P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

$40.73M over 1,500+ ATM attacks is at most about $27,000 each, and the charged route starts at the cabinet door

Treasury's $40.73 million over more than 1,500 alleged ATM attacks averages at most about $27,000 each. The charging papers describe a burglary first and malware third, and the man alleged to have written the malware pleaded not guilty on 2 October.

By Parminder Kumar Sharma · · 21 min read

A free-standing cash machine at night in a dark shopfront, seen from a low three-quarter angle: its screen lit with blank rounded pills and the large hinged service panel on its upper cabinet shut and locked with a small round lock. The left side of the picture is empty darkness carrying the headline.

The number, and what it does not say

Treasury's press release of 30 September 2026 puts reported losses from alleged ATM jackpotting attacks in the United States at $40.73 million across more than 1,500 attacks, as of August 2025. Divide one by the other and the answer is $27,153. Because the count is "more than" 1,500, that is a ceiling: the average attack took at most about $27,000 (derived). It is a plainer picture than the "over $100,000 per incident" that one report printed.

Three official averages, derived by us from three official documents. The arithmetic is in the fact check.

  1. Document and what it counts
    Treasury press release, 30 Sep 2026: reported losses from alleged US attacks, as of August 2025
    Figures it states
    $40.73 million over more than 1,500 attacks
    Average per attack (derived)
    At most $27,153
  2. Document and what it counts
    FBI FLASH, 19 Feb 2026: incidents in 2025 alone
    Figures it states
    More than $20 million over more than 700 incidents
    Average per attack (derived)
    About $28,600, if both are minimums
  3. Document and what it counts
    Nebraska indictment, 9 Dec 2025: charged attacks, committed or attempted
    Figures it states
    At least $5,401,181 over at least 117 attacks (63 bank, 54 credit union)
    Average per attack (derived)
    About $46,200

The indictment says losses at an attack were "sometimes well in excess of $100,000". DOJ's 20 February release says "in excess of $100,000 per jackpotting attempt". Neither supports $100,000 as an average. If all 117 charged attacks had passed $100,000, the total would exceed $11.7 million, more than twice the $5.4 million the indictment charges. The four attacks the indictment lists against the man now in custody are about $19,000, $29,280 and $79,200 taken, and one attempt for $199,466. BleepingComputer's 5 October report puts "surpassed $100,000 per incident" in the same sentence as $5.4 million over 63 bank and 54 credit union attacks, which joins two statements the indictment keeps apart.

What the number does not establish.

  • It does not say the losses are all Ploutus. Treasury states the figure as losses from "alleged ATM jackpotting attacks in the United States", in a paragraph about Tren de Aragua. The FBI says its incidents include "the Ploutus family". No source splits the total by malware.
  • It does not say the losses are all one group's. Treasury's sentence is about alleged attacks "in the United States". The same "as of August 2025" wording sits under a DOJ map of alleged incidents published on 18 December 2025, an image we could not read, so that map is our inference for the source. TRM Labs and BleepingComputer restate the figure as the gang's total. Treasury's sentence does not.
  • It is not current. "As of August 2025" is 13 to 14 months before the sanctions (derived).
  • It does not say each machine held about $27,000. The average may mix in partial and failed attempts, since the sources do not say whether the 1,500 count includes them, and the indictment separates a further $1,429,738 of attempted loss from the $5,401,181 it counts as lost.
  • It does not say the man arrested on 2 October wrote the malware. That is an allegation, and the next sections show exactly how it is worded.

What happened, with dates

Two linked items, and the dates matter because the coverage blurred them. OFAC acted on 30 September. The DOJ announced the apprehension in a release dated Friday 2 October. BleepingComputer's sanctions report is dated 2 October and its arrest report 5 October, which is reporting the Friday release as news. The OFAC entry dated 2 October is an unrelated action against a different group.

Timeline from the primary documents.

  1. Date
    9 Dec 2025
    What the document says
    A Nebraska grand jury indictment names 22 defendants on four conspiracy counts, including the man now in custody. It alleges at least 117 attacks and at least $5,401,181 of loss.
    Document
    Indictment 8:25-cr-00242, Doc 5
  2. Date
    19 Feb 2026
    What the document says
    FBI FLASH: more than 700 incidents and more than $20 million in 2025, 1,900 incidents since 2020, with indicators and mitigations.
    Document
    FBI FLASH-20260219-001
  3. Date
    March 2026
    What the document says
    Added to the FBI Ten Most Wanted Fugitives list: the first cyber fugitive and the 540th person listed.
    Document
    DOJ release 26-1135
  4. Date
    30 Sep 2026
    What the document says
    OFAC designates 10 targets in the ATM scheme and one more Tren de Aragua leader, and lists seven addresses on the TRON cryptocurrency network.
    Document
    Treasury sb0640; OFAC recent action
  5. Date
    2 Oct 2026
    What the document says
    DOJ announces the apprehension. Initial appearance the same day before a magistrate judge, not guilty pleas, detained pending trial.
    Document
    DOJ release 26-1135

Eight, ten or eleven? The sanctions coverage gave different counts, each for a reason. OFAC's own first sentence says it "designated 10 targets involved in a Tren de Aragua (TdA) fraud scheme". Its list entry adds one more name the same day.

How the counts reconcile, from Treasury's press release and OFAC's list entry of 30 September 2026.

  1. Count
    8
    What it counts
    Individuals designated for the ATM scheme: the alleged developer, six alleged associates and one more person. This is BleepingComputer's "eight members".
    Where
    Treasury sb0640
  2. Count
    2
    What it counts
    Mexico-based companies, each owned by one of the designated individuals.
    Where
    Treasury sb0640
  3. Count
    10
    What it counts
    OFAC's own count of targets in the ATM scheme, 8 plus 2. This is the figure in OFAC's first sentence.
    Where
    Treasury sb0640
  4. Count
    11
    What it counts
    Names added to OFAC's Specially Designated Nationals (SDN) list that day: 9 individuals and 2 entities. The ninth individual is a Tren de Aragua leader linked to gold mining and narcotics, designated separately.
    Where
    OFAC recent action, 30 Sep 2026
  5. Count
    7
    What it counts
    TRON addresses added, one attached to each of seven of the eight individuals.
    Where
    OFAC list entry; TRM Labs

Counting defendants. Treasury and BleepingComputer say 98 people have been indicted since October 2025. That figure matches DOJ's 26 June 2026 release, which counts 96 other defendants plus the two it sentenced. DOJ's own 2 October release says 120 defendants have been charged in the District of Nebraska to date, three of them sentenced. We use 120, dated 2 October. Neither figure says how many are in custody.

What the arrest does and does not establish

An arrest is a custody fact. DOJ's release ends with the sentence "An indictment is merely an allegation", and says the defendants are "presumed innocent until proven guilty beyond a reasonable doubt". Everything about the man in custody below is an allegation, not a finding. We do not print his name or alias, or those of the other designated people. Roles are enough to follow the argument, and the primary documents carry the names.

The DOJ release of 2 October 2026 and the indictment, claim by claim. Position at 17:08 BST on 5 October 2026.

  1. Topic
    Custody
    Stated
    Apprehension announced. Initial appearance on 2 October before a US magistrate judge, not guilty pleas, to remain detained in the District of Nebraska pending trial.
    Not stated
    When and where he was taken, whether he was extradited, or a trial date. The release thanks DOJ's attaché in Bogotá and its Office of International Affairs. That is thanks, not a location.
  2. Topic
    Charges
    Stated
    Four conspiracy counts: bank fraud (30 years maximum), bank burglary and fraud in connection with computers (5), money laundering (20), material support to terrorists (15).
    Not stated
    Any count for writing or selling malware. The support count cites section 2339A, which lists damage to a protected computer as the offence being supported.
  3. Topic
    Role
    Stated
    "Alleged to be the developer of the Ploutus malware and one of the principal leaders" of the conspiracy (DOJ). Treasury: "alleged engineer of the malware".
    Not stated
    In the indictment text we read, the word developer does not appear. It places him in four attacks between October 2024 and March 2025. The family is far older than the case: Kaspersky dates the first public sample to 24 October 2013, and DOJ's January release says this conspiracy "developed and deployed a variant".
  4. Topic
    Scale
    Stated
    120 defendants charged in the District of Nebraska to date, three sentenced. Attacks or attempts in 47 states, the District of Columbia and several foreign nations.
    Not stated
    How many are in custody, how many machines were opened, or which losses attach to him.
  5. Topic
    Sanctions link
    Stated
    OFAC sanctioned him on 30 September, two days before the court appearance (derived).
    Not stated
    That the arrest followed from, or was timed to, the sanctions.

Our earlier briefing on the ShinyHunters arrest found a first official record of 105 words, with the detail arriving a day later. Here the record is fuller, because the indictment is public, and reading it against the release shows the gap: the release names a role, while the indictment names conduct.

How the machine is entered, in the documents' own words

At defender level the primary documents agree on the shape of the attack. Someone reaches the machine, opens it, gets code onto its computer, triggers a dispense and removes the trace. We stop there: no method detail, no tooling, no steps.

A five step chain from the Nebraska indictment and DOJ releases: survey the machine, open the hood or door with generic keys, load code by swapping or connecting a drive, activate remotely and dispense, delete the malware. Under each step sit the controls the FBI, NCR Atleos, Indiana DFI and the UK ATM Security Working Group list.
Drawn from the Nebraska indictment (paragraphs 13 to 16), DOJ releases of 18 December 2025, 26 January and 2 October 2026, the FBI FLASH of 19 February 2026, NCR Atleos, Indiana DFI Advisory 2025-04 and the ATMSWG guidelines of July 2019.
  • The indictment: members "typically" gain physical access, remove the storage device, put code on it and put it back. They check beforehand for a silent hood alarm. The malware has a file that deletes it afterwards.
  • The FBI: access is "most often" gained by opening the ATM face with widely available generic keys.
  • DOJ, 26 January: crews open the hood or door and then "wait nearby" to see whether they triggered an alarm or a law enforcement response.
  • NCR Atleos, in two undated alerts: "These attacks require physical access inside the ATM." One successful attack hit a drive-up machine that "has the common NCR Atleos top box key" and had not been given all the maker's protections.

What the documents do not say. None describes an entirely remote entry. Indiana's regulator lists "installing malware via USB or network access" as one category, but the charging documents and the FBI describe hands on the machine, and Treasury's phrase "activated remotely" refers to the step after the code is already there. Nor does any of them say how many machines were opened, found hardened enough, and left alone. The counts are of attacks that were reported.

The friendly name: ATM malware is a burglary with a payload

"ATM malware" and "jackpotting" sound like a software problem with a software answer, antivirus and patching. The charging papers read differently. One count against the man in custody is conspiracy to commit bank burglary and fraud in connection with computers. The two defendants sentenced in June pleaded guilty to conspiracy to commit bank burglary and to computer fraud and intentional damage to a protected computer, after Lincoln police arrested them at the site of a jackpotting in October 2024.

The control surface follows the crime. The FBI's physical indicators start at the door: door-open alerts outside planned maintenance, low or no cash outside the refill schedule, unauthorised devices plugged in, hard drives removed. Its mitigations begin with locks, alarms and sensors. Antivirus appears only under endpoint protection, next to allowlisting, and the FBI calls routine comparison against a verified "gold image" one of the most effective defences. NCR Atleos says that "Missing any single step can render an ATM vulnerable to jackpot attack", which is the language of a chain and not of a product.

The label cuts the other way too. If the allegation is proved, one source of code is gone. The Ploutus family has been public since 2013, and the FBI's list is aimed at any code that reaches a machine this way. Nothing in an arrest changes who holds the keys to your cabinets or how long an alarm takes to bring a person to the machine.

The money: what the sanctions structure shows

Treasury says proceeds were "transferred within TdA among members and associates" to conceal their origin, and that the network it designated "uses cryptocurrency transactions" among other methods. The seven TRON addresses on the list are the only on-chain evidence in the public record, and the only description of what they carried comes from a vendor.

A structure drawn from the Treasury press release and OFAC list entry of 30 September 2026. Tren de Aragua sits at the top. Below it, the 10 designated targets in the ATM scheme: 8 individuals and 2 Mexico-based companies, with 7 TRON addresses. Treasury's account of the money sits on the left and TRM Labs' on-chain measurements on the right, including about $6.1 million of inflows. One further leader was designated separately.
Drawn from Treasury press release sb0640, OFAC's list entry of 30 September 2026 and TRM Labs. Names are left out on purpose.

TRM Labs, a blockchain analytics firm, measured about $6.1 million of total inflows to the seven addresses since March 2022, about $2.1 million of it at the largest. All seven are deposit addresses hosted at a centralised exchange, most dormant for months, the latest inflow in July 2026. TRM adds that not all of that value is necessarily tied to the jackpotting scheme, and that exchanges may be able to identify the account holders. It also reports about $35 million sent onward from TdA-linked addresses to a network US authorities link to a Venezuelan national whose charges are allegations. Six point one over 40.73 is 15 per cent (derived). That is arithmetic, not a laundering rate: one figure is inflow to addresses since 2022, the other is reported losses as of August 2025.

What a designation establishes, and what it does not.

  1. Establishes
    Treasury has designated the persons for assisting TdA, or because a designated person owns or controls them (E.O. 13581 and 13224).
    Does not establish
    Guilt for any jackpotting. The press release gives the legal basis and a description of each person, but no evidence.
  2. Establishes
    Seven TRON addresses are blocked, and foreign banks risk secondary sanctions for significant transactions with the designated people.
    Does not establish
    That the addresses hold money now. TRM says most have been dormant for months.
  3. Establishes
    Reported losses of $40.73 million are cited in the same release.
    Does not establish
    That the money reached these addresses. The release traces none of the $40.73 million.

Who is speaking. Treasury and DOJ are the prosecuting side. Their releases announce results and frame the case as terrorism finance, which is why one count is material support. The defence has not yet answered that charging theory, and the controls in this briefing do not depend on it. TRM Labs sells blockchain analytics and promotes its user conference on the same page. NCR Atleos sells ATMs, software and services. EAST is a trade body whose figures are what members choose to report. The FBI and the Indiana regulator sell nothing, and their lists overlap heavily with the manufacturer's, which is some comfort that the manufacturer's list is more than a catalogue.

UK firms. OFAC's rules bind US persons, and for these counter-terrorism designations Treasury warns that foreign banks that knowingly handle significant transactions for the designated people risk secondary sanctions. UK sanctions law is separate. We did not check the UK list, and no source we read says the UK has designated any of the ten.

The UK side: what the primaries say, and where they are silent

Scale. LINK's table, published 21 August 2026, gives 33,699 free-to-use and 8,693 pay-to-use machines at the end of 2025, 42,392 together (derived). The free-to-use count peaked at 54,599 in 2017, so it has fallen 38 per cent (derived). LINK says "almost every cash machine in the country" is connected to its network and expects the number to keep falling as people use less cash.

What is silent. The LINK pages we read do not mention jackpotting or malware. UK Finance's Annual Fraud Report 2026 has one cash machine figure, £25.7 million for 2025, defined as fraudulent transactions made at cash machines with a stolen card or a taken-over account and a genuine PIN. That is a crime against the cardholder. A jackpotting attack uses no card and no account, and the report says nothing about it, or about black box attacks. We found nothing on jackpotting on the NCSC or NCA sites, but their site search was partly cookie-gated and script-driven, so that is a failure to find and not proof of absence. In the sources we read there is no published UK count of machine-level cash-out attacks.

ATM malware and logical attacks reported to EAST by European states. The 2024 report's list of 19 supplying states includes the United Kingdom. EAST releases of 14 April 2025 and 22 April 2026.

  1. Year
    2020
    Malware and logical attacks reported
    202
    Reported losses
    EUR 1.24 million
  2. Year
    2021
    Malware and logical attacks reported
    52
    Reported losses
    EUR 0.70 million
  3. Year
    2022
    Malware and logical attacks reported
    31
    Reported losses
    EUR 0.14 million
  4. Year
    2023
    Malware and logical attacks reported
    7
    Reported losses
    EUR 0.07 million
  5. Year
    2024
    Malware and logical attacks reported
    3
    Reported losses
    None reported
  6. Year
    2025
    Malware and logical attacks reported
    1
    Reported losses
    None reported

EAST credits the fall to Europol's guidance on logical attacks, which has restricted circulation; "it is believed" is EAST's own wording, so that is a belief and not a measurement. EAST also says it will likely stop reporting these attacks from 2026, which would remove the only European series. The US count for 2025 alone is more than 700 incidents (FBI). Both are reported counts from different systems, so the contrast says where the campaign has been, not that Europe is safe. Physical attacks in the same EAST report were 2,986 in 2025, with EUR 19 million lost, 71 per cent of it to explosives. The UK share is not published in the release.

The UK guidelines. The ATM Security Working Group's July 2019 guidelines, hosted by LINK, mention a "Black Box/ Jackpot attack" once, as a note: access via the front fascia, then a remote PC connected to the ATM's technical systems. The alarm list in the sections we read names the safe body, the safe door, the service room and heat inside the machine. We did not find a requirement that names the door of the top box, where the computer sits, or its key. The guidelines do say that the alarm centre should be able to call a responder "within an agreed (ideally contractually binding) time period", and that merchant-fill machines should hold one day's trading cash only. Its introduction expects branch closures to bring "an increase in the number of bank-remote ATMs and independent-provider ATMs located in more vulnerable locations". Of a free-standing machine it says "physical protection is limited to the ATM itself". It predates the FBI FLASH by six and a half years, and we found no newer edition.

What can and cannot be said. The US cases involved free-standing and drive-up machines at banks and credit unions (DOJ, NCR). The UK has many free-standing machines in shops, petrol stations and malls. That is an inference about exposure, not a finding that any UK machine has been opened. One undated post on a US ATM services firm's blog, relaying NCR advice, reports a spike in black box attacks on through-the-wall machines in the UK. It gives no date, count or police source, so it is a lead and not a statistic.

What an ATM operator or bank security lead should do, in this order

The order is our judgement: cheapest and most likely to matter first. Each item names the source that says it; where nothing does, it says so. The sources are US regulator, FBI and manufacturer guidance, because we found no UK primary on jackpotting.

Take this with you

In the order worth doing

  • List every machine by make, model, operating system build and its support end date, site type and who holds the keys. Do free-standing and drive-up machines first. The FBI asks for make, model and vendor in any incident report, and you will need them in the first hour. Judgement on the order.
  • Change the keys. Replace standard cabinet and top box locks so a key bought online does not open them, and record who holds the new ones. The FBI and Indiana DFI say this. NCR's alert describes a machine opened with the common top box key.
  • Alarm the top box, not only the safe. Add door-open alerts, vibration or temperature sensors and a keypad that alarms if no code is entered when the maintenance hatch opens (FBI), and vary where the sensors sit (Indiana DFI). The UK 2019 alarm list names the safe and the service room, so check what yours covers.
  • Write down a response time in minutes, then test it by opening a door and timing who arrives. The ATMSWG says the alarm centre should be able to call a responder within an agreed, ideally contractually binding, time. DOJ says crews wait nearby to see whether an alarm brings anyone. The number is judgement.
  • Encrypt the disk and lock the firmware. Full-disk encryption (FBI, NCR, Indiana DFI), boot from the main disk only, a non-default BIOS password and Secure Boot where possible (NCR), and the expansion bus disabled where the top box can be opened (NCR).
  • Close the ports and allowlist what runs. Disable unused USB ports and allow only known devices (FBI, Indiana DFI), and allowlist software (FBI, NCR).
  • Keep a gold image and compare machines to it. The FBI calls routine validation against a verified image one of the most effective defences, and treats unsigned or newly introduced files as a potential compromise.
  • Patch, and check support dates. The FBI and NCR both say to patch the operating system and ATM software. As an example of why dates belong on the asset list: Microsoft lists 14 October 2026 as the extended end date for Windows 10 IoT Enterprise LTSB 2016 and Windows 10 2016 LTSB, nine days after the date of this briefing. No source we read says any UK machine runs them. Check your own list.
  • Log the physical events and send them off the machine. The FBI's example sequence is a USB insertion, a file copy, a process start, a service install and a cleared log. Enable removable-storage and process-creation auditing and store the logs centrally.
  • Watch for cash-out patterns. Alert on dispenses with no card, on a machine that goes offline unexpectedly and on low-cash flags outside the refill schedule (Indiana DFI, FBI), and consider automatic out-of-service on a combination of indicators (FBI).
  • Cap the cash where risk is high. ATMSWG says to fill a merchant-fill machine with one day's trading cash. The largest single attempt among the indictment's four listed acts was $199,466, so what you load is the loss you control. Judgement.
  • Report quickly and agree the route in advance. Police first when an attack is in progress or a machine is found open. The FBI asks US firms for date, time, location and equipment details. No source we read gives a UK reporting route for jackpotting, so agree one with your police contact and, where it applies, your scheme and regulator. Telling the NCA about suspected organised crime is judgement.
  • Put it in the supplier contract. Ask the maintainer and manufacturer which hardening baseline is applied, who holds the keys, how service visits are verified (Indiana DFI says to audit service staff and check credentials), how fast security alerts arrive (NCR runs a sign-up list) and the alarm response time.
  • Join the channels where this is shared: the FBI recommends industry information sharing, and the Europol guidance is reachable through trade bodies such as EAST. Judgement on which.

What we could not verify

The question this leaves

The arrest and the sanctions are the part of this story that has an author and a date. The part that decides whether a machine in your estate pays out is the part nobody announces: a lock, a sensor, a response time and an encrypted disk.

If someone opened the top box of your quietest free-standing machine at 03:00 tonight, who would be told, and how many minutes before anyone stood at it?

Key facts

Sources

  1. PrimaryPress release of 30 September 2026, read in full: the 10 targets, the $40.73 million and 1,500 attacks figure, the laundering description, the designation authorities and the separate gold mining designationUS Department of the Treasuryaccessed 2026-10-05
  2. PrimaryRecent action of 30 September 2026, read in full: the SDN list additions, 9 individuals and 2 entities, 7 TRON addresses, programme tags. Used to reconcile eight, ten and elevenOFACaccessed 2026-10-05
  3. PrimaryRelease 26-1135 of 2 October 2026, read in full: the apprehension, the initial appearance and not guilty pleas, the four counts, the 120 defendants charged and the allegation wordingUS Department of Justiceaccessed 2026-10-05
  4. PrimaryIndictment 8:25-cr-00242, Doc 5, filed 9 December 2025, read in full: stages of deployment, 63 bank and 54 credit union attacks, at least $5,401,181 lost, four counts, the overt actsUS District Court for the District of Nebraska, posted by DOJaccessed 2026-10-05
  5. PrimaryRelease of 18 December 2025: the two indictments, the 'as of August 2025' map of alleged incidents and the account of how crews workUS Attorney's Office, District of Nebraskaaccessed 2026-10-05
  6. PrimaryRelease of 26 January 2026: crews open the hood or door and wait to see whether an alarm brings a response; how code reaches the machineUS Department of Justiceaccessed 2026-10-05
  7. PrimaryRelease of 20 February 2026: 93 defendants, the 'in excess of $100,000 per jackpotting attempt' wording and the link to the FBI FLASHUS Department of Justiceaccessed 2026-10-05
  8. PrimaryRelease of 26 June 2026: two sentencings, the guilty pleas to conspiracy to commit bank burglary and computer fraud, the arrests at a jackpotting site, and the 98 figure that Treasury repeatsUS Department of Justiceaccessed 2026-10-05
  9. PrimaryFLASH-20260219-001 of 19 February 2026, read in full: more than 700 incidents and $20 million in 2025, generic keys, the physical and digital indicators, the mitigationsFBIaccessed 2026-10-05
  10. PrimaryAdvisory Letter 2025-04 of 14 October 2025: attack categories and shared mitigants, including re-keying, alarm sensor placement and anomaly monitoringIndiana Department of Financial Institutionsaccessed 2026-10-05
  11. PrimaryLogical Security whitepaper, updated February 2024: fifteen rules including BIOS lock down, full disk encryption, allowlisting and dispenser protection. A manufacturer's guidanceNCR Atleosaccessed 2026-10-05
  12. PrimaryUndated security alert: attacks that need physical access inside the top box, and the checklist where missing one step leaves a machine vulnerableNCR Atleosaccessed 2026-10-05
  13. PrimaryUndated security alert: a drive-up machine with the common top box key and incomplete logical protectionNCR Atleosaccessed 2026-10-05
  14. PrimaryRelease of 22 April 2026 on the 2025 European Payment Terminal Crime Report: malware and logical attacks down to 1, physical attacks 2,986 and EUR 19 millionEAST (European Association for Secure Transactions)accessed 2026-10-05
  15. PrimaryRelease of 14 April 2025 on the 2024 report: the 2020 to 2024 series for malware and logical attacks, the black box definition, and the 19 supplying states including the United KingdomEAST (European Association for Secure Transactions)accessed 2026-10-05
  16. PrimaryNews item on Europol's guidance on logical attacks on ATMs: the document's circulation is restricted to law enforcement and the banking and payments industryEAST (European Association for Secure Transactions)accessed 2026-10-05
  17. PrimaryATM Numbers table, published 21 August 2026: 33,699 free to use and 8,693 pay to use at the end of 2025; the total of 42,392 is our sum. Read with the 'protecting the ATM network' page, which does not mention jackpotting or malwareLINKaccessed 2026-10-05
  18. PrimaryPhysical ATM Security Guidelines, July 2019, read in full: the one-line black box note, the alarm equipment list, the monitoring and response clauses, the free-standing machine sectionATM Security Working Group, hosted by LINKaccessed 2026-10-05
  19. PrimaryAnnual Fraud Report 2026: the cash machine fraud figure of 25.7 million pounds for 2025 and its definition. Searched for jackpotting, black box and malware; none relatesUK Financeaccessed 2026-10-05
  20. PrimaryArticle of 14 February 2018: the first Ploutus variant became public on 24 October 2013. Used only for the age of the malware familyKaspersky Securelistaccessed 2026-10-05
  21. PrimaryLifecycle page for Windows 10 IoT Enterprise LTSB 2016: extended end date 14 October 2026 as listed. Used as an example of why support dates belong on the asset listMicrosoftaccessed 2026-10-05
  22. Reported byBlockchain analytics firm's note of 30 September 2026: the 6.1 million dollar inflow, exchange-hosted deposit addresses, the 35 million dollar onward flow. A vendor's analysis of the designationTRM Labsaccessed 2026-10-05
  23. Reported by5 October 2026 report on the arrest. A pointer to the DOJ release; its 'over $100,000 per incident' sentence and its 98 defendants figure are checked against the primariesBleepingComputeraccessed 2026-10-05
  24. Reported by2 October 2026 report on the sanctions. A pointer to the Treasury release; its 'eight members' is reconciled with OFAC's ten targetsBleepingComputeraccessed 2026-10-05
  25. Reported byDecember 2025 report giving 1,529 incidents since 2021 and $40.73 million as of August 2025. Not used for any figure in the article; we could not match it to a DOJ textThe Hacker Newsaccessed 2026-10-05
  26. Reported byUndated blog post by a US ATM services firm relaying NCR advice and reporting a spike in black box attacks on through-the-wall machines in the UK. A lead, not a statistic: no date, count or police sourceFTSIaccessed 2026-10-05

Share this briefing

Know someone who owns this problem? Send it to them.

Related briefings

The briefing, in your inbox

Practitioner analysis of cyber and AI security news. No vendor noise.

How often

Every new briefing in one email, at 7am, or at 7am, 12:30pm and 6pm. Nothing is sent when nothing is new. Unsubscribe any time.