With physical access and the right malware, criminals can command an ATM to dispense cash without a legitimate transaction.
That was the plan behind an attempted jackpotting operation in Kansas that ended with five Venezuelan nationals pleading guilty to conspiracy to commit bank larceny.
The group traveled from Indiana in December 2025, attempted to install malware on ATMs in Wamego and Manhattan, and planned to activate the compromised machines remotely so they would dispense cash.
Both attempts failed, but the case comes amid a broader nationwide increase in ATM jackpotting.
The FBI says criminals are combining physical access with ATM malware that can interact with the machine’s underlying hardware-control software, potentially allowing cash to be dispensed without a legitimate card, customer account, or bank authorization.
What Is ATM Jackpotting?
ATMs are supposed to dispense cash after a bank approves a transaction; jackpotting turns that model on its head.
Unlike skimming, which typically attempts to capture a customer’s card data or PIN, jackpotting targets the ATM itself.
The attack begins with physical access to the ATM. In the Kansas case, prosecutors said the five defendants specifically targeted ATMs they believed were more vulnerable to malware.
Once the malware is on the machine, the attacker can target the software layer that connects the ATM’s applications to its physical hardware.
According to an FBI advisory, malware from the Ploutus family can exploit the eXtensions for Financial Services, or XFS, layer that connects an ATM’s applications to its hardware. By issuing unauthorized commands through XFS, attackers can instruct the cash dispenser to release money without a bank card, customer account, or bank authorization.
Finance-motivated hacking makes a different move
Financially motivated hacking has traditionally involved stealing banking credentials, compromising accounts, or tricking victims into transferring money. Jackpotting makes a different move by going after the source of the money itself. It is closer to a bank robbery, except the criminals use malware and compromised ATM hardware instead of guns to get the cash.
That shift matters because jackpotting does not require criminals to deceive a customer or compromise an individual account. Instead, attackers target the machine holding the bank’s cash.
The FBI’s numbers show that this is becoming a larger problem rather than an isolated criminal technique.
The agency recorded 1,900 ATM jackpotting incidents in the U.S. from 2020 through 2025. More than 700 occurred in 2025 alone and caused over $20 million in losses.
Unlike fraud that may be detected through suspicious account activity, jackpotting operations can empty an ATM within minutes and may not be detected until after the cash is gone, according to the FBI.
The failed attempt serves as a lesson for everyone
The fact that these attacks failed shows why organizations need several defenses working together.
The defendants reportedly targeted ATMs they believed were more vulnerable to malware, which is a reminder that attackers will look for the weakest systems rather than trying to break through the best-protected ones.
This means keeping all software and underlying operating systems patched and hardening the interfaces that allow software to communicate with connected hardware.
But the lesson also extends well beyond ATMs. Security teams should assume that prevention can fail and build systems so that an attempted compromise does not fly past them blind.
That means implementing defense-in-depth methods. Access controls can prevent unauthorized entry; endpoint protections can block malware; application controls can restrict which software is allowed to run; and logging and monitoring can provide another opportunity to spot suspicious activity when earlier defenses fail.
In Wamego, the attempted malware installation triggered an alarm that brought law enforcement to the scene. Both attempted thefts were also captured by surveillance cameras, and authorities arrested the defendants several days later.
The broader takeaway for financial institutions is that ATM security must cover both physical and digital access. Patching software, restricting access, monitoring device activity, and maintaining overlapping controls can prevent one breached lock or missed alert from becoming an emptied cash dispenser.
Read more: New Manic Android malware can steal banking credentials and relay data through nearby infected phones, showing how financially motivated attackers continue to find new ways around conventional defenses.





