ATMs Hacked to Dispense Cash Without Cards

Credit: Patrick Foto/Shutterstock

(Image credit: Patrick Foto/Shutterstock)

Avoiding credit-card scams is easy as long as you use cash. What happens when getting cash proves just as perilous? Hackers have developed a very sophisticated ATM hack that's almost impossible to detect, requires neither an ATM card nor a preexisting PIN, and is being used in the United States.

Moscow-based security firm Kaspersky Lab covered the issue on its blog, explaining that ATM scams are on the rise worldwide. The company's native Russia is a particular hotspot, but the U.S. is second in the number of reported infections.

MORE: Best Mac Antivirus Software 2014

Scammers start by unlocking an ATM's enclosure, probably with a default master key, and using a CD to infect the machine with a piece of malware known as Backdoor.MSIL.Tyupkin. Days later, they return to the machine and use Tyupkin to dispense up to 40 bills without the need for verification.

Tyupkin only works on ATMs that run Windows 32-bit operating systems and are made by a major manufacturer that Kaspersky Lab did not name. Furthermore, Tyupkin accepts commands only in the dead of night on certain days of the week, keeping the exploit well-hidden most of the time.

When a malefactor does run the program, he or she needs a specially generated PIN based on an algorithm unique to the malware. Then, he or she can withdraw 40 bills at a time directly from the ATM: no user account required.

The good news (if you can call it that) is that since the hack affects ATMs directly, everyday users don't need to worry about this particular hack too much, unless their bank eventually folds due to nonstop theft.

Banks can theoretically also catch malefactors in the act with security cameras, since the scammers must be on-premises both to install the malware and withdraw cash. However, it's difficult to differentiate a scammer and a regular customer from afar, especially if they're blocking the screen with their bodies.

Kaspersky Lab suggests that banks change the locks on their ATM enclosures, since criminals often have master keys, and install physical alarms to go off when an ATM enclosure is opened. Banks that don't tighten their security could find their oversights very costly.

Marshall Honorof is a Staff Writer for Tom's Guide. Contact him at mhonorof@tomsguide.com. Follow him @marshallhonorof and on Google+. Follow us @tomsguide, on Facebook and on Google+.

TOPICS
Marshall Honorof

Marshall Honorof is a senior editor for Tom's Guide, overseeing the site's coverage of gaming hardware and software. He comes from a science writing background, having studied paleomammalogy, biological anthropology, and the history of science and technology. After hours, you can find him practicing taekwondo or doing deep dives on classic sci-fi. 

Latest in Online Security
A magnifying glass on top of the Steam logo in a web browser
Valve just pulled a malicious game demo spreading info-stealing malware from Steam
A man filing his taxes electronically on a laptop
AI-powered tax scams are here - how to stay safe from deepfakes, phishing and more this tax season
MacBook Pro 2023
New Mac attack is tricking users into thinking their computer is locked — how to stay safe
Hacker using a stolen social security card
Your Social Security number is a literal gold mine for scammers and identity thieves — here’s how to keep it safe
An open lock depicting a data breach
Half a million teachers hit in major data breach with SSNs, financial data and more exposed — what to do now
Green skull on smartphone screen.
Malicious Android apps with 60 million installs bombarding phones with ads and phishing attacks — how to stay safe
Latest in News
Apple Watch SE (2022) shown on wrist
Apple Watch SE 3 reportedly in ’serious jeopardy’ — here’s why
Galaxy S25 Plus held in the hand.
Samsung could delay One UI 7’s release in the US — here’s what we know
Claude AI on phone sitting on keyboard
Claude 3.7 Sonnet now supports real-time web searching — but there's a catch
Nintendo Switch 2
Nintendo Switch 2 pre-order date just tipped — here's when you might be able to buy
Apple iPhone 16 & 16 Plus hands-on.
iPhone 17 just tipped for this long overdue Pro feature in new report
Android 16 screen-off fingerprint unlock in Settings menu
Android 16's latest beta lets all Pixel users unlock their phone more easily — here’s how
  • WISDOMTECH
    WISDOM TECH of the email address. (wisdomtechatmhackers@gmail.com) its at it again! Cool way to have financial freedom!!! Are you tired of living a poor life,then here is the opportunity you have been waiting for. Get the new ATM BLANK CARD that can hack any ATM MACHINE and withdraw money from any account. You do not require anybody's account number before you can use it. Although you and I knows that its illegal,there is no risk using it. It has SPECIAL FEATURES, that makes the machine unable to detect this very card,and its transaction is can't be traced . You can use it anywhere in the world. With this card,you can withdraw nothing less than $50,000 in a day. So to get the card,reach the hackers via email address : wisdomtechatmhackers@gmail.com.
    Reply