An ATM may look like a simple machine: insert a card, enter a PIN, receive cash.
Behind that familiar interaction, however, is a complex system combining:
Embedded computers
Operating system
ATM middleware
Card readers and PIN pads
Cash dispensers ,
Bank switches and payment networks
Cryptographic key management
Remote monitoring
Physical access controls
That combination makes an ATM more than a cash dispenser. It makes the machine a high-impact attack surface.

If an attacker compromises an ordinary workstation, the result may be stolen data or unauthorized access. If an attacker compromises an ATM, the outcome can be more immediate: unauthorized withdrawals, customer fraud, service disruption, physical damage, or direct theft from the machine.
Why ATMs Are Different from Ordinary Computers
Many ATMs rely on long hardware lifecycles, specialized software, proprietary middleware, and difficult-to-update operating systems. Even short outages can affect customer access, cash availability, branch operations, bank reputation, and regulatory obligations.
That makes ATM security more than an endpoint-security issue. It requires physical protection, endpoint and application security, network monitoring, transaction monitoring, cryptographic controls, and strong vendor governance . Because a weakness in any layer can create an opening for attackers.
The ATM Software Layer: Why Middleware Matters
One of the most important components in an ATM is the middleware that connects the ATM application to its hardware.
A widely used standard in this area is CEN/XFS, commonly known as XFS.

This abstraction is useful for ATM manufacturers and software developers because the same application can work with different hardware models through a common interface.
However, it also creates a security concern.
If an attacker gains sufficient control of the ATM operating system or the software environment around XFS, they may be able to interact with hardware services in ways the original ATM application was never designed to allow.
That does not mean every XFS deployment is automatically insecure. Security depends on the operating system, vendor implementation, application permissions, hardening, access controls, and monitoring.
The risk appears when the ATM treats local software access as trustworthy.

Common ATM Attack Methods
1. Card Skimming and PIN Capture
Skimming is one of the most familiar ATM threats.
Criminals install unauthorized devices that capture card information or record the customer’s PIN.
Common techniques include:
Fake card readers
Internal skimmers
PIN-pad overlays
Hidden cameras
Fake ATM faceplates
Devices placed near exposed card-reader components
The stolen information may later be used to create counterfeit cards or conduct unauthorized transactions.
The FBI’s explanation of ATM skimming describes how criminals can capture card data and PINs using fake readers, hidden cameras, and keypad overlays. The FDIC also provides consumer guidance on skimming indicators.

2. ATM Jackpotting and Black-Box Attacks
ATM jackpotting is different from ordinary card fraud.
Instead of stealing a customer’s card information, attackers attempt to make the ATM dispense the bank’s cash without a legitimate customer transaction.
According to the FDIC Office of Inspector General, jackpotting can involve criminals accessing the ATM, installing malware or unauthorized devices, and controlling the machine’s cash-dispensing functions.
The FBI estimated approximately 700 ATM jackpotting incidents and more than $20 million in losses during 2025, according to the same alert.

The goal is to bypass the normal transaction process.
Instead of:
codeCard → PIN → Authorization → Cashthe attacker attempts to create a path such as:
codeUnauthorized access → ATM control → Cash dispensing
The U.S. Department of Justice has also prosecuted large alleged jackpotting schemes. For example, its February 2026 announcement described an international conspiracy involving malware and the theft of millions of dollars from ATMs.
Important distinction
Not every unauthorized cash withdrawal is jackpotting.
Transaction-reversal fraud, stolen-card fraud, cash trapping, and ATM burglary are different attack categories. They may produce similar financial losses but require different controls.
Accurate classification matters because the investigation and response process will be different for each type.
3. Network and Banking-System Compromise
An ATM does not operate in isolation.
It communicates with systems such as:
ATM switches
Transaction processors
Core banking platforms
Monitoring systems
Remote-management platforms
Vendor support infrastructure
Authentication and key-management systems
If attackers compromise the network surrounding ATMs, they may attempt to move from one system to another.
This is why ATM networks should not be treated as ordinary office networks.
They require strong segmentation, restricted access, monitoring, and carefully controlled communication paths.

A real-world warning: UNC2891
Research published by Group-IB on UNC2891 describes a financially motivated threat actor that targeted banking infrastructure and used a Raspberry Pi device connected inside a bank’s internal network.
The research highlights an important lesson:
An attacker may not need to break through the main perimeter if they can gain a foothold inside the environment.
The case involved sophisticated access, custom malware, and attempts to reach critical banking systems.
Bangladesh’s ATM Security Reality
Bangladesh’s ATM network inherits risks from card skimming, cash-out attacks, physical tampering, and weaknesses in older systems. As ATM usage grows, banks must strengthen inspections, endpoint security, network monitoring, and customer awareness. A single compromised machine can create financial loss, operational disruption, and damage to customer trust.

The Bangladesh Bank’s ATM security guidance provides a useful baseline for understanding expected protections. Its recommendations include:
CCTV coverage
Confidentiality and integrity of ATM communications
Protected ATM-to-bank connectivity
Regular ATM key changes
Unique keys for different ATMs
Anti-skimming mechanisms
Encrypted PIN pads
Restrictions on removable media
Vulnerability assessment and penetration testing
Blocking unnecessary ports and shared folders
Protection against data leakage
The guidance is available in the Bangladesh Bank ATM Security guideline document.
Why One ATM Compromise Can Become a Network Problem
A bank may operate hundreds or thousands of ATMs.
If those machines share:
Similar configurations
Common software images
Reused credentials
Standardized access keys
Shared management tools
Common vendor connections
Similar network rules
then one successful attack may reveal a repeatable path to other machines.
This creates a dangerous relationship between standardization and security.
Standardization improves operational efficiency. But if every machine is configured identically, a weakness in one machine may exist across the entire fleet.

A Practical ATM Security Framework
1. Strengthen Physical Security

The FDIC OIG jackpotting alert specifically recommends measures such as unique ATM keys, security gates, CCTV, alarms, tamper-resistant screws, and employee awareness training.
Physical security is not simply about preventing theft of the machine. It is also about preventing unauthorized access to the computer inside it.
2. Harden the ATM Endpoint

Full-disk encryption is valuable, but it should not be treated as a complete solution. Encryption should be combined with secure boot, firmware protection, strong key management, and physical controls.
If an attacker can boot the machine from external media or replace hardware, encryption alone may not prevent compromise.
3. Protect ATM Middleware and Applications
Banks should review how ATM applications interact with middleware and hardware services.

Where supported, banks should use:
Application allowlisting
Code signing
Process isolation
Least privilege
Protected configuration files
Secure software deployment
Integrity monitoring
Restricted service access
4. Segment and Monitor the ATM Network
ATM traffic should be separated from ordinary corporate traffic wherever possible.

A bank should be able to answer:
Which systems can communicate with this ATM and why?
If the answer is unclear, the network is probably too permissive.
5. Improve Cryptographic Key Management
ATM security depends heavily on cryptographic protection.
Banks should carefully manage:
PIN encryption keys
ATM master keys
Key-encryption keys
Key rotation
Key distribution
Key storage
Dual control
Split knowledge
Hardware security modules
Key compromise procedures

6. Monitor Transactions and Physical Events Together
Traditional monitoring may focus on transactions:
Unusual withdrawal volume
Multiple withdrawals in a short period
Unusual locations
Failed PIN attempts
Unexpected cash depletion
ATM security monitoring should also include physical and endpoint signals:

The strongest detection comes from combining signals.
For example:
ATM cabinet opened + unauthorized USB device + new executable + unusual cash dispensing
That combination should trigger an immediate investigation.
7. Test the Entire Attack Surface
ATM testing should go beyond a conventional web application assessment.

All physical and operational testing must be explicitly authorized and carefully coordinated. ATM testing can disrupt services or create real financial risk if performed without proper controls.
What Banks Should Do Now
A practical ATM security program should begin with a clear inventory and risk assessment.
Immediate priorities
Identify every ATM and its software version.
Document operating systems and middleware.
Review physical access controls.
Replace shared or default keys.
Disable unauthorized removable media.
Restrict local administrator access.
Review ATM network segmentation.
Validate remote-management controls.
Enable centralized logging.
Monitor unusual hardware and software changes.
Review vendor access.
Test incident-response procedures.
Conduct authorized vulnerability assessments and penetration tests.

If these questions do not have clear answers, the organization may have security gaps that have not yet been measured.
How Penough Can Help
ATM security requires more than installing an antivirus product or adding another firewall rule.
It requires an assessment of how physical access, software, middleware, network connectivity, transaction processing, and operational processes work together.

Our Target :
Find the weaknesses before attackers turn them into cash loss, service disruption, or a wider banking compromise.