Five Men Tried to Make Kansas ATMs Spit Out Cash

Five men pleaded guilty after targeting Kansas ATMs with jackpotting malware as the FBI warns of a nationwide rise in attacks and financial losses.

Sep 2, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

With physical access and the right malware, criminals can command an ATM to dispense cash without a legitimate transaction.

That was the plan behind an attempted jackpotting operation in Kansas that ended with five Venezuelan nationals pleading guilty to conspiracy to commit bank larceny. 

The group traveled from Indiana in December 2025, attempted to install malware on ATMs in Wamego and Manhattan, and planned to activate the compromised machines remotely so they would dispense cash.

Both attempts failed, but the case comes amid a broader nationwide increase in ATM jackpotting.

The FBI says criminals are combining physical access with ATM malware that can interact with the machine’s underlying hardware-control software, potentially allowing cash to be dispensed without a legitimate card, customer account, or bank authorization.

What Is ATM Jackpotting?

ATMs are supposed to dispense cash after a bank approves a transaction; jackpotting turns that model on its head.

Unlike skimming, which typically attempts to capture a customer’s card data or PIN, jackpotting targets the ATM itself. 

The attack begins with physical access to the ATM. In the Kansas case, prosecutors said the five defendants specifically targeted ATMs they believed were more vulnerable to malware.

Once the malware is on the machine, the attacker can target the software layer that connects the ATM’s applications to its physical hardware.

According to an FBI advisory, malware from the Ploutus family can exploit the eXtensions for Financial Services, or XFS, layer that connects an ATM’s applications to its hardware. By issuing unauthorized commands through XFS, attackers can instruct the cash dispenser to release money without a bank card, customer account, or bank authorization.

Advertisement

Finance-motivated hacking makes a different move

Financially motivated hacking has traditionally involved stealing banking credentials, compromising accounts, or tricking victims into transferring money. Jackpotting makes a different move by going after the source of the money itself. It is closer to a bank robbery, except the criminals use malware and compromised ATM hardware instead of guns to get the cash.

That shift matters because jackpotting does not require criminals to deceive a customer or compromise an individual account. Instead, attackers target the machine holding the bank’s cash.

The FBI’s numbers show that this is becoming a larger problem rather than an isolated criminal technique. 

The agency recorded 1,900 ATM jackpotting incidents in the U.S. from 2020 through 2025. More than 700 occurred in 2025 alone and caused over $20 million in losses.

Unlike fraud that may be detected through suspicious account activity, jackpotting operations can empty an ATM within minutes and may not be detected until after the cash is gone, according to the FBI.

The failed attempt serves as a lesson for everyone

The fact that these attacks failed shows why organizations need several defenses working together. 

The defendants reportedly targeted ATMs they believed were more vulnerable to malware, which is a reminder that attackers will look for the weakest systems rather than trying to break through the best-protected ones.

This means keeping all software and underlying operating systems patched and hardening the interfaces that allow software to communicate with connected hardware.

But the lesson also extends well beyond ATMs. Security teams should assume that prevention can fail and build systems so that an attempted compromise does not fly past them blind.

That means implementing defense-in-depth methods. Access controls can prevent unauthorized entry; endpoint protections can block malware; application controls can restrict which software is allowed to run; and logging and monitoring can provide another opportunity to spot suspicious activity when earlier defenses fail.

Advertisement

In Wamego, the attempted malware installation triggered an alarm that brought law enforcement to the scene. Both attempted thefts were also captured by surveillance cameras, and authorities arrested the defendants several days later.

The broader takeaway for financial institutions is that ATM security must cover both physical and digital access. Patching software, restricting access, monitoring device activity, and maintaining overlapping controls can prevent one breached lock or missed alert from becoming an emptied cash dispenser.

Read more: New Manic Android malware can steal banking credentials and relay data through nearby infected phones, showing how financially motivated attackers continue to find new ways around conventional defenses.

Joseph Ofonagoro

Joseph is a technical writer with about three years of experience creating clear, practical content across consumer technology, startups, tutorials, and cybersecurity. He is also advancing a career in cyber threat intelligence, driven by a strong interest in the responsible use of technology and its role in protecting people, organizations, and digital systems. His passion for cybersecurity grew out of a broader commitment to helping others understand technology safely and effectively. As an undergraduate at the National Open University of Nigeria, he leads a community of technology enthusiasts, guiding beginners, sharing learning resources, and helping students build confidence as they explore careers in tech. Joseph’s writing combines technical curiosity with an accessible, beginner-friendly style. In addition to his editorial work, he periodically shares cybersecurity case studies and research reports on social media, covering threat trends, security lessons, and practical insights for readers interested in cyber awareness and digital safety.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.