Penough Logo

ATM Security: From Cash Dispensers to High-Impact Attack Surfaces

7 min read
Key Insight

An ATM may look like a simple machine: insert a card, enter a PIN, receive cash. Behind that familiar interaction, however, is a complex system combining: Embedded computers , Operating system , ATM middleware , Card readers and PIN pads , Cash dispensers , Bank switches and payment networks , Cryptographic key management , ,Remote monitoring , Physical access controls That combination makes an ATM more than a cash dispenser. It makes the machine a high-impact attack surface.

Share:

An ATM may look like a simple machine: insert a card, enter a PIN, receive cash.

Behind that familiar interaction, however, is a complex system combining:

  • Embedded computers

  • Operating system

  • ATM middleware

  • Card readers and PIN pads

  • Cash dispensers ,

  • Bank switches and payment networks

  • Cryptographic key management

  • Remote monitoring

  • Physical access controls

That combination makes an ATM more than a cash dispenser. It makes the machine a high-impact attack surface.

If an attacker compromises an ordinary workstation, the result may be stolen data or unauthorized access. If an attacker compromises an ATM, the outcome can be more immediate: unauthorized withdrawals, customer fraud, service disruption, physical damage, or direct theft from the machine.


Why ATMs Are Different from Ordinary Computers

Many ATMs rely on long hardware lifecycles, specialized software, proprietary middleware, and difficult-to-update operating systems. Even short outages can affect customer access, cash availability, branch operations, bank reputation, and regulatory obligations.

That makes ATM security more than an endpoint-security issue. It requires physical protection, endpoint and application security, network monitoring, transaction monitoring, cryptographic controls, and strong vendor governance . Because a weakness in any layer can create an opening for attackers.


The ATM Software Layer: Why Middleware Matters

One of the most important components in an ATM is the middleware that connects the ATM application to its hardware.

A widely used standard in this area is CEN/XFS, commonly known as XFS.

This abstraction is useful for ATM manufacturers and software developers because the same application can work with different hardware models through a common interface.

However, it also creates a security concern.

If an attacker gains sufficient control of the ATM operating system or the software environment around XFS, they may be able to interact with hardware services in ways the original ATM application was never designed to allow.

That does not mean every XFS deployment is automatically insecure. Security depends on the operating system, vendor implementation, application permissions, hardening, access controls, and monitoring.

The risk appears when the ATM treats local software access as trustworthy.


Common ATM Attack Methods

1. Card Skimming and PIN Capture

Skimming is one of the most familiar ATM threats.

Criminals install unauthorized devices that capture card information or record the customer’s PIN.

Common techniques include:

  • Fake card readers

  • Internal skimmers

  • PIN-pad overlays

  • Hidden cameras

  • Fake ATM faceplates

  • Devices placed near exposed card-reader components

The stolen information may later be used to create counterfeit cards or conduct unauthorized transactions.

The FBI’s explanation of ATM skimming describes how criminals can capture card data and PINs using fake readers, hidden cameras, and keypad overlays. The FDIC also provides consumer guidance on skimming indicators.


2. ATM Jackpotting and Black-Box Attacks

ATM jackpotting is different from ordinary card fraud.

Instead of stealing a customer’s card information, attackers attempt to make the ATM dispense the bank’s cash without a legitimate customer transaction.

According to the FDIC Office of Inspector General, jackpotting can involve criminals accessing the ATM, installing malware or unauthorized devices, and controlling the machine’s cash-dispensing functions.

The FBI estimated approximately 700 ATM jackpotting incidents and more than $20 million in losses during 2025, according to the same alert.

The goal is to bypass the normal transaction process.

Instead of:

code
Card → PIN → Authorization → Cash

the attacker attempts to create a path such as:

code
Unauthorized access → ATM control → Cash dispensing

The U.S. Department of Justice has also prosecuted large alleged jackpotting schemes. For example, its February 2026 announcement described an international conspiracy involving malware and the theft of millions of dollars from ATMs.

Important distinction

Not every unauthorized cash withdrawal is jackpotting.

Transaction-reversal fraud, stolen-card fraud, cash trapping, and ATM burglary are different attack categories. They may produce similar financial losses but require different controls.

Accurate classification matters because the investigation and response process will be different for each type.


3. Network and Banking-System Compromise

An ATM does not operate in isolation.

It communicates with systems such as:

  • ATM switches

  • Transaction processors

  • Core banking platforms

  • Monitoring systems

  • Remote-management platforms

  • Vendor support infrastructure

  • Authentication and key-management systems

If attackers compromise the network surrounding ATMs, they may attempt to move from one system to another.

This is why ATM networks should not be treated as ordinary office networks.

They require strong segmentation, restricted access, monitoring, and carefully controlled communication paths.

A real-world warning: UNC2891

Research published by Group-IB on UNC2891 describes a financially motivated threat actor that targeted banking infrastructure and used a Raspberry Pi device connected inside a bank’s internal network.

The research highlights an important lesson:

An attacker may not need to break through the main perimeter if they can gain a foothold inside the environment.

The case involved sophisticated access, custom malware, and attempts to reach critical banking systems.


Bangladesh’s ATM Security Reality

Bangladesh’s ATM network inherits risks from card skimming, cash-out attacks, physical tampering, and weaknesses in older systems. As ATM usage grows, banks must strengthen inspections, endpoint security, network monitoring, and customer awareness. A single compromised machine can create financial loss, operational disruption, and damage to customer trust.

The Bangladesh Bank’s ATM security guidance provides a useful baseline for understanding expected protections. Its recommendations include:

  • CCTV coverage

  • Confidentiality and integrity of ATM communications

  • Protected ATM-to-bank connectivity

  • Regular ATM key changes

  • Unique keys for different ATMs

  • Anti-skimming mechanisms

  • Encrypted PIN pads

  • Restrictions on removable media

  • Vulnerability assessment and penetration testing

  • Blocking unnecessary ports and shared folders

  • Protection against data leakage

The guidance is available in the Bangladesh Bank ATM Security guideline document.


Why One ATM Compromise Can Become a Network Problem

A bank may operate hundreds or thousands of ATMs.

If those machines share:

  • Similar configurations

  • Common software images

  • Reused credentials

  • Standardized access keys

  • Shared management tools

  • Common vendor connections

  • Similar network rules

then one successful attack may reveal a repeatable path to other machines.

This creates a dangerous relationship between standardization and security.

Standardization improves operational efficiency. But if every machine is configured identically, a weakness in one machine may exist across the entire fleet.


A Practical ATM Security Framework

1. Strengthen Physical Security

The FDIC OIG jackpotting alert specifically recommends measures such as unique ATM keys, security gates, CCTV, alarms, tamper-resistant screws, and employee awareness training.

Physical security is not simply about preventing theft of the machine. It is also about preventing unauthorized access to the computer inside it.


2. Harden the ATM Endpoint

Full-disk encryption is valuable, but it should not be treated as a complete solution. Encryption should be combined with secure boot, firmware protection, strong key management, and physical controls.

If an attacker can boot the machine from external media or replace hardware, encryption alone may not prevent compromise.


3. Protect ATM Middleware and Applications

Banks should review how ATM applications interact with middleware and hardware services.

Where supported, banks should use:

  • Application allowlisting

  • Code signing

  • Process isolation

  • Least privilege

  • Protected configuration files

  • Secure software deployment

  • Integrity monitoring

  • Restricted service access


4. Segment and Monitor the ATM Network

ATM traffic should be separated from ordinary corporate traffic wherever possible.

A bank should be able to answer:

Which systems can communicate with this ATM and why?

If the answer is unclear, the network is probably too permissive.


5. Improve Cryptographic Key Management

ATM security depends heavily on cryptographic protection.

Banks should carefully manage:

  • PIN encryption keys

  • ATM master keys

  • Key-encryption keys

  • Key rotation

  • Key distribution

  • Key storage

  • Dual control

  • Split knowledge

  • Hardware security modules

  • Key compromise procedures


6. Monitor Transactions and Physical Events Together

Traditional monitoring may focus on transactions:

  • Unusual withdrawal volume

  • Multiple withdrawals in a short period

  • Unusual locations

  • Failed PIN attempts

  • Unexpected cash depletion

ATM security monitoring should also include physical and endpoint signals:

The strongest detection comes from combining signals.

For example:

ATM cabinet opened + unauthorized USB device + new executable + unusual cash dispensing

That combination should trigger an immediate investigation.


7. Test the Entire Attack Surface

ATM testing should go beyond a conventional web application assessment.

All physical and operational testing must be explicitly authorized and carefully coordinated. ATM testing can disrupt services or create real financial risk if performed without proper controls.


What Banks Should Do Now

A practical ATM security program should begin with a clear inventory and risk assessment.

Immediate priorities

  • Identify every ATM and its software version.

  • Document operating systems and middleware.

  • Review physical access controls.

  • Replace shared or default keys.

  • Disable unauthorized removable media.

  • Restrict local administrator access.

  • Review ATM network segmentation.

  • Validate remote-management controls.

  • Enable centralized logging.

  • Monitor unusual hardware and software changes.

  • Review vendor access.

  • Test incident-response procedures.

  • Conduct authorized vulnerability assessments and penetration tests.

If these questions do not have clear answers, the organization may have security gaps that have not yet been measured.


How Penough Can Help

ATM security requires more than installing an antivirus product or adding another firewall rule.

It requires an assessment of how physical access, software, middleware, network connectivity, transaction processing, and operational processes work together.

Our Target :

Find the weaknesses before attackers turn them into cash loss, service disruption, or a wider banking compromise.

AUTHOR

Abrar

Cybersecurity researcher and technical contributor at Penough Ltd.