ATMs Are Standard PCs in Sheet Metal Boxes

▶ Watch (5:03)

ATMs are not specialized IoT devices. Inside the cabinet sits a standard PC with USB ports, IO pins for tamper detection, a DVD drive, and a small-form-factor hard drive. The cash dispenser connects via USB. Four currency cassettes hold around 2,000 bills each. One cassette handles rejects from incomplete withdrawals. Sandström calls his first engagement a Scooby-Doo moment: he expected complex embedded systems and found commodity hardware running familiar payloads.

Physical Access: Thin Metal and eBay Keys

▶ Watch (7:17)

The top half of an ATM opens with locks so weak that technicians sometimes break them deliberately to avoid carrying keys. The sheet metal is thinner than a changing-room locker. Locks typically have three pins or fewer. The keys are sold on eBay. Sandström notes that if lockpicking is not practical, buying the key is faster. Once open, the service compartment gives direct access to the PC, USB ports, and internal cabling. The vault below uses a different, stronger lock.

Missing Disk Encryption Renders Every Other Control Irrelevant

▶ Watch (10:01)

About 30 to 40% of ATMs Sandström has tested lack disk encryption. That single gap undoes every other control. App locker and antivirus mean nothing when an attacker pulls the drive, boots a live OS, and installs jackpotting software. The cash dispenser enforces mutual authentication with the ATM’s own PC, so an attacker cannot plug in a random laptop and trigger a payout. Without encryption, the attacker controls the PC, and the PC has authentication by design.

Unencrypted Networks Expose Card Data and Dispense Commands

▶ Watch (11:56)

Network gear between ATMs and bank back-ends is often a home router running vulnerable firmware with default credentials. The link between the router and the ATM runs unencrypted. Transaction logs and card numbers travel in plaintext. Sandström shows a Wireshark capture where asterisks mask card digits in the on-screen receipt but the raw dump contains full card numbers. An attacker on that segment can also manipulate dispense commands: the machine has no concept of denomination and responds to raw bill counts.

The Swedish Heist: USB Cable, No PC Required

▶ Watch (16:57)

Three years before the talk, Sandström witnessed a police investigation into two Russians who robbed ATMs in Sweden. Using chisels, gloves, and crowbars, they pried open the thin metal top. Those dispensers had no mutual authentication. The attackers plugged a USB extension cable directly into the dispenser and triggered payouts without touching the PC. Police found vendor dispenser software on the crew’s laptop, suggesting inside knowledge of which machines lacked authentication. They took around $80,000. A fully stocked ATM holds up to $300,000.

Q&A

What percentage of ATMs are still vulnerable to these attacks? Sandström estimates 30 to 40% still lack disk encryption and says the pattern holds across current engagements, varying by country and bank. ▶ 19:46

How often do banks update ATM components? Not often. Exploits from a year or more before the engagement still work because ATMs go unpatched, and half a year to a year off on patches is not unusual. ▶ 21:06

What percentage of successful attacks are physical versus technical? Sandström estimates about 70% physical and 30% technical, with technical attacks more likely to succeed without getting caught. ▶ 21:40

Could compromised ATMs serve as initial access into bank networks? Sandström agrees it is worth investigating, suggesting operator credentials harvested from ATMs may be a better entry point than spear phishing. ▶ 22:22

Notable Quotes

This will be part of your red team exam Fredrik Sandström · ▶ 1:24

this so it’s quite It’s quite scary. Fredrik Sandström · ▶ 14:17

Criminals didn’t have better phones. Fredrik Sandström · ▶ 19:21

So it’s security by economics, not by Fredrik Sandström · ▶ 20:35

Key Takeaways

  • About 30 to 40% of ATMs still lack disk encryption, bypassing all software-level controls.
  • ATM top panels use weak three-pin locks; the keys are available for purchase on eBay.
  • Transaction data and full card numbers often travel unencrypted between the ATM and the bank.

About the Speaker(s)

Fredrik Sandström is Head of Cyber Security at Basalt in Stockholm, Sweden, with nearly a decade of penetration testing experience and a background in software development and embedded systems engineering. His early career included work at the Swedish Defence Research Agency. Since 2015, he has delivered penetration tests, red team exercises, and threat emulation engagements for clients in banking, insurance, automotive, energy, communications, and IT services. He holds the GXPN, GCPN, GRTP, and HTB CBBH certifications and has presented at SEC-T and DevCon in Bucharest.