Part IV: Financial Fraud · Chip, Cash & Ticket Fraud
ATM Jackpotting (Malware-Based Theft)
How it works
Criminals gain physical access to ATM internals (often by posing as service technicians) and install malware that forces the machine to dispense all its cash on command. The Ploutus malware family, first identified in Mexico in 2013, has been used in operations across the United States. In 2025, the DOJ indicted 54 individuals in a multi-million-dollar jackpotting scheme. Crews would scout bank and credit union ATMs, open panels to install malware via external devices or hard drive swaps, then use activation codes to trigger cash dispensing.
Where it appears
Casino floor ATMs, standalone ATMs in less-monitored areas
On the record
Ploutus malware first appeared in Mexico (2013) and has since spread globally. The 2025 DOJ indictment of 54 individuals represented one of the largest ATM jackpotting prosecutions in U.S. history. While primarily targeting banks, casino ATMs are equally vulnerable.
Published as a detection reference for surveillance, compliance and gaming-operations professionals. Thresholds and tuning are set by the property. Nothing here is instruction — the method is described so it can be recognised.