Diebold Nixdorf, the world’s largest ATM manufacturer, is warning banks about a new type of “black box” attack on ATMs that was recently detected in Europe. “Black box” attacks on ATMs are a type of jackpotting attack. A jackpotting attack can be carried out by installing malware on an ATM or by using a “black box.” A “black box” attack occurs when an attacker unscrews an external ATM case to gain access to its ports or drills a hole in the case to gain direct access to the machine’s internal wiring or other hidden connections. Using these access points, the attacker then connects a “black box” device – which is usually a laptop or Raspberry Pi board – to the ATM’s internal components, which they use to send commands to the ATM’s cash dispenser and withdraw all the money the machine has inside.
ATM jackpotting attacks have been on the threat landscape for over a decade. This type of attack is extremely popular with criminal gangs, as the technique used is not only cheaper but also simpler to execute, compared to using scanning or card cloning, which take months to complete. “Black box” attacks allow hackers to quickly purchase the black box equipment and malware they need and start jackpotting an ATM in just a few days.

In a security advisory, Diebold Nixdorf said its researchers have been made aware of a new variant of the “black box” attack, which is being used in countries across Europe. Diebold Nixdorf also noted that the new attacks are only being used on ProCash 2050xe ATM terminals, with attackers connecting to the machine via USB. Diebold Nixdorf also explained that in the recent attacks, the hackers appear to have targeted external systems and damaged parts of the fascia to gain physical access to the head compartment. They then disconnected the USB cable between the CMD-V4 hub and the dedicated electronics.
Diebold Nixdorf also said that while in most attacks the hackers used malware or their own code to interact with the ATM's cash dispenser, in the recent attacks, the perpetrators appear to have obtained a copy of the ATM software (firmware), which they installed on the black box and used to interact with the machine's cash dispenser. Diebold Nixdorf also believes that the attackers may have connected to an ATM and found the software stored insecurely on an unencrypted hard drive.

Diebold Nixdorf’s warning follows an investigation into a series of ATM jackpotting attacks that took place in Belgium in June. The attacks forced Belgian bank Argenta to close 143 ATMs after it suffered two jackpotting attacks on its ATMs. One attack took place in June and the other last weekend. The attacks, believed to be the first jackpotting incidents in Belgian history, used the technique described in Diebold Nixdorf’s warning, with attackers connecting to the ATM via USB and emptying the cash dispenser.
According to The Brussels Times, the attacks in Europe only targeted Diebold Nixdorf ATMs. It is worth noting that Manuel Pintag, a cybersecurity and bank fraud expert at Telefonica, said that this technique had been used in Latin America before appearing in Europe.
