Search
00
GBAF Logo
trophy
Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

Subscribe to our newsletter

Get the latest news and updates from our team.

Global Banking and Finance Review

Global Banking & Finance Review

Company

    GBAF Logo
    • About Us
    • Profile
    • Privacy & Cookie Policy
    • Terms of Use
    • Contact Us
    • Advertising
    • Submit Post
    • Latest News
    • Research Reports
    • Press Release
    • Awards▾
      • About the Awards
      • Awards TimeTable
      • Submit Nominations
      • Testimonials
      • Media Room
      • Award Winners
      • FAQ
    • Magazines▾
      • Global Banking & Finance Review Magazine Issue 79
      • Global Banking & Finance Review Magazine Issue 78
      • Global Banking & Finance Review Magazine Issue 77
      • Global Banking & Finance Review Magazine Issue 76
      • Global Banking & Finance Review Magazine Issue 75
      • Global Banking & Finance Review Magazine Issue 73
      • Global Banking & Finance Review Magazine Issue 71
      • Global Banking & Finance Review Magazine Issue 70
      • Global Banking & Finance Review Magazine Issue 69
      • Global Banking & Finance Review Magazine Issue 66
    Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

    Global Banking & Finance Review® is a leading financial portal and online magazine offering News, Analysis, Opinion, Reviews, Interviews & Videos from the world of Banking, Finance, Business, Trading, Technology, Investing, Brokerage, Foreign Exchange, Tax & Legal, Islamic Finance, Asset & Wealth Management.
    Copyright © 2010-2025 GBAF Publications Ltd - All Rights Reserved.

    ;
    Editorial & Advertiser disclosure

    Global Banking and Finance Review is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website.

    Home > Banking > Ensuring ATMs aren’t the weakest link to banking cybersecurity
    Banking

    Ensuring ATMs aren’t the weakest link to banking cybersecurity

    Ensuring ATMs aren’t the weakest link to banking cybersecurity

    Published by linker 5

    Posted on September 21, 2020

    Featured image for article about Banking

    By Elida Policastro, Regional VP – Cybersecurity division at Auriga

    Digital banking brings huge benefits to customers, but the risks of cyber-attacks continue to rise. For banks, there is a need to stay ahead of the game, anticipating new methods of attack so that innovative solutions can be put in place in time to minimise those changing threats.

    In terms of attack targets, the ATM ecosystem is complex and made up of heterogeneous hardware and software that is expensive and difficult to update especially when ATMs and customer touchpoints need to be available 24/7. Because of this, financial organisations usually do not have the latest security policies in place, nor a centralised view of the ATM attack surface. It is vital that banks and ATM operators strike the balance between software deployment and hardware maintenance with keeping control of changes in software and hardware and ensuring the ATM network is as secure as possible.

    This is critical because ATMs and central servers, which are the systems that control ATMs, have become a popular target for cyber-attacks. Last year, over a half (58%) of the global banking industry respondents to the ATMIA Global Fraud and Security Survey 2019 reported that ATM attacks, which includes both physical security breaches and fraud incidents, had increased.

    ATM fraud attacks fall into three categories:

    • Data fraud, resulting from data breach, such as account numbers, pin codes, and other personal data
    • Physical fraud, consisting of theft of valuable assets, such as cash by stealing cards
    • Cyber fraud – logical attacks to the systems and communications

    Jackpotting is a an increasingly popular form of cyber-attack that exploits physical and software-based vulnerabilities in ATMs to get cash and thus an immediate financial reward for the attacker. It is estimated that in the last five years, financial organisations have lost millions to jackpotting. For example, the Ploutus family of ATM malware, which originally appeared in Mexico in 2013, has created losses of over $450 million dollars (€398 million) around the world.

    ATMs suffer physical and logical attacks for several reasons: one is that the physical cash inside acts as an incentive, and another is that cash machines contain confidential information like debit card numbers and PIN codes, which can be stolen and sold.

    Critically, ATMs are a weak link in a bank’s security systems. They appeal to attackers because they are often poorly monitored and little logical action is taken to protect the data in them. In addition, cyber-criminals have also realised that ATM networks utilise security infrastructure that is based on a great deal of legacy hardware and software. This is more vulnerable to attacks because of the high cost of upgrades and difficulty to install security updates with machines that are geographically dispersed and use older operating systems and protocols. Unfortunately, this results in insecure systems that can be easily exploited.

    On top of all of that, there is a real risk of an insider threat. There are a lot of different people and roles responsible for the upkeep of an ATM and these all have administration rights, including employees from the financial institutions, service providers, developers and installers.

    One of the main ways cyber adversaries attack ATMs is via the ‘XFS layer’, a standard interface designed to have multivendor software running on manufacturers’ ATMs and other hardware. While the XFS layer uses standard APIs to communicate with self-service applications, there is no standard way of secure authentication that comes with it, making it easy for cyber-criminals to exploit this vulnerability. Cyber-attackers can therefore deploy malware into banking touchpoints such as cash machines to trick them into giving ‘cash out’ commands and dispense money. The card reader may also be compromised – able to steal card numbers and track the pin pad to learn pin numbers, making the XFS layer a very attractive target. The importance of cybersecurity in banking is therefore only going to increase.

    So, how should banks and ATM operators best prevent attacks? For ATMs, typical endpoint protection security such as anti-malware technology is just not enough. ATM networks and systems are critical infrastructure devices that need to be constantly available and so they require greater protection and a different approach.

    The best approach is a centralised security solution that protects, monitors, and controls ATM networks and thus manages the entire banking asset network in one place and take appropriate action, such as stopping malware spreading throughout the network from infected ATMs.

    Such modern technology solutions not only provide invaluable cybersecurity protection, they can also save banking organisations time and money, as ATM and infrastructure management is centralised into a single hub. Actions can be executed remotely to quickly establish new defences via techniques such as network segmentation or implementing new firewalls.

    It is particularly important for banks to have several layers of protection in one single platform. Such layers could involve full disk encryption, application whitelisting, hardware protection and file integrity protection.

    Although financial organisations are making a concerted effort to improve their security landscape, cyber-criminals are continuing to innovate their attacks, making it an environment of threats that is evolving and advancing. From this, banks must constantly be proactive in implementing and testing their cyber-defences. It is therefore wise to draw upon external counsel with specialist security knowledge to double check on security plans and processes and help ensure ATM security is up to date and preventative.

    Cyber Threat Intelligence (CTI) can provide banks with an early warning system to detect and contain potential threats before they become incidents. This intelligence is essential for any business as cybersecurity threats become increasingly indiscriminate. Once they become aware of any relevant threats and vulnerabilities, then they will begin to understand where and how these can be exploited, as well as the impact this may have on both the business and individuals.

    Awareness of the threat landscape is vital for banks to understand what could be exploited and utilised for future cyber-attacks. If they do not, they open themselves up to the very real possibility of experiencing security breaches, loss of sensitive customer data, and of course stolen cash.

    Related Posts
    DeFi and banking are converging. Here’s what banks can do.
    DeFi and banking are converging. Here’s what banks can do.
    Are Neo Banks Offering Better Metal Debit Cards Than Traditional Banks?
    Are Neo Banks Offering Better Metal Debit Cards Than Traditional Banks?
    Banking at the Intersection: From Nashville to Cannes, A Strategic Call to Action
    Banking at the Intersection: From Nashville to Cannes, A Strategic Call to Action
    Driving Efficiency and Profit Through Customer-Centric Banking
    Driving Efficiency and Profit Through Customer-Centric Banking
    How Ecosystem Partnerships Are Redefining Deposit Products
    How Ecosystem Partnerships Are Redefining Deposit Products
    CIBC Private Banking wins four 2025 Global Banking & Finance Awards
    CIBC Private Banking wins four 2025 Global Banking & Finance Awards
    How Banks Can Put AI to Work Now and Prove ROI in 90 Days
    How Banks Can Put AI to Work Now and Prove ROI in 90 Days
    Top 5 AI quality assurance framework providers for Banks and Financial Services firms.
    Top 5 AI quality assurance framework providers for Banks and Financial Services firms.
    The Unbanked Paradox: How Banking Access Creates Economic Resilience
    The Unbanked Paradox: How Banking Access Creates Economic Resilience
    Hyper-Personalised Banking - Shaping the Future of Finance
    Hyper-Personalised Banking - Shaping the Future of Finance
    The End of Voice Trust: How AI Deepfakes Are Forcing Banks to Rethink Authentication
    The End of Voice Trust: How AI Deepfakes Are Forcing Banks to Rethink Authentication
    Predicting and Preventing Customer Churn in Retail Banking
    Predicting and Preventing Customer Churn in Retail Banking

    Why waste money on news and opinions when you can access them for free?

    Take advantage of our newsletter subscription and stay informed on the go!

    Subscribe

    Previous Banking PostCloud in Banking: An Opportunity That Can’t be Ignored
    Next Banking PostBank fraud prevention in a post-COVID-19 world

    More from Banking

    Explore more articles in the Banking category

    Growth and Impact: Banreservas Leads Dominican Republic Economic Expansion

    Growth and Impact: Banreservas Leads Dominican Republic Economic Expansion

    Turning Insight into Impact: Making AI and Analytics Work in Retail Banking

    Turning Insight into Impact: Making AI and Analytics Work in Retail Banking

    KeyBank Embraces Next-Generation AI Platform to Transform Fraud and Financial Crime Prevention

    KeyBank Embraces Next-Generation AI Platform to Transform Fraud and Financial Crime Prevention

    Understanding Association Banking: Financial Solutions for Community Success

    Understanding Association Banking: Financial Solutions for Community Success

    Applying Symbiosis for advantage in APAC banking

    Applying Symbiosis for advantage in APAC banking

    AmBank Islamic Berhad Earns Triple Recognition for Excellence in Islamic Banking

    AmBank Islamic Berhad Earns Triple Recognition for Excellence in Islamic Banking

    FinTok Strategy: How Banks Are Reaching Gen Z Through Social Media

    FinTok Strategy: How Banks Are Reaching Gen Z Through Social Media

    Rethinking Retail Banking Sustainability: Why the ATM is an Asset in the Sustainable Transition

    Rethinking Retail Banking Sustainability: Why the ATM is an Asset in the Sustainable Transition

    How private banks can survive the neo-broker revolution

    How private banks can survive the neo-broker revolution

    Next-Gen Bank Branches: The Evolution from Transaction Hubs to Experience Centers

    Next-Gen Bank Branches: The Evolution from Transaction Hubs to Experience Centers

    The Banking Talent Crunch: How Financial Institutions Are Competing for Digital-Native Skills

    The Banking Talent Crunch: How Financial Institutions Are Competing for Digital-Native Skills

    Beyond Interest: How Banks Are Reimagining Revenue in the Digital Age

    Beyond Interest: How Banks Are Reimagining Revenue in the Digital Age

    View All Banking Posts