Cook Solutions Group

Man-in-the-Middle ATM Attacks: Securing Financial Systems Against MITM Fraud

Published:
August 14, 2026
/
Man-in-the-Middle ATM Attacks: Securing Financial Systems Against MITM Fraud

Watch: ATM Man-in-the-Middle Attacks Explained

In this episode of the Bank Customer Experience Podcast, CSG experts return for an update on man-in-the-middle (MITM) ATM attacks — now the most common logical attack they're seeing in the field. They break down how these attacks have evolved toward wireless, remotely controlled black boxes and server spoofing, walk through a real attack step by step, and explain the layered defenses that stop them — from alarmed top hats and better surveillance to TLS 1.2 Enhanced with certificate pinning at the host level.

Key moments

  • 00:56 — What is a man-in-the-middle ATM attack?
  • 04:31 — A typical attack, step by step: recon, testing defenses, interception, cash harvesting, and cleanup
  • 10:27 — How CSG works with the Secret Service and FBI on investigations
  • 12:56 — Are white-label and independently owned ATMs targeted too?
  • 13:24 — The layers of security every financial institution should have in place
  • 18:56 — The host-level defense: TLS 1.2 Enhanced with certificate pinning

Abstract:

A man-in-the-middle (MITM) attack targets ATMs and ITMs by placing a device between the machine and its host, letting criminals intercept, eavesdrop on, modify, or impersonate the communications that authorize transactions. This article breaks down how these attacks work — including a real black-box example built from a Raspberry Pi and USB-to-Ethernet adapters — and how the threat has evolved.

MITM attacks reach ATMs two ways: physical access at the machine, or lateral movement through a financial institution's network, most often starting with email phishing. We cover practical defenses for both, from user training and network segmentation to hiding cables, MAC address filtering, and confirming your ATM host uses TLS 1.2 Enhanced with certificate pinning.

Finally, we look at how CSG helps financial institutions detect and respond to these attacks — through RemoteView with quarterly patching and the Security+ module, Smart Camera Analytics for real-time surveillance and managed response, and investigation support that helps recover evidence after an incident.

Man in the Middle Attacks

Introduction: What is a Man-in-the-Middle (MITM) attack?

A Man-in-the-Middle(MITM) attack occurs by placing a device between the ATM and the Host. There are two methods for MITM attacks. The attacker can gain access via malware or via a “black box”.  There are four main goals for MITM attacks: Interception, Eavesdropping, Modification, and/or Impersonation. In the picture below, you can see an example of what one of these Black-Box attacks looks like:

Raspberry Pi black-box device wired inline between an ATM and its network connection

In this example, the attacker used a Raspberry PI that was preprogrammed with malicious code and  USB-to-Ethernet adapters to intercept communications between the ATM and the Network.

Anatomy of an ATM Attack

How a Man-in-the-Middle ATM Attack Unfolds

Man-in-the-middle ATM attacks are typically coordinated operations that develop in stages — from reconnaissance and testing to network interception, fraudulent withdrawals, and cleanup.

01

Reconnaissance

The crew surveys the ATM, photographs the environment, and identifies potential access points and security measures.

02

Testing the Response

Attackers may briefly tamper with the ATM enclosure to see whether alarms trigger, the machine goes offline, or anyone responds.

04

Fraudulent Cash Withdrawal

Once communications are compromised, fraudulent transactions may appear authorized, allowing attackers to withdraw significant amounts of cash.

05

Cleanup & Return

The equipment is removed and the ATM may be returned to normal operation, making the incident difficult to detect immediately. Organized crews may return after the ATM has been replenished.

Why These Attacks Can Be Difficult to Spot

A sophisticated MITM attack may create only a brief service interruption. By the time a cash shortage is discovered, the unauthorized equipment may already be gone and the ATM may appear to be operating normally.

This is organized crime, not opportunistic vandalism. These attacks can involve coordinated teams performing reconnaissance, testing security responses, carrying out the attack, and returning to previously targeted machines.

The Problem: How does it happen?

For a MITM black-box attack to take place, the attacker must first access the LAN network cable via the top hat of the ATM or the network jack in the wall. Once they have access, the attacker plugs in their device “in-line” with the existing connection. The attacker may also opt for connecting directly to the cash dispenser in the machine and send commands directly to the dispenser to empty its cassettes.

As mentioned earlier, not all MITM attacks require physical access to an ATM these days. Another way this can be accomplished is via lateral movement through a Financial Institution's network. Email Phishing is the most common way network access is obtained.

 

Diagram of a MITM attack spreading through a financial institution's network to ATMs

The Solution: What steps can I take to mitigate my risk?

To ensure that your network and ATMs are secure, there are several things your Financial Institution can do today.

  • Train all end users on phishing, smishing, and other similar attacks and how to properly spot and report them.
  • From a networking perspective, ensure that your ATMs are segmented off from the rest of your network. This will make it much harder for attackers to gain access to your machines.
  • Protect your network by ensuring that all network cables are hidden from view. Consider employing MAC address filtering across your network if it is not already. This will ensure that only authorized devices can access your network.  

In addition to these immediate solutions, CSG offers several solutions that directly relate to mitigation of MITM attacks. Here are a couple of highlights:

  • All ATMs on CSG’s RemoteView product are protected with quarterly windows patches and our Security+ module. Security+ uses Blackberry’s Cylance PROTECT to lock down all peripheral device access and protection from zero-day attacks.
  • CSG’s Smart Camera Analytics provide real-time notifications with surveillance footage to detect loitering, vandalism, and fraud. In addition to the real-time notifications, our Managed Services team can remotely take your ATM out of service or shut it down to stop an attack in its tracks.
  • Confirm your ATM host or processor has TLS 1.2 Enhanced with certificate pinning enabled. Standard TLS 1.2 can be defeated by server spoofing with a generic certificate; certificate pinning requires a specific trusted certificate for the transaction to authorize.
  • Alarm your top hats + have a response procedure

 

References:

Amado, J. (2020, July 14). Sepio Cyber.  Retrieved from Black Box Attack :  https://sepiocyber.com/blog/atm-black-box-attacks/

Cook Solutions Group. (n.d.). Application Control  & Patch Management. Retrieved from Cook Solutions Group:  https://www.cooksolutionsgroup.com/managed-services/security-modules-patch-management

Cook Solutions Group. (n.d.). How much time does  your IT staff spend to support your security and ATM/ITM infrastructure?  Retrieved from Cook Solutions Group:  https://www.cooksolutionsgroup.com/managed-services-new/network-operations-center

Gemert, W. v. (n.d.). NCR. Retrieved from  EuroPol_Guidance-Recommendations-ATM-logical-attacks:  https://www.ncr.com/content/dam/ncrcom/content-type/brochures/EuroPol_Guidance-Recommendations-ATM-logical-attacks.pdf

H4cksploit. (2023, May 8). Hacking Atms Using  Black Box. ATMJackpotting. Retrieved from Medium: https://h4cksploit.medium.com/hacking-atms-using-black-box-atmjackpotting-dd3056abcc9e

Minin, R. (2021, January 25). Man in the Middle  Attack . Retrieved from Sepio Cyber:  https://sepiocyber.com/blog/man-in-the-middle-attack/

CSG's unique approach against multiple types of ATM fraud.

Our strategy extends beyond traditional surveillance, incorporating real-time monitoring, intelligent analytics, and proactive threat detection. Our approach is based on a layered security strategy that addresses various vulnerabilities, including:

  • Hook & Chain, Physical Attacks: Fortify terminals against brute force attacks aiming to extract cash.
  • Reg E Claims: Support compliance with Regulation E by providing evidence and transaction verification to resolve disputes.
  • Software Vulnerabilities: Utilize AI based Endpoint Security to shield the ATM operating system from malware and other cyber threats.
  • Data Compliance: Ensure the confidentiality and integrity of data stored on terminal hard drives using hard drive encryption.
  • Card Skimming, Deep Insert and Cash Harvesting: Prevent unauthorized data capture and cash removal from terminals.
  • Terminal Jackpotting: Guard against unauthorized software manipulation aiming to dispense cash fraudulently.
  • Cash Dispensing and Cash Trapping: Secure dispensing mechanisms from tampering and unauthorized cash trapping devices.
  • Transaction Reversal Fraud (TRF): Protect against manipulation techniques that reverse transactions to withdraw cash.
  • Man-in-the-Middle (MITM) Attacks: By placing a device between the ATM and the Host, attackers pursue objectives such as interception, eavesdropping, modification, and impersonation.
ATM Security FAQs

Man-in-the-Middle ATM Attack FAQs

Learn how man-in-the-middle attacks target ATMs, how black-box devices manipulate network communications, and what financial institutions can do to reduce their risk.

What is a man-in-the-middle ATM attack?

A man-in-the-middle (MITM) ATM attack is a physical network attack in which a criminal inserts a device, often called a "black box," between the ATM's computer and its network connection. The device intercepts communications between the ATM and the host network.

Once connected, the attacker may be able to collect information, redirect network traffic, or impersonate the ATM host. This can allow fraudulent transactions to appear authorized and cause the ATM to dispense cash.

How does a man-in-the-middle attack work on an ATM?

Attackers typically gain physical access to the ATM's network connection, disconnect the Ethernet cable, and insert a small computer or "black box" between the ATM and the network.

The ATM continues communicating through the device, allowing the attacker to intercept or manipulate network traffic. If the ATM cannot properly authenticate the host it is communicating with, the attacker's device may be able to send fraudulent authorization commands back to the ATM.

Can independently owned or white-label ATMs be targeted by MITM attacks?

Yes. Man-in-the-middle attacks are not limited to bank-owned ATMs. White-label ATMs, independently operated ATMs, and other payment machines can also be vulnerable if an attacker can access and manipulate their network communications.

Any device that facilitates the transfer or dispensing of money can potentially become a target.

How can financial institutions help prevent man-in-the-middle ATM attacks?

One important host-level defense is TLS 1.2 Enhanced with certificate pinning. Certificate pinning requires the ATM to verify a specific trusted certificate before allowing communication with the host to continue.

This helps prevent an attacker from inserting a device that impersonates the legitimate ATM host. Financial institutions should ask their ATM host or processor whether TLS 1.2 Enhanced and certificate pinning are enabled for their ATM fleet.

Physical security, network monitoring, ATM hardening, network segmentation, and controlling access to network connections should also be part of a layered ATM security strategy.

Is regular TLS 1.2 enough to protect an ATM from a man-in-the-middle attack?

TLS 1.2 provides encrypted communication, but encryption alone does not necessarily prevent every physical man-in-the-middle attack. Certificate validation and certificate pinning provide an additional layer of protection by helping ensure the ATM communicates only with the intended host.

Financial institutions should verify with their ATM host or processor exactly how certificates are validated and whether enhanced security controls such as certificate pinning are enabled.

How does Cook Solutions Group help investigate ATM man-in-the-middle attacks?

Cook Solutions Group can assist law enforcement agencies, including the U.S. Secret Service and FBI, with evidence recovery following ATM attacks.

Because an ATM's electronic journal may retain records of card activity, transaction requests, authorizations, and cash dispensed, CSG technicians can help recover information that may assist investigators in reconstructing an incident.

CSG can also help customers retrieve relevant surveillance footage through the Piko video surveillance platform, including potential face captures, vehicle information, license plates, and other evidence that may support an investigation.

Access white-papers & guides content:

Access our exclusive white-papers
Your message has been sent. Thank you for getting in touch with us!
Sorry, something seems to be missing. Make sure you have filled in all the required fields.