Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

FBI: $20 Million Losses Caused by 700 ATM Jackpotting Attacks in 2025

The FBI has confirmed that the Ploutus malware, which has been around for over a decade, is still being used in the wild.

ATM jackpotting

A flash alert published on Thursday by the FBI warns of an increase in malware-enabled ATM jackpotting attacks in the United States.

According to the agency, roughly 1,900 ATM jackpotting attacks have been reported since 2020, with more than 700 in 2025 alone. The incidents recorded last year resulted in losses exceeding $20 million.

ATM jackpotting attacks involve physical access to the targeted machine to plant malware that instructs its cash-dispensing module to eject currency. 

The US has cracked down on ATM jackpotting, prosecuting dozens of individuals for various roles in such operations. Many of the suspects targeted by the Justice Department in recent months are Venezuelan nationals and they face deportation. 

US authorities suggest that multiple malware families are used in ATM jackpotting, but the most frequently named is Ploutus.

Ploutus has been around for more than a decade, but it hasn’t been in the news much since its peak in 2017 and 2018, until recently. 

Advertisement. Scroll to continue reading.

A map published last year by the Justice Department showing the locations of jackpotting incidents in the US suggested that Ploutus has remained active.

The FBI’s latest alert confirms that the malware is still widely used. 

“Once Ploutus is installed on an ATM, it gives threat actors direct control over the machine, allowing them to trigger cash withdrawals,” the FBI said. “Ploutus attacks the ATM itself rather than customer accounts, enabling fast cash-out operations that can occur in minutes and are often difficult to detect until after the money is withdrawn.”

“The malware can be used across ATMs of different manufacturers with very little adjustment to the code as the Windows operating system is exploited during the compromise,” the law enforcement agency noted.

The FBI’s alert provides indicators of compromise (IoCs) to help targeted organizations detect attacks, along with recommended mitigations. 

However, it’s worth noting that authorities previously mentioned that the Ploutus malware is designed to autonomously delete traces of its own code to deceive forensic investigators and bank employees.

Related: Ivanti Exploitation Surges as Zero-Day Attacks Traced Back to July 2025

Related: OpenClaw Security Issues Continue as SecureClaw Open Source Tool Debuts

Related: PromptSpy Android Malware Abuses Gemini AI at Runtime for Persistence

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

PNC Financial Services Group has appointed Christian Winward as CISO.

Brian Gumbel has joined Armadin as Chief Revenue Officer.

EigenQ has appointed Mark Pecen as Vice Chairman and Alexander Truskovsky as CISO.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.