SardineCon SF/2026

Learn More
Card & payment fraud4分 で読めます

ATM cash-out attackとは?

ニュースレターを購読

An ATM cash-out attack is a coordinated operation that forces bank machines to dispense large amounts of cash at once, using stolen card data with controls disabled or malware that overrides the machine. It is fast, high-volume, and usually pulled off across many machines in different cities within a single window of a few hours.

What is an ATM cash-out attack?

An ATM cash-out attack is a coordinated cash grab. Instead of draining one stolen card at one machine, criminals arrange for many machines to spit out cash in a tight, planned window. The goal is to pull the maximum amount before the issuer, processor, or network can notice and shut it down.

There are two main flavors. In an unlimited operation, attackers breach a card issuer or processor and remove the account controls that normally cap withdrawals: daily limits, balance checks, and fraud holds. A small set of card numbers can then be used again and again with no ceiling. In a jackpotting attack, the machine itself is the target, with malware or a hardware device attached to the ATM so it dispenses its entire cash cassette on command.

For a fraud team, this sits at the intersection of card fraud and infrastructure compromise. The stolen card data or the physical machine access is only the front end. The real enabler is that the normal transaction controls have been turned off, so authorization systems keep saying yes.

How a cash-out attack unfolds

These are planned in advance and executed on a clock:

  1. CompromiseGet the access Attackers breach a processor or issuer to lift card data and disable controls, or install malware directly on target ATMs.
  2. PrepareClone cards and stage crews Card details are written onto blank plastic and handed to teams of cashers positioned near machines in multiple locations.
  3. ExecuteHit the machines at once On a signal, crews withdraw the maximum repeatedly across many ATMs during off-hours, often a weekend, to pull cash fast.
  4. DisperseScatter and settle up Cashers take a cut and hand the rest up the chain. The whole operation is usually over before daylight monitoring catches it.

Who is involved?

Who

Their role

The operator

The organized group that breaches the processor or plants the malware, controls the card data, and sets the timing of the attack.

The cashers

Local crews who stand at the machines with cloned cards and physically withdraw the cash, working from a list of PINs and limits.

The issuer or processor

The financial institution or vendor whose systems were compromised and whose controls were switched off, making the withdrawals authorize.

The ATM owner

The bank or independent operator whose machines and cash reserves are physically drained, especially in jackpotting attacks.

What it looks like in practice

Over a single weekend, a mid-sized card program sees roughly twenty account numbers used for hundreds of ATM withdrawals in a dozen cities at once. Each card, which would normally hit a daily cap after a few hundred dollars, is pulling thousands, again and again, because a breach earlier that week quietly removed the withdrawal limits on those accounts.

The transactions authorize cleanly because the balance and limit checks have been bypassed at the processor. By the time an analyst spots the impossible pattern on Monday, the same card numbers have withdrawn far more than the accounts ever held, and the cash is long gone.

Why it matters for operators

Cash-out attacks turn a small foothold into a large, immediate loss. Because the money leaves as physical cash, there is nothing to reverse and no chargeback to chase. A handful of compromised cards can generate losses that dwarf normal fraud, all inside a few hours, which makes early detection and hard limits far more valuable than after-the-fact investigation.

They are also a signal of something worse. A cash-out almost always means an attacker already had deep access to a processor or issuer system, or physical access to machines. Treating the withdrawals as ordinary card fraud misses the real problem: your controls were disabled, and whoever did that may still be inside.

What to watch in the data

  • Same card, many places. One account number authorizing withdrawals in several cities in a short window is physically impossible for a real cardholder.
  • Limits ignored. Approved withdrawals that exceed the account's daily cap or available balance point to controls being bypassed upstream.
  • Off-hours spikes. Sudden clusters of ATM activity late at night or over a weekend, when staffing and monitoring are thin, are a common attack window.
  • Repeated max amounts. The same maximum-allowed sum withdrawn over and over on a small set of cards is a cash-out fingerprint, not organic spending.
  • Full-cassette dispenses. A machine emptying its entire cash load in one session, or errors around the dispenser, can indicate jackpotting malware or a physical device.

Quick questions

How is a cash-out attack different from regular card skimming?

Skimming steals card data one victim at a time and spends it gradually. A cash-out attack pairs stolen data with disabled account controls or compromised machines so a few cards can be drained at scale in a single coordinated burst.

What is jackpotting?

Jackpotting is the variant where the ATM itself is attacked. Criminals install malware or a hardware device that commands the machine to dispense all the cash in its cassettes, regardless of any account. It targets the machine, not a cardholder's balance.

Why do these happen on weekends?

Weekends and holidays have thinner staffing, slower fraud review, and longer gaps before systems reconcile. That delay gives crews more time to withdraw before anyone notices the pattern and shuts the cards down.

Who absorbs the loss?

It usually falls on the compromised issuer or processor, since the accounts were drained through their systems and controls. The exact split depends on network rules and the contracts between the parties, but the cash itself is unrecoverable.

Can limits alone stop it?

Hard limits enforced independently of the compromised system help a lot, because the attack relies on removing those caps. Velocity checks, geographic impossibility rules, and real-time monitoring across machines add the layers a single limit cannot.

What should a team do mid-attack?

Freeze the affected card numbers and account ranges immediately, block further authorizations, alert the network and law enforcement, and start hunting for how the controls were disabled, because the withdrawals are a symptom of a deeper breach.

ATM cash-out attackと併せて知っておきたい用語

レポート

2026年 不正・AMLレポート

予測は不要です。このレポートは、不正・AMLチームが実際に直面していることと、その対応方法を分解して解説します。

レポートをダウンロード