FBI ATM jackpotting mitigation guidance
Advisory/Mitigation
Summary
Hide ▲
Show ▼
The FBI has issued mitigation guidance for ATM jackpotting, aiming to reduce cash-out risk across deployed ATM devices. The recommendations focus on physical security, access control, and monitoring to make unauthorized ATM access harder. The guidance matters because jackpotting attacks can force machines to dispense cash without a legitimate transaction and can be difficult to detect before losses occur.
Related Happenings
Tren de Aragua members charged in ATM jackpotting case
Law Enforcement
First: 20.02.2026 12:08
Last: 20.02.2026 12:08
Sources 1
About this happening:
The U.S. Department of Justice charged **87 Tren de Aragua members** over the past **six months** in a case tied to **ATM jackpotting** and **Ploutus malware**. The charging actio...
Tren de Aragua members charged in ATM jackpotting case
Law EnforcementAbout this happening: The U.S. Department of Justice charged **87 Tren de Aragua members** over the past **six months** in a case tied to **ATM jackpotting** and **Ploutus malware**. The charging actio...
U.S. ATM jackpotting cash-out wave
Exploitation Wave
First: 20.02.2026 10:05
Last: 20.02.2026 10:05
Sources 1
How related:
A new FBI Flash alert claimed that the 700+ attacks seen in 2025 resulted in losses of over $20m.
About this happening:
**ATM jackpotting** is intensifying across the **U.S.**, with **1,900 incidents since 2020** and **more than $20 million** lost in **2025**. The wave shows attackers repeatedly co...
U.S. ATM jackpotting cash-out wave
Exploitation WaveHow related: A new FBI Flash alert claimed that the 700+ attacks seen in 2025 resulted in losses of over $20m.
About this happening: **ATM jackpotting** is intensifying across the **U.S.**, with **1,900 incidents since 2020** and **more than $20 million** lost in **2025**. The wave shows attackers repeatedly co...
Ploutus malware in nationwide ATM jackpotting operation
Malware Activity
First: 27.01.2026 18:27
Last: 27.01.2026 18:27
Sources 1
How related:
The jackpotting attacks involve the use of specialized malware, such as Ploutus, to infect ATMs and force them to dispense cash.
About this happening:
The **Ploutus** malware was used in a **nationwide ATM jackpotting operation** that drained cash from **bank and credit union ATMs across the United States**, raising theft and co...
Ploutus malware in nationwide ATM jackpotting operation
Malware ActivityHow related: The jackpotting attacks involve the use of specialized malware, such as Ploutus, to infect ATMs and force them to dispense cash.
About this happening: The **Ploutus** malware was used in a **nationwide ATM jackpotting operation** that drained cash from **bank and credit union ATMs across the United States**, raising theft and co...
Latest development: 20.02.2026 10:05
The FBI warned that ATM jackpotting incidents across the U.S. have increased, citing more than $20 million lost in 2025, 1,900 reported incidents since 2020, and about $40.73 million collectively lost since 2021. The bulletin says attackers use Ploutus and similar malware to gain access to ATMs, exploit XFS on the underlying Windows operating system, and force cash-outs, and it recommends stronger physical security, security cameras, threat sensors, lock changes, device auditing, default-credential resets, device allowlisting, automatic shutdown on indicators of compromise, and logging.
Tren de Aragua (TdA) indicted in ATM jackpotting operation allegedly orchestrated by Tren de Aragua
Law Enforcement
First: 27.01.2026 18:27
Last: 27.01.2026 18:27
Sources 1
About this happening:
A **Nebraska federal grand jury** charged **31 additional defendants** in an **ATM jackpotting** case, expanding the federal prosecution of a scheme that used **Ploutus malware**...
Tren de Aragua (TdA) indicted in ATM jackpotting operation allegedly orchestrated by Tren de Aragua
Law EnforcementAbout this happening: A **Nebraska federal grand jury** charged **31 additional defendants** in an **ATM jackpotting** case, expanding the federal prosecution of a scheme that used **Ploutus malware**...
AI-assisted Truman Show investment fraud campaign
Campaign
First: 09.01.2026 13:00
Last: 09.01.2026 13:00
Sources 1
About this happening:
The **Truman Show** operation is an **AI-assisted investment fraud campaign** that uses **fake personas** and **attacker-controlled infrastructure** to lure victims into crypto sc...
AI-assisted Truman Show investment fraud campaign
CampaignAbout this happening: The **Truman Show** operation is an **AI-assisted investment fraud campaign** that uses **fake personas** and **attacker-controlled infrastructure** to lure victims into crypto sc...
Timeline
-
20.02.2026 10:05 3 articles · 3mo ago
FBI issues ATM jackpotting mitigation guidance
Mitigation Patch UpdateThe FBI issued mitigation guidance for ATM operators across the U.S. after warning that Ploutus and similar malware can exploit physical and software vulnerabilities in ATMs to force cash-outs without a legitimate transaction. The recommendations focus on stronger physical security, device auditing, default-credential changes, automatic shutdown when indicators of compromise appear, device allowlisting, and log retention to make unauthorized ATM access and cash-dispense abuse harder.
Show sources
- FBI Reports 1,900 ATM Jackpotting Incidents Since 2020, $20M Lost in 2025 — thehackernews.com — 20.02.2026 10:05
- FBI Reports 1,900 ATM Jackpotting Incidents Since 2020, $20M Lost in 2025 — thehackernews.com — 20.02.2026 10:05
- Jackpotting Surge Costs Banks Over $20m, Warns FBI — www.infosecurity-magazine.com — 23.02.2026 12:30