The news sounds like a dream come true for many: walking past an ATM and having the machine start dispensing its contents without asking for anything. We haven't given up hope yet (!), but what brings us here today is actually a massive cyberattack that spanned the entire year, affecting ATMs in several countries, especially in Europe. The information was published by Russian security company Group IB, and the FBI has already issued an alert to US banks about the possibility of similar attacks.

Cyberattack Forces European ATMs to Spit Out Banknotes
ATM

The 'Jackpotting' Technique

The technique is known as “jackpotting”. Its application depends on the type of ATM, but the ultimate goal is the same: making the machine start handing out banknotes one after another. YouTube is full of demonstrations, and honestly, I don't know how security experts get whole ATMs, but the point is that some have vulnerabilities. Essentially, ATMs are computers with environments built to run for weeks without interruption, giving rise to various hacks and exploits. The first news about jackpotting began circulating mid-year, with reports of attacks in Taiwan and Thailand. Now, a statement from Russian security company Group IB confirms operations on European soil, including Spain. The big difference is that this jackpotting was remote.

Cyberattack Forces European ATMs to Spit Out Banknotes
Ripping ATMs out of the ground is a thing of the past. Now they attack banking networks and only need to show up to collect the cash...

Group IB's Cobalt Report speaks of “at least 14 countries” affected on two different continents, but they have withheld the names of the banks involved for logical reasons. Both Diebold Nixdorf and NCR, two of the largest ATM manufacturers in the world, admitted to being aware of the attacks and have been working with their clients on mitigation techniques throughout this time. Everything suggests that the ATMs are infected remotely through banking networks, after they have been compromised with the security tool Cobalt Strike (hence the name of the report). The attack in Europe was likely the work of a single group of cybercriminals, which Group IB identifies as Buhtrap.

The ATM Security Association did not share any comment with the media after the report's publication, and neither did spokespeople from Europol or the FBI, but it was indicated that the US agency has already sent a series of alerts to local banks about this new threat. How big is it? Buhtrap managed to steal $28 million between August 2015 and January 2016 by attacking Russian ATMs. The attack on Bangladesh's banking network caused losses of $81 million. And it's logical to assume there will be more incidents of this nature. It makes no sense for cybercriminals to keep stealing individual cards and accounts when an attack on an insecure banking network allows them to empty ATMs at will...

Source: