We have received multiple reports of an increase Man in the Middle (MITM) attacks targeting ATMs in the Pacific Northwest and across the United States. All ATM manufacturers are susceptible to this type of attack which targets the physical network infrastructure. A key difference with this current round of MITM attacks is they can defeat basic TLS 1.2.
We recommend the following actions are taken immediately:
· Verify top hat of ATM is alarmed and create a response plan for active alarms to include historical footage review.
· Contact your ATM Host to confirm availability of TLS 1.2 Enhanced.
· Confirm BIOS and firmware are up to date with the latest security releases.
· Verify HDE encryption is enabled on all ATMs.
· Inspect for tampering daily.
· Increase monitoring through Command Center or other remote management tools.
· Report any suspicious activity to the NOC immediately.
These attacks are highly coordinated and often occur after hours. Quick reporting and verification of system integrity are critical in preventing losses. For RVATM users you can confirm HDE, BIOS version and TLS 1.2 Enhanced via Command Center. If you have any questions, please open a ticket with our Support team by visiting cc.cooksolutionsgroup.com or via email at Support@cooksolutionsgroup.com.