A new crime wave is hitting automated teller machines (ATMs); the common banking appliances are being rigged to spit out their entire cash supplies into a criminal’s waiting hands.

The crime is called “ATM jackpotting” and has targeted banking machines located in grocery shops, pharmacies and other locations in Taiwan, Europe, Latin America and, in the last several months, the United States. Rough estimates place the total amount of global losses at up to $60 million.

What is jackpotting?

ATM jackpotting is a combination of a physical crime and a cyberattack. Typically, a criminal with a fake ID enters a grocery shop or pharmacy posing as an ATM technician, then uses a crowbar to open the top of the ATM – the “top hat” – to gain access to the personal computer that operates the machine.

If a legitimate customer approaches the machine in the meantime, it can operate as usual until activated otherwise by the malware

Once he or she has access to the PC, they remove the hard drive, disable any anti-virus software, install a malware program, replace the hard drive and then reboot the computer. The whole operation takes about 30 seconds. The malware then enables the thief to remotely control the ATM and direct it to dispense all its cash on command.

An accomplice – the “mule” – later approaches the ATM to collect the bounty, as the “technician” remotely directs the machine to dispense all its cash. If a legitimate customer approaches the machine in the meantime, it can operate as usual until activated otherwise by the malware.

ATMs in supermarkets and pharmacies tend to be targeted because they may not be as well-protected, and store personnel likely would not know who is authorised to work on the ATM. In contrast, anyone approaching an ATM at a bank location would be more likely to be challenged.

Emergence of criminal activity

The crime first emerged in the United States several months ago, and the U.S. Secret Service, financial institutions and ATM manufacturers have been scrambling to find a solution. Older ATMs are particularly vulnerable.

In some cases, financial institutions have not embraced the highest levels of security offered by ATM manufacturers because of costs, and because previously the crime was not common in the U.S. One estimate is that losses north of $10 million have occurred in the U.S. just in the last couple of months.

There are solutions, and then there are ways to get around the solutions,” says Samir Agarwal, Accelerite’s general manager for security.

ATM jackpotting originated back in 2010 when Barnaby Jack, a New Zealand hacker and computer expert, demonstrated how he could exploit two ATMs
Hackers remove the hard drive, disable any anti-virus software, install a malware program, replace the hard drive and then reboot the computer

ATM protection technology

Accelerite is a California-based software company that focuses on the digital enterprise, including hybrid cloud infrastructure, endpoint security, Big Data analytics, and the Internet of Things. Accelerite’s solution to the ATM jackpotting problem is built on the company’s Sentient security framework.

Accelerite’s approach to ATM jackpotting is to immediately stop the dispensing of cash when any sign of trouble is detected. The system can track alarms, such as when a “top hat” is opened, when a hard disk is removed, if the antivirus software has been tampered with, and so on.

The system can send a notification within 20 seconds that the ATM is being hacked and then automatically shut down the machine. If the bad guy reboots the machine, the system can confirm there was a previous alert and shut it down over and over.

We create multiple lines of defense,” says Agarwal. “The criminal would decide it’s not worth his while and walk away.”

The consequences of jackpotting impact every level of the industry, including ATM manufacturers and financial institutions

Origins of ATM jackpotting

ATM jackpotting originated back in 2010 when Barnaby Jack, a New Zealand hacker and computer expert, demonstrated how he could exploit two ATMs and make them dispense cash on the stage at the Black Hat computer security conference in Las Vegas. Since then, malware has been created and made available on the “Dark Web” that can instruct an ATM to dispense all its cash on demand.

Previously ATM jackpotting attacks have focused on more cost-conscious global markets and those likely to use older-model ATMs with fewer security features. Strong U.S. law enforcement also likely prevented criminals from taking the risk – until now. Attacks in the United States have raised awareness.

There is more cognisance of the possibility of bad things happening,” says Agarwal. “This came out of nowhere and had not happened in the past in the United States. This crime is unlike what you hear about hacks or when data is stolen – there’s just money being stolen.”

Best practices to prevent an attack

However, the consequences impact every level of the industry, including ATM manufacturers and financial institutions. Also, the supermarket and grocery shops that are targeted face additional security challenges, and even consumers could lose confidence in ATMs if they think their personal information could be at risk.

There are best practices that can also prevent an attack. For example, an ATM computer could have a “white list” of approved applications and not allow anything to be installed that is not on the list; for instance, no malware. Another approach is to encrypt the disk drive so that a key or certificate is needed in order to install new software.

Agarwal notes that solving the challenge of ATM jackpotting illustrates the need to combine both physical and cybersecurity approaches to protect modern companies.

It’s the reality as we move into a more digital world,” he says. “Physical security at that level will be difficult to protect, and you will be depending more on cyber solutions. It’s the direction the world is moving into.

Download PDF version

Author profile

Larry Anderson Editor, SourceSecurity.com

An experienced journalist and long-time presence in the US security industry, Larry is SourceSecurity.com's eyes and ears in the fast-changing security marketplace, attending industry and corporate events, interviewing security leaders and contributing original editorial content to the site. He leads SourceSecurity.com's team of dedicated editorial and content professionals, guiding the "editorial roadmap" to ensure the site provides the most relevant content for security professionals.

In case you missed it

IFSEC International 2018 highlights solutions approach and open systems
IFSEC International 2018 highlights solutions approach and open systems

IFSEC International 2018 kicked off last week at London’s ExCel Centre. Visitors were lucky enough to experience a rare three days of British sunshine as they came together to discuss the latest trends and technologies in the physical security industry. Many exhibitors commented on how the show seemed smaller than previous years, with stands more spread out, and fewer ‘double-decker’ offerings than earlier shows. Although exhibitors represented all aspects of physical security, including access control and intrusion detection, the show was largely dominated by video surveillance. Video manufacturers Avigilon and Dahua were key sponsors, while the largest stand by far was occupied by Hikvision. Rather than hosting large product portfolios, exhibitors chose to demonstrate how integrated solutions could provide a more holistic solution If stands seemed more modest than in previous years, this may be a reflection of the industry shifting away from its long-standing product focus. Displaying large product portfolios takes more exhibit space. In an increasingly commoditised market, security integrators are combatting price erosion by emphasising holistic solutions rather than products and features. While some manufacturers have responded by collaborating with partners to offer a broader portfolio of solutions, others have invested in building end-to-end systems. Both these trends were reflected at the show; rather than hosting large product portfolios with a wide range of features, exhibitors chose to demonstrate how integrated solutions could provide a more holistic solution to end users’ challenges. Integrated systems approach One manufacturer opting for a solutions focus was door entry systems provider STANLEY Product and Technology. The stand was represented by a range of STANLEY brands including PACOM and PAC GDX, as well as technology from existing partner 3xLOGIC. The PACOM team was on hand to demonstrate integrations of PACOM’s Graphical Management System (GMS) with workflow management software from RightCrowd, and biometric authentication products from EyeLock. PACOM Systems’ Commercial Director Gary Rowden explained that the stand was designed specifically to showcase all of STANLEY’s brands and partners in one place, encouraging customers to buy into the STANLEY solutions approach, rather than focusing on specific products. The show was largely dominated by video surveillance, with video manufacturer Avigilon a key sponsor Connecting with partners Another company emphasising partner solutions was Milestone Systems. Milestone’s Vice President for EMEA, Malou Mousten Dyhr Toft, who joined the company in March, explained how IFSEC International continues to be a key show. It was an opportunity to meet with Milestone’s expansive community of existing partners, as well as connecting with new partners and end users. Milestone hopes to enable community customers to process more video data with fewer servers, increasing scalabilityIn February this year, the company launched the Milestone System Builder initiative, allowing partners to optimise their hardware to pre-load Milestone’s XProtect VMS software. Several system builder partners were present at the Milestone stand. By collaborating with NVIDIA, Milestone hopes to enable community customers to process more video data with fewer servers, increasing scalability and reducing the total cost of ownership of its partner solutions. The stand showcased Milestone’s latest XProtect 2018 R2 VMS that leverages NVIDIA’s high-powered graphics processing units (GPUs), which can handle up to 2,000 video streams on one single server. Commitment to open systems MOBOTIX took this year’s IFSEC International as an opportunity to spread the word about its increased commitment to open systems. Since the company’s majority acquisition by Konica Minolta in 2016, and the subsequent addition of CEO Thomas Lausten last year, the company has undergone a significant change in approach, all-the-while guarding its core decentralised IP video product offering and made-in-Germany DNA. Lausten was previously a key figure at Milestone Systems and has brought to MOBOTIX a new approach focused on collaboration. Partners present at the MOBOTIX stand included Milestone, Kentix and Wavestore. The company also demonstrated its commitment to open systems by unveiling MOBOTIX MOVE, the manufacturer’s first line of ONVIF G compliant cameras. Visitors were lucky enough to experience a rare three days of British sunshine at IFSEC International this year Security system provider Vanderbilt had many new developments on show, including integrations both within Vanderbilt systems and with partner systems. The company’s SPC intrusion detection system now integrates with Milestone software, allowing SPC users to trigger events and control alarm systems from within the Milestone platform. A further highlight was Vanderbilt’s ACTEnterprise access control system, which now integrates with ASSA ABLOY’s Aperio wireless locking solution. Vanderbilt hopes that the integration will provide customers with faster, more cost-effective access control installations.Vanderbilt hopes that the integration will provide customers with faster, more cost-effective access control installations Reducing costs, increasing ease-of-use Many exhibitors were keen to demonstrate how integrated solutions could reduce costs for integrators by unifying systems on one easy-to-use platform. Arecont Vision unveiled its new Contera cloud-based video management solution at ISC West in April, making IFSEC the technology’s first outing in the European market. Contera is Arecont’s first video management offering and will allow customers to benefit from end-to-end solutions from the US-based company. Since the Contera system is designed to be web-based from the start, integrators will not be faced with the additional cost of adapting a legacy VMS system to the cloud. IDIS was another manufacturer highlighting their enhanced user experience and reduced cost offered by end-to-end systems. Visitors experienced demonstrations of the IDIS Center video management software, which is designed to offer smart user experience controls, and a user-friendly interface. Also on display were the company’s latest ranges of analogue and IP cameras. The IDIS system allows users to ‘mix-and-match’ HD analogue and IP video depending on the requirements of the project, with all surveillance operated from the same IDIS software interface. The mix-and-match approach avoids the additional cost of unnecessarily ripping and replacing legacy analogue systems. IFSEC 2018 presented a snapshot of how manufacturers from across video, access control and intrusion detection are continuing to innovate and collaborate to stay competitive in an increasingly challenging market, without losing sight of the most pressing needs of end users and integrators.

Ensuring smart home security and automation with consumer radar technology
Ensuring smart home security and automation with consumer radar technology

In the state of the residential security market today, we see many who are offering home security packages that rely on numerous sensors and multiple devices to provide a comprehensive coverage of the home and provide peace of mind. Each individual sensor or device within the package provides a specific functionality, and the user finds himself burdened by an overwhelming amount of sensors and devices. This overload is intensified by the penetration of additional IoT and smart devices into the home, such as pet-cams or smart speakers that add to the burden of installation and maintenance. In addition, we are witnessing the rise in popularity of DIY security devices, indicating that users are looking for models and technologies that provide both contract flexibility and simplicity of use. The past years have seen major advancements in radar technology, which have brought the formerly military technology into the consumer space. Radars provide interesting prospects for home security and smart homes due to several inherent characteristics which give it an advantage over existing technologies. The resolution of an advanced radar sensor enables not only presence detection, but also provides advanced features for security, automation and well-being Advanced security and automation features Of primary importance, a consumer designed radar sensor provides the user with full privacy, but the use of radar is also beneficial because it is indifferent to environmental, temperature and lighting conditions. In addition, radar signals (at certain frequencies) are capable of penetrating through almost any type of material, enabling concealed installation, robust monitoring in cluttered spaces and even the coverage of several separate rooms with only one device. In terms of capabilities, simple time of flight 2-antenna radar sensors, which have been around for a while, do not provide much additional value in comparison to existing solutions and are not necessarily competitive in terms of pricing. However, the new generation of radar sensors are also opening up new capabilities previously achieved with optics only. Today, the resolution of an advanced radar sensor is high enough to enable not only presence detection, but also to provide advanced features for security, automation and well-being, all in one. Imagine for example, that the security sensor installed in your elderly parent’s home could also detect a fall having occurred, monitor the breathing of a baby or even leaks in your wall. Due to the unique field of view that radar provides as well as the multi-functional potential, this technology will be the key to the awaited convergence of smart home functionalities and minimisation of home devices. Using AI and machine learning, the data derived by radar sensors can be leveraged to provide smarter, verified alerts Secret of the consumer radar A radar sensor’s accuracy and its ability to support wide functionality and applications is determined initially by its resolution, which is based on two key factors: bandwidth and number of channels. The wider the bandwidth and the more channels the radar supports, the more accurate the data received. Imagine the difference between a 1990s television model and a 4K 2018 television model - As the resolution is ever improving, the sharper and more detailed is the image. When looking at the short-range radar sensor market, prominent companies such as Texas Instruments and NXP are offering radar-on-chip solutions supporting 2\3 transmitters (Tx) and 3\4 receivers (Rx), mainly utilising frequency bands of 77-81GHz, as they target mostly automotive and autonomous driving applications. Another company that develops such radar-on-chip solution is Vayyar Imaging, an Israeli start-up, founded in 2011, that developed a radar sensor for 3D imaging. Vayyar Imaging directly targets the smart home and security markets with its radar-on-chip, developing modules and products for intruder detection, automation and elderly care (fall detection). Providing not only chips, but complete systems, the new model makes radar technology highly available and accessible. The radar-on-chip technology opens the door to installation of security and well-being devices in locations where privacy or environmental conditions pose an issue Radar-on-chip solution The radar-on-chip solution supports 72 full transceivers, an integrated DSP and radar bands between 3-81GHz. The resolution provided by this type of specification is high enough to provide subtle information about people’s real time location posture (lying down\falling\sitting\walking), and breathing, and enables to classify pets from humans, but it is low enough as to not compromise privacy. This type of technology opens the door to installation of security and well-being devices in locations where privacy or environmental conditions pose an issue, such as in bathrooms or heavily lit environments. Moreover, utilisation of this technology allows to dramatically minimise the numbers of sensors installed in the home, as it provides full home coverage with just one or two sensors and enables using the same HW to support additional capabilities such as breath monitoring, fall detection and highly accurate automation. Using AI and machine learning, the data derived by these sensors can be leveraged to provide smarter, verified alerts on the one hand and whole new insights on the on the other. The sensor can be tuned to learn the location of the house entrances or boundaries, where the inhabitants are expected to be at night, or where they should be expected to enter from into the home, adding new logics to the traditional yes\no decision making. Home security is widely regarded as a necessity, provides peace of mind to people and is integral to people's day to day lives Additional smart home services Among the evolving home technology verticals, security is by far the most relevant and integral to people’s day to day lives. Home security is widely regarded as a necessity and provides peace of mind to people. Being a legacy industry with many well-known and well-trusted brands, security players are well positioned to introduce new technology into the home and have the ability and credibility to expand their offerings to additional smart home services by utilising existing infrastructure and channels. With technology giants entering the security arena through the smart home door the DIY security solution market expected to explode with a CAGR of 22.4% (according to a report by Persistence Market Research). Now that new pricing and service models offer minimal commitment, traditional security players will need to step up. Security companies will need to expand their offering, provide new value or higher flexibility if they intend to stay relevant and competitive. It will be imperative to utilise new technologies that offer unique capabilities and fit in to market where the trends of functionality converge with the need for minimising maintenance and installation costs.

2018 FIFA World Cup Russia integrates safety, security and service
2018 FIFA World Cup Russia integrates safety, security and service

The 2018 FIFA World Cup tournament is bringing 32 national teams and more than 400,000 foreign football fans from all over the world to 12 venues in 11 cities in Russia. Fans are crowding into cities including Moscow, St. Petersburg and Kazan. Given continuing global concerns about terrorism, security is top-of-mind. Protection of the World Cup games in Russia is focusing on an “integrated safety, security and service approach,” according to officials. Combining the term “security” with the terms “safety” and “service” is not an accident. An aggressive security stance is necessary, but at the end of the day, fan safety is paramount, and a service-oriented approach ensures a positive fan experience. Medical responders will be working side-by-side with police and antiterrorism personnel. Risk management best practices We asked Sean T. Horner and Ben Joelson, directors of the Chertoff Group, a global advisory firm focused on best practices in security and risk management, to comment on security at FIFA World Cup 2018. Although not involved in securing the 2018 World Cup, the Chertoff Group is experienced at securing large events and enterprises using risk management, business practices and security. Integration is another important aspect of protecting the games, says Horner. The use of multiple resources, including Russian military, intelligence and law enforcement, will be closely integrated to provide the best security for the large-scale event in each of the host cities, he says. The approach will be centralised and flexible, with resource deployment guided by effective situational awareness. Primary security and emergency operations centres will be dispersed throughout each host city “There is a unified command structure at the Russian Federation level, and they will keep resources in reserve and shift them as needed to various events and venues based on any specific intelligence, in effect deploying resources where threats are greatest,” says Joelson. “There will also be some regional commands, and resources will incorporate a spectrum of police and military personnel ranging from the ‘cop on the beat’ to the Spetsnaz, the Russian ‘special forces'.” Primary security and emergency operations centres will be dispersed throughout each host city, and additional forces can be shifted as necessary, he notes. Role of law enforcement In Russia, the lines of separation between law enforcement and the military are not as stark as in the United States, for example, where military forces are restricted from deployment for domestic law enforcement by the Posse Comitatus Act. In Russia, there is no such restriction.  A broad range of technology will play a role at the World Cup, Horner and Joelson agree. Technology will be used primarily as a force multiplier and a decision-support tool for security personnel. There are robust CCTV systems in many Russian cities, and mobile CCTV systems, such as camera towers or mobile security centres on wheels, will also be deployed. Technologies will include infrared cameras, flood lights, and ferromagnetic screening systems to scan hundreds of individuals as they walk by. In some locations, facial recognition systems will be used, tied into various intelligence, military and law enforcement databases of known bad actors. Behaviour analytics will be used as a decision-support tool. In addition to security in public areas, private CCTV systems in hotels, at transportation hubs, and inside the venues themselves will be leveraged. Video analytics and detection will help personnel review live view of people who may be acting suspiciously or who leave a bag unattended. In some locations, facial recognition systems will be used, tied into various intelligence, military and law enforcement databases of known bad actors Rigorous anti-terrorism measures A Fan ID card is required to enter the 2018 World Cup Tournament, even for Russian residents. The Russians have an aggressive stance against domestic terrorism, which will also help ensure the safety of the World Cup games, say Horner and Joelson. Terrorist group ISIS has promised “unprecedented violence” at the games, but they make similar threats at every major global event. Russia has been an active force disrupting ISIS in Syria, and experts suggest that losing ground geographically could lead to addition “asymmetric” terrorist attacks. However, Russia is leveraging all their intelligence resources to identify any plots and deploying their security apparatus to disrupt any planned attacks, experts say. Russia’s rigorous anti-terrorism measures include a total ban on planes and other flying devices (such as drones) around the stadiums hosting the World Cup. Private security In addition to military, intelligence and law enforcement personnel, private security will play a have a high profile during the 2018 World Cup in Russia. Private security personnel will be on the front lines in hotels and in “fan zones.” They will operate magnetometers at entrances, perform bag checks, enforce restrictions on hand-carried items, etc. Private security will be especially important to the “guest experience” aspects of protecting the games. Private security will be especially important to the “guest experience” aspects of protecting the games Another private security function at the World Cup is executive protection of dignitaries and high-net-worth individuals who will be attending. Executive protection professionals will arrive early, conduct advanced security assessments before VIPs arrive, and secure trusted and vetted transportation (including armoured cars in some cases.) VIPs will include both Russian citizens and foreign (including U.S.) dignitaries attending the games. Private security details will be out in force. Aggressive security approach Overeager and outspoken fans are a part of the football culture, but Russia will deploy a near-zero tolerance policy against hooliganism and riots. An overwhelming force presence will take an aggressive approach to curbing any civil disturbances, and offenders will be removed quickly by Russian security forces. Strict restrictions on the sale and consumption of alcohol will be enforced in the venue cities before and after the matches. Officials will also be cognisant of the possibility of a riot or other event being used as a distraction to draw attention from another area where a terrorist event is planned. It will be a delicate balance between deploying an aggressive security approach and preserving the fan experience. Joelson notes that freedom of speech is not as valued in Russia as in other parts of the world, so the scales will be even more tipped toward security. “The last thing they want is for things to get out of control,” says Horner. “The event is putting Russia on the world stage, and they want visitors to walk away safely after having a great time and wanting to go back in the future.” Attendees should also have good situational awareness, and keep their heads up, scanning crowds and identifying unsafe situations" Precautions for World Cup attendees Attendees to the World Cup in Russia should take some basic precautions, Horner and Joelson agree. For example, Russia requires a translated, notarised letter explaining any prescription drugs. The country has a more aggressive foreign intelligence environment, so visitors cannot depend on their data being private. Joelson recommends the usual “social media hygiene” and privacy settings. Visitors should not post information about their travel plans or locations, and it’s best to travel with a disposable mobile phone that does not contain personal information. Location tracking should be deactivated. Travellers should also beware of talking and sharing information with others, or of saying anything derogatory. “They should also have good situational awareness, and keep their heads up, scanning crowds and identifying unsafe situations,” says Joelson. “If you bring a personal electronic device, you should expect that it has been compromised,” says Horner. Text messages and email will not be private, and he suggests creating an email address used only for travel. Don’t leave drinks unattended. Travellers from the U.S. should register at the Smart Traveler Enrollment Program (STEP) operated by the U.S. State Department. “Plan before you travel and before you get to the airport,” says Horner.