Cyber criminals are increasingly accessing ATM machines through the banks’ networks, with squads of money mules standing by ready to pick up the stolen cash, Europe’s policing agency warned Tuesday.
“The malware being used has evolved significantly and the scope and scale of the attacks have grown proportionately,” said Steven Wilson, who head’s Europol’s EC3 cyber crime centre.
Previously criminals used physical ‘skimming’ devices or USB sticks or CDs to install malware within ATMs but since 2015 “a new and unnerving trend… has been picking up speed,” Europol said in a 40-page report on the latest ATM crime trends.
“The criminals have realised that not only can ATMs be physically attacked, but it is also very possible for these machines to be accessed through the (bank’s) network,” the report said, which was published in conjunction with the Trend Micro security software company.
One of the tricks used by hackers is to send a so-called phishing email to bank employees which once opened, contains software to penetrate the bank’s internal computer network.
Once the ATM has been targeted and told to dispense the money “standby money ‘mules’ will pick up the cash and go.”
Europol warned that incidents of ATM targeting is likely to rise in the future.
“In the past, banks might have thought that network segregation was enough to keep their ATM networks safe from cyber crooks,” Europol said.
“This is no longer the case.”
The policing agency also said that “financial organisations need to take more steps to secure their ATM installations by deploying more security layers.”
In addition to a public report, Europol is also giving out a private report providing details to institutions to firm up their security against ATM piracy.
Related: New Ploutus ATM Malware Variant at Large
Related: Malware Allows Remote Administration of ATMs
Related: ATM Thief Sent to Prison for Stealing Nearly $1 Million

More from AFP
- Cyberattacks Target Websites of German Airports, Admin
- Meta Slapped With 5.5 Million Euro Fine for EU Data Breach
- International Arrests Over ‘Criminal’ Crypto Exchange
- France Regulator Raps Apple Over App Store Ads
- More Political Storms for TikTok After US Government Ban
- Meta Hit With 390 Million Euro Fine Over EU Data Breaches
- Facebook Agrees to Pay $725 Million to Settle Privacy Suit
- China’s ByteDance Admits Using TikTok Data to Track Journalists
Latest News
- Critical Vulnerability Impacts Over 120 Lexmark Printers
- BIND Updates Patch High-Severity, Remotely Exploitable DoS Flaws
- Industry Reactions to Hive Ransomware Takedown: Feedback Friday
- Microsoft Urges Customers to Patch Exchange Servers
- Iranian APT Leaks Data From Saudi Arabia Government Under New Persona
- US Reiterates $10 Million Reward Offer After Disruption of Hive Ransomware
- Cyberattacks Target Websites of German Airports, Admin
- US Infiltrates Big Ransomware Gang: ‘We Hacked the Hackers’
