
Seven Hundred Jackpotting Attacks Last Year. The Cheapest Tool Was a Key.
In February the FBI's Internet Crime Complaint Center put out a FLASH alert about ATM jackpotting. It is a short document and it does not editorialize, which somehow makes it land harder.
The number in it: roughly 1,900 jackpotting incidents reported since 2020. More than 700 of those happened in 2025 alone, and they accounted for over $20 million in losses.
Read that ratio again. Five years of reporting, and better than a third of it landed in a single year.
What the Attack Actually Is
Jackpotting sounds like something out of a heist film. It is considerably more boring than that, and the boredom is the point.
Someone opens the top of the machine. Not the safe. The upper cabinet, the part that holds the computer, which on a lot of generic terminals is secured by a lock whose key can be bought online for the price of lunch and which opens a very large number of other machines besides yours.
From there it is one of a few plays. Swap the hard drive for one already carrying malware. Plug in a device and load it. In the worst version, compromise a central administrative system and push it out to a fleet.
The malware most often named is the Ploutus family. It works by talking to the XFS layer, the standard software interface between an ATM's computer and its cash dispenser. Instead of asking the bank whether a withdrawal is authorized, it just tells the dispenser to dispense. The machine is not tricked into thinking a transaction happened. The transaction is skipped entirely.
Then a person stands there with a bag until the cassettes are empty. Minutes, not hours.
The whole thing turns on physical access. Everything downstream of that lock is software, and software attacks scale. That is why one compromised key pattern can produce a run of incidents across three states.
The Shape of the Problem Has Changed
For most of this industry's history, ATM crime meant something violent and obvious. A truck and a chain. A pry bar. A hole in a wall.
That is no longer where the volume is.
ATMIA's crime database has logged more than 51,000 reported incidents. In their 2025 U.S. breakdown, jackpotting and cash-out attacks accounted for roughly 72 percent of criminal activity. Skimming and card data compromise made up about 20 percent. Physical attacks were the remainder.
Fraud has overtaken force. The crowbar has been replaced by a USB stick, and the USB stick is a great deal harder to see on a security camera.
Two more things worth putting on your radar.
Cash trapping is showing up in the United States in a way it historically has not. The device is simple: something seated in the dispenser throat that catches the notes on their way out. The cardholder sees a failed transaction and leaves. Someone comes back later and collects. It is low-tech, cheap to deploy, and the only reliable defense is somebody physically looking at the machine on a regular schedule.
And skimming has not gone anywhere. The Secret Service examined close to 60,000 terminals, gas pumps and ATMs in 2025 and put the prevented fraud figure at more than $400 million. That is the number for what got caught.
The Part Operators Get Wrong
The reasonable response to all of this is not alarm. Alarm produces a security audit, a flurry of purchase orders, and then nothing for eighteen months.
The reasonable response is to notice that these attacks are not clever. They are opportunistic. They select for the machine that is easiest to reach, easiest to open, and least likely to be observed.
Which means the question is not whether your fleet is secure in the abstract. It is narrower and more useful than that.
Which of your terminals could someone open, work on for ten minutes, and walk away from without anyone knowing?
Almost every operator can answer that immediately. It is usually the same handful of machines. The unattended one at the back of a mall corridor. The one at a 24-hour fuel stop where the clerk cannot see the lobby. The one at the location that stopped answering your calls two years ago.
You already know which ones they are. That is the encouraging part.
Here's the Move
Three things, in the order they pay off.
Change the locks on the machines you just thought of. Not all of them. Those. Generic upper-cabinet keys are the single cheapest attack surface in this business and the single cheapest one to close.
Second, make sure something is watching that is not a person. A terminal that comes offline unexpectedly, reboots at three in the morning, or throws a dispenser fault at a location with no traffic is telling you something. On most fleets nobody hears it until the settlement is short. Continuous monitoring with an actual response behind it is what turns that signal into a phone call instead of a footnote. That is what Watchdog is for, and it is worth being precise about the claim: it does not make a machine unbreakable. It makes a machine that cannot be worked on quietly.
Third, put eyes on the dispenser. Cash trapping is defeated by inspection and essentially nothing else. Build it into the cash run. It costs a few seconds per visit.
None of that is a project. It is a Tuesday.
The operators who get hit are rarely the ones who were targeted. They are the ones who were available.
If you want a straight read on where your fleet is exposed, book a demo at clearchoicepay.com/book-demo. Bring your terminal list. We will start with the ones you already suspect.
Sources: FBI IC3 FLASH alert FLASH-20260219-001, February 19, 2026; ATMIA Crisis & Crime Management Intelligence System, 2025; U.S. Secret Service, 2025 skimming operations.