ATM jackpotting sounds like a movie plot, but it is a real form of cash out fraud. Criminals compromise an ATM and force it to dispense cash without a legitimate customer transaction.
The attack is directed at the machine or the systems that control it. That distinction matters because jackpotting is not the same as stealing one customer’s card details and making an unauthorized withdrawal.
What is ATM jackpotting?
ATM jackpotting is an attack that causes a machine to release cash on command. Threat actors may gain physical access to the ATM, introduce malware, replace or modify components, or compromise systems that manage ATM settings and authorization controls.
In a February 2026 alert, the FBI reported an increase in malware-enabled jackpotting incidents across the United States. The agency said more than 1,900 incidents had been reported since 2020, including more than 700 incidents and over $20 million in losses during 2025.
How does the attack work?
Methods vary, but the FBI described attacks involving access to ATM hardware and the installation of malware that communicates with the machine’s cash dispenser. The malware can bypass the normal transaction flow and instruct the ATM to release cash.
Other large cash-out schemes target web-based control panels or card authorization systems. The FFIEC has warned that criminals may change withdrawal parameters, weaken controls, and coordinate withdrawals across multiple machines.
Why ATMs are attractive targets
An ATM combines cash, a computer, peripheral devices, remote connectivity, and physical access points in one machine. That creates several areas that require protection:
- Cabinet locks, service panels, and cash compartments
- Operating systems, middleware, and vendor applications
- USB ports and other removable media interfaces
- Remote support tools and network connections
- Administrative credentials and web control panels
- Logging, monitoring, and alerting
What should financial institutions review?
The FBI and FFIEC guidance points to a layered approach. Institutions should work with qualified security teams, ATM vendors, processors, and legal or compliance reviewers to assess their specific environment.
Physical controls
Review locks, access procedures, cameras, tamper detection, maintenance schedules, and alerts for unexpected cabinet openings or changes in device state.
System integrity
Maintain verified software baselines, restrict unauthorized applications and hardware, monitor for unexpected files or services, and protect administrative access.
Network and account security
Limit privileged access, use appropriate authentication controls, monitor unusual logins and parameter changes, and segment critical systems based on risk.
Incident readiness
Test response plans with internal teams and third-party providers. A plan should address cash loss, system isolation, evidence preservation, law enforcement reporting, customer communications, and restoration.
What jackpotting means for access strategy
Jackpotting does not make ATMs obsolete. It does show that dedicated cash machines carry a physical and technical security burden that must be managed throughout their life cycle.
Banks evaluating their channel mix can consider where a machine is necessary and where another access model may be appropriate. SPARE’s Virtual ATM uses a participating retailer’s existing POS as the access point instead of placing another standalone cash machine.
That is an infrastructure distinction, not a guarantee against fraud or operational risk. Every financial service requires controls, monitoring, approved procedures, and a clear allocation of responsibilities.
