware. Most often, they go undetected by financial institutions and ATM operators until the cash is already gone.

    Wiz

    As the FBI explained, cash machines are designed to verify transactions through their bank before dispensing cash. However, Ploutus bypasses this process entirely, allowing the criminals to issue commands directly to the ATM and trigger withdrawals on demand without a bank card, a customer account, or the bank’s approval.

    “Ploutus malware exploits the eXtensions for Financial Services (XFS), the layer of software that instructs an ATM what to physically do. When a legitimate transaction occurs, the ATM application sends instructions through XFS for bank authorization,” the FBI said. “If a threat actor can issue their own commands to XFS, they can bypass bank authorization entirely and instruct the ATM to dispense cash on demand.”

    To install the malware, the attackers usually gain physical access to the targeted ATM using widely available generic keys. Once inside, they remove the machine’s hard drive, copy malware onto it and reinstall it, or even swap the original drive out entirely for another one preloaded with the malicious software.

    To defend against these attacks, the FBI encouraged financial institutions to audit their ATM systems for signs of unauthorized removable storage use and unauthorized processes.

    “When combined with gold image integrity validation, this approach enables early identification of physical intrusion and malware staging events that would otherwise evade network-based monitoring,” the law enforcement agency added.

    FBI’s warning comes after a wave of arrests targeting members of the Tren de Aragua (TdA) gang, all linked to a massive ATM jackpotting scheme that used Ploutus malware to steal millions in cash from bank ATMs across the United States.

    In total, the U.S. Department of Justice has charged 87 Tren de Aragua members over the past six months, who are now facing maximum prison terms ranging from 20 to 335 years each.


    tines

    Modern IT infrastructure moves faster than manual workflows can handle.

    In this new Tines guide, learn how your team can reduce hidden manual delays, improve reliability through automated response, and build and scale intelligent workflows on top of tools you already use.

    ATM attacks Malware Million stolen surge
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleGoogle Chrome Now Has Split View (and Two More New Productivity Features)
    Next Article Galaxy S26 series is getting ‘Hey Plex’ and a major AI upgrade
    admin
    • Website

    Related Posts

    Microsoft releases emergency patches for critical ASP.NET flaw

    April 22, 2026

    Progress Patches Multiple Vulnerabilities in MOVEit WAF, LoadMaster

    April 22, 2026

    Ransomware Negotiator Pleads Guilty to Aiding BlackCat Attacks in 2023

    April 22, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    Microsoft releases emergency patches for critical ASP.NET flaw

    April 22, 2026

    Progress Patches Multiple Vulnerabilities in MOVEit WAF, LoadMaster

    April 22, 2026

    How to build a YouTube analytics report in Data Studio

    April 22, 2026

    Fairphone CEO says there is ‘no financial excuse’ for smartphone manufacturers to pay their workers less than a living wage, as the sustainable electronics manufacturer shares its 2025 Impact Report

    April 22, 2026
    Categories
    • Blogging (66)
    • Cybersecurity (1,442)
    • Privacy & Online Earning (176)
    • SEO & Digital Marketing (876)
    • Tech Tools & Mobile / Apps (1,728)
    • WiFi / Internet & Networking (238)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    Microsoft releases emergency patches for critical ASP.NET flaw

    April 22, 2026

    Progress Patches Multiple Vulnerabilities in MOVEit WAF, LoadMaster

    April 22, 2026

    How to build a YouTube analytics report in Data Studio

    April 22, 2026
    Most Popular
    • Microsoft releases emergency patches for critical ASP.NET flaw
    • Progress Patches Multiple Vulnerabilities in MOVEit WAF, LoadMaster
    • How to build a YouTube analytics report in Data Studio
    • Fairphone CEO says there is ‘no financial excuse’ for smartphone manufacturers to pay their workers less than a living wage, as the sustainable electronics manufacturer shares its 2025 Impact Report
    • Someone turned an ESP32 T-LoRa Pager into a portable music machine, and you can too
    • Ransomware Negotiator Pleads Guilty to Aiding BlackCat Attacks in 2023
    • Google Adds New Tasked-Based Search Features
    • Grab this Samsung Galaxy S25 clear case for just $5
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.