Skip to main content
  1. Home
  2. Computing
  3. News

Hackers are targeting ATMs and stealing wads of cash

Add as a preferred source on Google

Hackers are targeting ATMs with malicious software that forces the machines to spew out cash, according to a new report from a cybersecurity firm.

Group IB said has it discovered a hacker group called Cobalt that had attacked ATMs in more than a dozen countries in Europe and Asia, including the U.K. and Russia. The “smash and grab” attacks were coordinated from unknown command centers. They don’t require any physical tampering of the ATMs but the hackers do need someone to be present when the attack happens so they can collect the wads of cash from the ATM.

Recommended Videos

No banks have been named but ATM manufacturers Diebold Nixdorf and NCR Corp have stated that they are aware of the attacks and are working with banks to add new protections.

Nicholas Billett, head of Diebold Nixdorf’s ATM security, said the hackers have gone to the “next level” by attacking huge numbers of ATMs at the same time: “They know they will be caught fairly quickly, so they stage it in such a way that they can get cash from as many ATMs as they can before they get shut down.”

Several other countries were named as victims in Group IB’s report such as the Netherlands, Spain, Malaysia, and Moldova with more attacks predicted in the future if banks and ATM makers don’t take action.

“Logical attacks on ATMs are expected to become one of the key threats targeting banks: they enable cybercriminals to commit fraud remotely from anywhere globally and attack the whole ATM network without being ‘on the radar’ of security services,” said Dmitry Volkov, Group IB’s head of investigation.

Volkov added that the malware used in these attacks isn’t particularly sophisticated and can be easily acquired on the deep web.

In its last report, EU law enforcement agency Europol warned that remote ATM attacks will “evolve and proliferate.”

Different kinds of ATM attacks aren’t new but have become more prevalent, and include skimmers that have been physically installed on machines to steal info off cards. Earlier this year, a bank in Taiwan suspended withdrawals after more than $2 million was allegedly stolen from ATMs using malware.

This marks a significant move for cybercriminals who are finding new ways to pilfer cash. Stealing credit card numbers is one thing but in February we saw hackers steal a staggering $81 million from the Bangladesh central bank. They targeted vulnerabilities in SWIFT, the global banking industry’s messaging network. And now the financial sector has remote ATM hacking to worry about, too.

Jonathan Keane
Jonathan is a freelance technology journalist living in Dublin, Ireland. He's previously written for publications and sites…
Your favorite Edge extension may stop working soon as Microsoft follows Chrome’s lead
Microsoft has announced the transition to Manifest V3, gradually phasing out older browser extensions.
Microsoft Edge on PC and Mobile Featured

Microsoft Edge is finally making the same controversial move that Google Chrome did earlier this year, and it could mean the end of some of the browser's most popular ad blockers. Microsoft has announced that Edge is officially transitioning its extensions ecosystem to Manifest Version 3 (MV3), Google's newer extension platform that promises better security, privacy, and performance. As part of that shift, the browser will gradually stop supporting older Manifest V2 (MV2) extensions over the coming months, meaning legacy extensions such as the original uBlock Origin will eventually stop working in Edge.

What is Manifest V3, and why is Microsoft adopting it?

Read more
Help, I’m talking to my computer. It’s remarkably convenient and utterly embarrassing.
Oh look, I have become the guy who randomly starts talking while staring at his computer.
Person using a laptop.

A decade ago, Google introduced voice typing with the Gboard app on Android, and a year later, the perk landed on iPhones with the keyboard app. I never paid much attention to it. The biggest reason was that it was just not accurate. 

The big promise was a whole new way of interacting with our phones, but it was never good enough to make me quit tapping, or swiping on an on-screen keyboard. Fast forward to 2026, I'm talking to my computer. In fact, this whole article was dictated and copy-pasted in WordPress. 

Read more
Cloudflare’s new browser Kitesurf is designed for AI agents to browse the internet
AI agents just got their own browser that lets them browse the internet more efficiently.
cloudflare-kitesurf-browser-for-ai

Cloudflare just entered the AI-browser race with a twist. Instead of building another Chrome alternative for people, the company launched Kitesurf, a cloud-hosted browser made only for AI agents. Since autonomous AI systems are increasingly the ones doing the actual browsing and scrolling online, Cloudflare just made its to claim that space.

https://twitter.com/Cloudflare/status/2085372860650913898

Read more