Here’s how cybercriminals profit from hacking ATMs
Here’s how cybercriminals profit from hacking ATMs
5:19

Here’s how cybercriminals profit from hacking ATMs

Privacy
Criminals are interested in return on investment, and the return on investment for an attack like this is much higher, because you can target multiple ATMs without leaving your house. [MUSIC] This is a home-based command centre, think of it as the IT-technician for this crime. This is just a standard ATM. So I'm going to withdraw $40 from this ATM. Select English, [INAUDIBLE] PIN, I'm gonna make sure to protect my PIN. I'm gonna do withdraw checking for 40. We have two X-force red $20 bills. I'm gonna request $40 again. Let's see how much money I can get out. [BLANK_AUDIO] I'll take a receipt, now, this time, in fact, if you look at my receipt, it also says $40. [MUSIC]. From a criminal point of view one of the great things about this attack is that the bank has no idea what's happened. The bank told the ATM to dispense two bills. It has no idea that the attacker modified the response and changed it to 10 bills. And what operating systems do these generally run? You see everything from XP Embedded, XP Windows 7, All the way up to more modern variants of Windows. So you're saying that the most vulnerable versions of Windows are deployed on thousands of ATM machines across the country? Yes, you have a lot of ATMs across the country that still run Windows XP. So the type of vulnerabilities that we exploit initially on an ATM are very common. ATMs are architected a very similar way to home PC. In fact it often times it may be more vulnerable because of the difficulty in patching ATMs that are distributed across the wild geographic area. Most of the ATMs don't have a support staff that are standing there. And that the bank has to send someone out to each ATM to install software. It significantly increases cost. So they're usually very conservative about which patches of which software they push out. This is the receipt printer has the standard USB connection shows up in Windows just like any other printer. You could actually print Word documents on this the same is true for the safe. The cash dispenser is also just a USB device was printed out our own money stopped it up. Once the ATM is compromised, that's where it gets a lot more complicated. An attacker has to know how to communicate with the specialized devices. Each vendor has a separate set of hardware that they're going to be using every piece of software on an ATM has the potential to be a little bit different. So we create our own custom software when we're performing attacks. The attacker can monitor everything that's going on. For example, the attacker can see what's actually displayed on the screen of the ATM and also observe the network traffic. The highlighted text here is the magnetic stripe data from the card. You can see the 4000 is corresponds to the $40 that Charles requested. A lot of people assume that when an ATM withdraws, a process that the bank issues a yes or no response, but in reality it tells the ATM how many bills to dispense. So in the response it told the ATM to dispense two bills, but We can modify it as the attacker change that 02210 so the 10 bills are dispensed Do I need to people do I need to you extracting cash and some attacker sitting in a remote location synced up Conceivably he could do it from right outside the atm but it makes more sense because there's less risk to him being compromised if he can send A low cost criminal employee to go pick up the cash for. [MUSIC] This is us taking control the ATM now notice it goes out of service. [LAUGH] Sometimes criminals may not want to put a card into the ATM for whatever reason and they may just want to dispense money. Is often referred to in the industry as jackpotting. And it doesn't even require a card. David is just going to remotely dispense cash. [BLANK_AUDIO] [MUSIC] How often they're updated often depends On the volume of usage for an ATM, but an ATM like this can hold over $200,000. In fact, in certain rare instances they can be stocked with up to a million dollars. And it's very difficult for banks to detect this in the short run because. ATMs don't have a precise way of measuring how many bills are in the back. It's just a counter. It's really only if the criminals empty the ATM completely of cash that warning bells go off. So a lot of the technology that is needed to defend against these are things that are already on the market. For example, having encrypted network connections between the ATM and the bank. Well, that's been available for for literally decades now, surprising how many banks are still using insecure network communication. When an ATM like this is compromised, it's the consumer that pays and the form of increased fees. [MUSIC]

Up Next

Best antivirus software for Windows (2021 edition)
antivirus-thumb

Up Next

Best antivirus software for Windows (2021 edition)

Which VPN should you pick?
vpn

Which VPN should you pick?

Here's how the pandemic is changing how we shop online
nw-micheleherron

Here's how the pandemic is changing how we shop online

Video game industry targeted by Chinese hackers
jeffrosen-00-00-14-25-still002

Video game industry targeted by Chinese hackers

CISA director: Paper record key to keeping 2020 election secure
krebs-image

CISA director: Paper record key to keeping 2020 election secure

Blackhat 2020: Tech community must help secure elections
matt-blaze-image

Blackhat 2020: Tech community must help secure elections

Chinese hackers charged with allegedly stealing COVID-19 vaccine
chinesehackers

Chinese hackers charged with allegedly stealing COVID-19 vaccine

How to protect your phone (and your privacy) at a protest
gettyimages-phone-protest

How to protect your phone (and your privacy) at a protest

Everything you need to know about stalkerware
stalkerware

Everything you need to know about stalkerware

Prepare for a 'new national surveillance system' in order to wipe out COVID-19
covid19-privacy-final

Prepare for a 'new national surveillance system' in order to wipe out COVID-19

Tech Shows

The Apple Core
apple-core-w

The Apple Core

Alphabet City
alphabet-city-w

Alphabet City

CNET Top 5
cnet-top-5-w

CNET Top 5

The Daily Charge
dc-site-1color-logo.png

The Daily Charge

What the Future
what-the-future-w

What the Future

Tech Today
tech-today-w

Tech Today

Latest News All latest news

Purple Mattress Guide: Which Bed Should You Sleep On?
The Purple Restore mattress against a colorful background and a man in a sweatshirt in the front.

Purple Mattress Guide: Which Bed Should You Sleep On?

Digital Heroes: Connecting New Yorkers to Affordable, High-Speed Internet Access
230922-yt-nyc-mesh-v01b

Digital Heroes: Connecting New Yorkers to Affordable, High-Speed Internet Access

TV Buying Guide: Sizes, Prices and When to Buy to Get a Good Deal
tv-buying-guide-cnet-seq-00-08-50-25-still008

TV Buying Guide: Sizes, Prices and When to Buy to Get a Good Deal

Brain-Computer Interface: No Open Brain Surgery Required
demo3

Brain-Computer Interface: No Open Brain Surgery Required

First Look: Microsoft Surface Studio 2 and Surface Go 3 Laptops
surface-laptops-1080-seq-00-05-17-28-still005

First Look: Microsoft Surface Studio 2 and Surface Go 3 Laptops

10 Must-Try Hidden iOS 17 Features on Your iPhone
230921-site-ios-17-hidden-features

10 Must-Try Hidden iOS 17 Features on Your iPhone

Most Popular All most popular

TV Buying Guide: Sizes, Prices and When to Buy to Get a Good Deal
tv-buying-guide-cnet-seq-00-08-50-25-still008

TV Buying Guide: Sizes, Prices and When to Buy to Get a Good Deal

Amazon Announces New Ring and Blink Cameras for the Home
amazon-reveals-new-ring-and-blink-cameras-00-04-09-02-still001

Amazon Announces New Ring and Blink Cameras for the Home

Amazon Shows Off New Fire TV Soundbar, 4K Stick
amazon-seq-00-00-08-14-still001

Amazon Shows Off New Fire TV Soundbar, 4K Stick

iPhone 15 Pro Max vs. Galaxy S23 Ultra: Spec Comparison
iphone15promax-vs-galaxys23ultra-site

iPhone 15 Pro Max vs. Galaxy S23 Ultra: Spec Comparison

First Look: Microsoft Surface Studio 2 and Surface Go 3 Laptops
surface-laptops-1080-seq-00-05-17-28-still005

First Look: Microsoft Surface Studio 2 and Surface Go 3 Laptops

Surprises From First Days of iPhone 15 and Apple Watch Series 9
230921-site-one-more-thing-revelations-of-the-reviews-2

Surprises From First Days of iPhone 15 and Apple Watch Series 9

Latest Products All latest products

Vizio's New Quantum Pro TVs Could Be a Strong Value Play
new-vizio-tvs-cnet-00-00-41-11-still001.png

Vizio's New Quantum Pro TVs Could Be a Strong Value Play

Amazon Announces New Ring and Blink Cameras for the Home
amazon-reveals-new-ring-and-blink-cameras-00-04-09-02-still001

Amazon Announces New Ring and Blink Cameras for the Home

Amazon Unveils Echo Pop Kids, Fire HD 10 Kids Tablets for Young Users
cnet-thumbnail-amazonevent-kids-site

Amazon Unveils Echo Pop Kids, Fire HD 10 Kids Tablets for Young Users

Review: The iPhone 15 Pro, 15 Pro Max Are Impressive
iphone15pro-promax-review-clean

Review: The iPhone 15 Pro, 15 Pro Max Are Impressive

Bose Debuts QuietComfort Ultra Headphones and Ultra Earbuds (Hands-On)
bosehandson-00-00-21-12-still001

Bose Debuts QuietComfort Ultra Headphones and Ultra Earbuds (Hands-On)

Apple Watch Ultra 2: First Look
handson-applewatch-ultra2-clean

Apple Watch Ultra 2: First Look

Latest How To All how to videos

10 Must-Try Hidden iOS 17 Features on Your iPhone
230921-site-ios-17-hidden-features

10 Must-Try Hidden iOS 17 Features on Your iPhone

How to Record Your Screen in Windows 11
how-to-record-your-screen-in-windows-11-00-00-48-13-still002

How to Record Your Screen in Windows 11

Windows Copilot Preview: How to Manage Your PC With the AI Assistant
copilot-clean

Windows Copilot Preview: How to Manage Your PC With the AI Assistant

How to Build a Portable AC Unit in Minutes
diy-portable-ac-for-youtube-00-02-55-23-still001

How to Build a Portable AC Unit in Minutes

How to Blur Your Home or an Object in Google Maps
how-to-blur-your-house-in-google-maps-1b

How to Blur Your Home or an Object in Google Maps

How to Clone Your Own Voice with AI
230620-site-how-to-make-an-ai-voice-clone

How to Clone Your Own Voice with AI