UPDATED 21:03 EST / JANUARY 28 2018

INFRA

Secret Service warns US ATMs are being targeted by ‘jackpotting’ hack

A form of automatic teller machine hacking previously seen in Europe, Asia and Mexico has made its way to the United States, prompting the Secret Service to warn financial institutions to be on the lookout.

The Secret Service memo, obtained and described Saturday by security research Brian Krebs, details the “jackpotting” ATM hacking method that involves hackers physically accessing a machine and infecting it with a form of malware known as Ploutus.D. Once the machine is infected, the hackers can control the operations of the ATM, including the ability for them to make the machine spit out cash, hence the name “jackpotting,” as in winning a jackpot Las Vegas casino-style.

The attacks were confirmed by two major ATM makers, Diebold Nixdorf Inc. and NCR Corp., in a Reuters report, with both companies saying that they had sent out the alerts to clients. NCR said its equipment had not been targeted in the recent attack, but it was still a concern for the entire ATM industry. Diebold Nixdorf said it had been warned that hackers were targeting its Opteva ATM model, which ceased production several years ago.

ATM hacking is not a new concept, but mostly for better-known methods such as skimming, in which a device is physically added to a machine to steal account data, including PIN numbers, from unsuspecting victims.

The ability to hack an ATM and have it spit out money first appeared in 2016 with a Skimmer malware variant discovered by Kaspersky Lab that required the hacker to insert a custom-made command card into an ATM to control it.

The new Ploutus.D jackpotting method allows hackers to access the ATM remotely once it has been infected, enabling them to use mules to collect money from infected machines.

Photo: 76657755@N04/Flickr

Since you’re here …

… We’d like to tell you about our mission and how you can help us fulfill it. SiliconANGLE Media Inc.’s business model is based on the intrinsic value of the content, not advertising. Unlike many online publications, we don’t have a paywall or run banner advertising, because we want to keep our journalism open, without influence or the need to chase traffic.The journalism, reporting and commentary on SiliconANGLE — along with live, unscripted video from our Silicon Valley studio and globe-trotting video teams at theCUBE — take a lot of hard work, time and money. Keeping the quality high requires the support of sponsors who are aligned with our vision of ad-free journalism content.

If you like the reporting, video interviews and other ad-free content here, please take a moment to check out a sample of the video content supported by our sponsors, tweet your support, and keep coming back to SiliconANGLE.