Search
00
GBAF Logo
trophy
Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

Subscribe to our newsletter

Get the latest news and updates from our team.

Global Banking & Finance Review®

Global Banking & Finance Review® - Subscribe to our newsletter

Company

    GBAF Logo
    • About Us
    • Advertising and Sponsorship
    • Profile & Readership
    • Contact Us
    • Latest News
    • Privacy & Cookies Policies
    • Terms of Use
    • Advertising Terms
    • Issue 81
    • Issue 80
    • Issue 79
    • Issue 78
    • Issue 77
    • Issue 76
    • Issue 75
    • Issue 74
    • Issue 73
    • Issue 72
    • Issue 71
    • Issue 70
    • View All
    • About the Awards
    • Awards Timetable
    • Awards Winners
    • Submit Nominations
    • Testimonials
    • Media Room
    • FAQ
    • Asset Management Awards
    • Brand of the Year Awards
    • Business Awards
    • Cash Management Banking Awards
    • Banking Technology Awards
    • CEO Awards
    • Customer Service Awards
    • CSR Awards
    • Deal of the Year Awards
    • Corporate Governance Awards
    • Corporate Banking Awards
    • Digital Transformation Awards
    • Fintech Awards
    • Education & Training Awards
    • ESG & Sustainability Awards
    • ESG Awards
    • Forex Banking Awards
    • Innovation Awards
    • Insurance & Takaful Awards
    • Investment Banking Awards
    • Banking Awards
    • Banking Innovation Awards
    • Digital Banking Awards
    • Finance Awards
    • Investor Relations Awards
    • Leadership Awards
    • Islamic Banking Awards
    • Real Estate Awards
    • Project Finance Awards
    • Process & Product Awards
    • Telecommunication Awards
    • HR & Recruitment Awards
    • Trade Finance Awards
    • The Next 100 Global Awards
    • Wealth Management Awards
    • Travel Awards
    • Years of Excellence Awards
    • Publishing Principles
    • Ownership & Funding
    • Corrections Policy
    • Editorial Code of Ethics
    • Diversity & Inclusion Policy
    • Fact Checking Policy
    • Financial Awards
    • Private Banking Awards
    • Private Banking Innovation Awards
    • Retail Banking Awards
    Original content: Global Banking and Finance Review - https://www.globalbankingandfinance.com

    A global financial intelligence and recognition platform delivering authoritative insights, data-driven analysis, and institutional benchmarking across Banking, Capital Markets, Investment, Technology, and Financial Infrastructure.

    Copyright © 2010-2026 - All Rights Reserved. | Sitemap | Tags

    Editorial & Advertiser disclosure

    Global Banking & Finance Review® is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website.

    1. Home
    2. >Top Stories
    3. >Consumer Card Controls Could Have Prevented $11.5m ATM Heist
    Top Stories

    Consumer Card Controls Could Have Prevented $11.5m Atm Heist

    Published by Gbaf News

    Posted on September 18, 2018

    8 min read

    Last updated: January 21, 2026

    Add as preferred source on Google
    This image illustrates the financial challenges faced by Thames Water, including its restructuring efforts and the conflict with Class B creditors. The article discusses how the utility company aims to stabilize its finances amid competing plans.
    Thames Water financial restructuring proposal amidst Class B creditor dispute - Global Banking & Finance Review
    Why waste money on news and opinion when you can access them for free?

    Take advantage of our newsletter subscription and stay informed on the go!

    Subscribe

    Global Banking & Finance Awards 2026 — Now Open for Entries
    Tags:Digital transformationEscalating fraud epidemicThird-party vulnerabilities
    Global Banking & Finance Awards 2026 — Call for Entries

    Gordon McKenzie,EMEA MD at Ondot Systems explores how consumer card controls can tackle the challenge of ATM cashouts

    Wherever there are users and money there will be cybercrime and fraud. So it is that financial institutions and their customers are increasingly being targeted by global attackers. Most recently, Indian lender Cosmos Bank lost $11.5m after an international criminal network fraudulently withdrew funds from ATMs in 28 countries around the world. That’s despite a warning from the FBI that an “ATM cashout” operation was imminent.

    In our 24×7, digital-first society customers increasingly expect to be empowered with greater control over card management.

    It’s a move that could have saved this financial institution, and many more like it, millions in losses and brand damage.

    Out of control

    ATM cashouts typically happen at smaller banks where security controls are less rigorously implemented, there’s less budget to throw at the problem and third-party vulnerabilities may be more obvious, according to the FBI’s warning. Global gangs usually phish or hack their way into back-end systems. Just before the allotted hour, they’ll often remove internal fraud controls such as maximum ATM withdrawal amounts and limits on volume of daily withdrawals, and may also artificially increase customer balances. Forged magstripe cards are then used around the world to withdraw funds in a highly co-ordinated campaign.

    This is certainly not the first ATM-based cyber-attack: in 2013 cyber-criminals stole $45m from ATMs, and in 2016 over $12m was taken from cashpoints in Japan using cards cloned from a South African bank. However, the bad news, according to the FBI, is that it “expects the ubiquity of this activity to continue or possibly increase in the near future.” ATMs — unmanned and usually loaded with cash — are also particularly vulnerable to external tampering. Attackers can quite easily attach “skimmers” to the front of the card reader slot to read card info as it’s pushed into the machine, and overlay pads which record the card’s PIN, or motion-activated cameras to record the same information. That provides everything they need to create a clone. It’s no surprise that ATM-maker Diebold Nixdorf has described skimming as a $2bn+ problem globally.

    These ATM attacks are also part of a wider pattern of soaring global card fraud. In the UK alone, an estimated £2bn+ was stolen from the bank accounts of cardholders last year, a 38% rise from the previous 12 months. Other figures pointed to steep rises in e-commerce fraud (24%) and fraudulent applications for cards (12%). The bottom line is that as financial institutions and organisations undergo digital transformation to become more competitive, agile and innovative, they’re also exposing their systems to increasingly well resourced and determined cyber-criminals. The vast underground cybercrime economy has effectively democratised access to customer account data, PII, and hacking tools while the anonymising power of the dark web and crypto-currencies have significantly reduced the risk of getting caught. The result? A thriving threat landscape.

    Time for change

    So what’s the answer? Thousands of financial institutions around the world have already woken up to the possibilities of card control applications. Offering granular control to cardholders through a simple mobile app interface can —amongst other things — empower them to restrict usage of certain transactions. That means in the event of an ATM cashout warning, accounts could be locked down so that even spoofed cards won’t work. If a user needs emergency cash, they can temporarily enable ATM withdrawals, get the money and then disable ATM transactions again. And, while ATM withdrawals are blocked, a user could still enable in-person, e-commerce or other types of transaction.

    This granularity extends across a range of scenarios, allowing cardholders to decide where in the world their cards can be used, as well as spending limits, time frames and even merchant categories. It’s all about providing maximum visibility and control over how cards are used, with transaction alerts provide peace of mind when consumers need it most.

    Financial institutions can not only reduce fraud rates in this way but also lower call centre costs, improve false decline rates, drive greater use of cards and build closer bonds with their customers. In our always-on, 24×7 world there are opportunities round-the-clock for the bad guys to expose gaps in protection. By handing more control back to the consumer to self-serve, financial institutions are already adding value and supporting digital transformation whilst protecting them and their customers from an escalating fraud epidemic.

    The fraud and threat landscape is constantly evolving. That’s why, in order to succeed, our response must be just as innovative.

    Gordon McKenzie,EMEA MD at Ondot Systems explores how consumer card controls can tackle the challenge of ATM cashouts

    Wherever there are users and money there will be cybercrime and fraud. So it is that financial institutions and their customers are increasingly being targeted by global attackers. Most recently, Indian lender Cosmos Bank lost $11.5m after an international criminal network fraudulently withdrew funds from ATMs in 28 countries around the world. That’s despite a warning from the FBI that an “ATM cashout” operation was imminent.

    In our 24×7, digital-first society customers increasingly expect to be empowered with greater control over card management.

    It’s a move that could have saved this financial institution, and many more like it, millions in losses and brand damage.

    Out of control

    ATM cashouts typically happen at smaller banks where security controls are less rigorously implemented, there’s less budget to throw at the problem and third-party vulnerabilities may be more obvious, according to the FBI’s warning. Global gangs usually phish or hack their way into back-end systems. Just before the allotted hour, they’ll often remove internal fraud controls such as maximum ATM withdrawal amounts and limits on volume of daily withdrawals, and may also artificially increase customer balances. Forged magstripe cards are then used around the world to withdraw funds in a highly co-ordinated campaign.

    This is certainly not the first ATM-based cyber-attack: in 2013 cyber-criminals stole $45m from ATMs, and in 2016 over $12m was taken from cashpoints in Japan using cards cloned from a South African bank. However, the bad news, according to the FBI, is that it “expects the ubiquity of this activity to continue or possibly increase in the near future.” ATMs — unmanned and usually loaded with cash — are also particularly vulnerable to external tampering. Attackers can quite easily attach “skimmers” to the front of the card reader slot to read card info as it’s pushed into the machine, and overlay pads which record the card’s PIN, or motion-activated cameras to record the same information. That provides everything they need to create a clone. It’s no surprise that ATM-maker Diebold Nixdorf has described skimming as a $2bn+ problem globally.

    These ATM attacks are also part of a wider pattern of soaring global card fraud. In the UK alone, an estimated £2bn+ was stolen from the bank accounts of cardholders last year, a 38% rise from the previous 12 months. Other figures pointed to steep rises in e-commerce fraud (24%) and fraudulent applications for cards (12%). The bottom line is that as financial institutions and organisations undergo digital transformation to become more competitive, agile and innovative, they’re also exposing their systems to increasingly well resourced and determined cyber-criminals. The vast underground cybercrime economy has effectively democratised access to customer account data, PII, and hacking tools while the anonymising power of the dark web and crypto-currencies have significantly reduced the risk of getting caught. The result? A thriving threat landscape.

    Time for change

    So what’s the answer? Thousands of financial institutions around the world have already woken up to the possibilities of card control applications. Offering granular control to cardholders through a simple mobile app interface can —amongst other things — empower them to restrict usage of certain transactions. That means in the event of an ATM cashout warning, accounts could be locked down so that even spoofed cards won’t work. If a user needs emergency cash, they can temporarily enable ATM withdrawals, get the money and then disable ATM transactions again. And, while ATM withdrawals are blocked, a user could still enable in-person, e-commerce or other types of transaction.

    This granularity extends across a range of scenarios, allowing cardholders to decide where in the world their cards can be used, as well as spending limits, time frames and even merchant categories. It’s all about providing maximum visibility and control over how cards are used, with transaction alerts provide peace of mind when consumers need it most.

    Financial institutions can not only reduce fraud rates in this way but also lower call centre costs, improve false decline rates, drive greater use of cards and build closer bonds with their customers. In our always-on, 24×7 world there are opportunities round-the-clock for the bad guys to expose gaps in protection. By handing more control back to the consumer to self-serve, financial institutions are already adding value and supporting digital transformation whilst protecting them and their customers from an escalating fraud epidemic.

    The fraud and threat landscape is constantly evolving. That’s why, in order to succeed, our response must be just as innovative.

    More from Top Stories

    Explore more articles in the Top Stories category

    Image for Why Global Supply Chains Are Becoming Smarter, Faster, and More Resilient
    Why Global Supply Chains Are Becoming Smarter, Faster, and More Resilient
    Image for Why Workforce Agility Is Becoming Critical in the Future of Work
    Why Workforce Agility Is Becoming Critical in the Future of Work
    Image for Why Global Trade Is Entering a New Era of Resilience and Reinvention
    Why Global Trade Is Entering a New Era of Resilience and Reinvention
    Image for Why Cybersecurity Is Becoming a Core Business Priority in the Digital Economy
    Why Cybersecurity Is Becoming a Core Business Priority in the Digital Economy
    Image for Why Data-Driven Decision-Making Is Becoming the Backbone of Modern Business Strategy
    Why Data-Driven Decision-Making Is Becoming the Backbone of Modern Business Strategy
    Image for How Real-Time Data Is Redefining Decision-Making in the Digital Economy
    How Real-Time Data Is Redefining Decision-Making in the Digital Economy
    Image for Why Cash Flow Visibility Is Becoming the Most Critical Metric for Business Survival
    Why Cash Flow Visibility Is Becoming the Most Critical Metric for Business Survival
    Image for How Digital Payments Are Redefining the Speed and Scale of Global Commerce
    How Digital Payments Are Redefining the Speed and Scale of Global Commerce
    Image for How Digital Transformation Is Reshaping Business Models Across Industries
    How Digital Transformation Is Reshaping Business Models Across Industries
    Image for How Artificial Intelligence Is Transforming Productivity Across Global Industries
    How Artificial Intelligence Is Transforming Productivity Across Global Industries
    Image for Lessons From the Ring and the Deal Table: How Boxing Shapes Steven Nigro’s Approach to Banking and Life
    Lessons From the Ring and the Deal Table: How Boxing Shapes Steven Nigro’s Approach to Banking and Life
    Image for Joe Kiani in 2025: Capital, Conviction, and a Focused Return to Innovation
    Joe Kiani in 2025: Capital, Conviction, and a Focused Return to Innovation
    View All Top Stories Posts
    Previous Top Stories PostThe Evolution of Digital Assets Regulation: Past, Present and Future
    Next Top Stories PostBrexit May Not Spell the End of London— As Long as It’s a Soft Brexit