A document containing detailed information on ATM programming was found online, via the Chinese search engine Baidu.
The frequency of attacks with sophisticated software targeting ATMs has increased in recent years, and with such an element at the disposal of criminals, it is clear that the situation has begun to deteriorate significantly.
The API documentation discovered by F-Secure security researchers concerns ATMs manufactured by NCR Corporation. This manual can be used to create malicious code that can interact with the ATMs. These machines run Windows Embedded, an operating system that has significant differences compared to regular versions of Windows.
The researchers came across the document while searching for specific internals of an ATM malware they were investigating. The researchers were trying to figure out how the malware interacted with ATMs, and to do so, they needed access to the machines’ API documentation. As it turned out, a simple search with the right keywords was enough to get all the information they needed.
Of course, malicious actors can also gain access to the file with the same ease. And as is well known, once a document has been leaked online, despite all efforts to remove it, there is no guarantee that it will be completely eliminated.

