Skip to main content
Should You Harden Every ATM or Focus on Detection?Fraud Typologies
5 min readFor Bank Information Security Officers

Should You Harden Every ATM or Focus on Detection?

Five Venezuelan nationals pleaded guilty to ATM jackpotting attempts in Kansas, joining 87 others charged in connection with Tren de Aragua operations that stole over $20 million last year. The U.S. Attorney's Office responded by encouraging banks to "invest in these updates", but which updates, exactly?

You're facing two strategies. The first: harden every ATM against malware through firmware updates, physical locks, and whitelisting. The second: accept that some machines will be compromised and invest in rapid detection and response. Both approaches have their advocates, and both require real budget dollars.

This isn't an academic debate. Your choice determines where your next security dollar goes and how you'll explain the next incident to your board.

The Case for Hardening First

Hardening advocates start with a simple premise: if attackers can't install malware, they can't jackpot your machine. The criminals in Kansas failed twice because they couldn't complete the installation, the Wamego attempt triggered an alarm before malware deployment, and the Manhattan machine never dispensed cash.

This camp argues you should:

Deploy firmware that validates every executable before it runs. Modern ATM operating systems support application whitelisting. If Ploutus or ATMitch isn't on your approved list, it won't execute.

Require Multi-Factor Authentication (MFA) for any configuration changes. The typical jackpotting sequence involves opening the ATM cabinet, connecting a USB keyboard or using the PIN pad to issue commands, then instructing the cash dispenser to empty. MFA at the cabinet level means physical access alone isn't enough.

Upgrade machines that can't be hardened. The U.S. Attorney noted that criminals "specifically target ATMs they thought were by design more vulnerable to malware." If your fleet includes older models running Windows XP or unpatched embedded systems, you're advertising vulnerability. Replace them or pull them from service.

The hardening argument rests on a prevention-first philosophy: every successful attack you block is cash you don't lose and a SAR you don't file. When surveillance caught the Kansas group, they'd already failed, but only because the machines resisted compromise.

The Case for Detection and Response

The detection camp doesn't dispute that hardening helps. They argue it's not sufficient, or that it's where your marginal dollar delivers the most risk reduction.

Their argument: criminals adapt faster than you can patch. The source article lists eight malware families used in jackpotting attacks: ATMii, ATMitch, GreenDispenser, Alice, RIPPER, Skimer, SUCEFUL, and Ploutus. That's not an exhaustive list, it's what we know about. By the time you've hardened against Ploutus, attackers have moved to a variant your whitelist doesn't recognize.

This camp argues you should:

Instrument every ATM for behavioral anomalies. A machine that suddenly attempts to dispense its entire cash cassette outside of normal transaction patterns is signaling compromise, regardless of which malware enabled it. Detection at the dispenser-command level catches attacks your firmware updates missed.

Integrate ATM alerts with your security operations. The Wamego machine triggered an alarm that brought law enforcement while criminals were still on-site. That's the model: detect the attempt in progress, respond before cash leaves the cassette. Your mean time to response matters more than your patch cadence.

Accept that physical access defeats most hardening. If an attacker opens your cabinet and connects a keyboard, they're working at a privilege level your software controls can't fully restrict. Detection acknowledges this reality and focuses on limiting damage rather than preventing all access.

The detection argument rests on an assumption about attacker sophistication: organized groups like Tren de Aragua have resources to develop new malware faster than you can harden against it. Your defense should assume eventual compromise and optimize for containment.

Where Practitioners Actually Land

In practice, most banks don't choose one strategy exclusively. You're running a hybrid model whether you've formalized it or not.

Your newer machines, the ones deployed in the past three years, probably support whitelisting and encrypted firmware updates. You've hardened those because the vendor made it straightforward. Your legacy fleet, the machines you're depreciating over another two years before replacement, can't support the same controls. You've focused detection there because hardening isn't technically feasible without replacement.

Geography matters too. Your high-volume urban ATMs justify more hardening investment because the cash-at-risk is higher. Your rural machines in low-traffic locations might get surveillance and behavioral monitoring but not firmware overhauls.

The Kansas cases illustrate why neither strategy alone is sufficient. The criminals failed in Wamego because an alarm triggered during the installation attempt, that's detection working. They failed in Manhattan because the machine refused to dispense cash even after they'd gained physical access, that's hardening working. Both defenses contributed to the outcome.

Our Take

Harden what you can, detect what you must, and don't pretend you can harden everything.

Start with an honest inventory. Which machines in your fleet can support application whitelisting and MFA for configuration changes? Implement those controls now. The U.S. Attorney's encouragement to "invest in these updates" isn't aspirational, it's pointing at controls that already exist and that you can deploy without hardware replacement.

For machines that can't support modern hardening, build detection that assumes compromise. You need behavioral monitoring at the cash dispenser level and alert integration that brings your security operations team into the loop within minutes, not hours. The criminals in Kansas were arrested days after their attempts, but the Wamego alarm triggered while they were still on-site. That's your response time target.

Budget your next three years with replacement in mind. If a machine can't be hardened and you're relying entirely on detection, it's a candidate for accelerated depreciation. The $20 million stolen last year wasn't distributed evenly, some banks lost significantly more than others, and the common factor was machines that couldn't resist malware installation and didn't alert fast enough to contain the damage.

The debate between hardening and detection is a false binary. You need both, deployed strategically based on what each machine can support and what each location's risk profile justifies. The criminals are organized, well-funded, and adaptable. Your defense should be equally pragmatic.

You Might Also Like