- Growth & Innovation
ATM security without compromise
Jordan Riek
Share
Today’s ATMs operate more like mini-branches than ever before. This means that financial institutions must ensure their devices are protected against criminals targeting them for purposes of theft, intrusion and compromise.
Establishing effective defense mechanisms, however, is just the first step. Hardened ATM security requires an institution to be aware and vigilant of new criminal schemes every day to protect its cardholders, as well as its brand.
Protecting ATMs from fraud attacks requires a blend of physical and cybersecurity measures. ATM feature functionality and operating designs continue to expand—and so does the battlefield where ATM security managers and ATM-focused criminals meet. Each new ATM feature or system brings a potential new way for criminals to learn and reverse-engineer how those mechanisms work.
A physical attack on an ATM often includes attacking the device’s surrounding environment in addition to the ATM itself. Some of the ways criminals compromise the physical security of an ATM include card skimmers, crowbar smash-and-grabs and other brute-force attempts to open the machine on-site or remove it to another location to open it. Cyberattacks on ATMs are those that target computer systems, applications, network, and data. These include malware introduction, endoscopic attack (used in “jackpotting” schemes), BIOS manipulation, ransomware installation and wiretapping.
These types of attacks are often the work of sophisticated criminal enterprises that use reconnaissance to gather information about the network, device software and monitor capabilities of the ATM management system prior to launching the attack based on their findings.
Maintaining ATM security vigilance requires regular intelligence gathering and sharing, as well as a clear but flexible strategy for protecting both the fleet and sensitive cardholder data. First and foremost, ATM managers should think about where data resides or is transmitted and ensure its security. In addition, ATM use behaviors are generally similar, making it relatively easy to detect potential fraud using analysis tools.
Based on our deep knowledge of ATM security and our experiences with customers around the world, we recommend all financial institutions consider incorporating some or all of these best practices into their ATM security protocols:
ATM fraud is preventable with vigilance and consistent best practices. It’s not unlike the way new parents are instructed to baby-proof their house: get down on their hands and knees and look at the world from an infant’s point of view. Assessing ATM fraud and security risks should be done in a similar manner.
Jordan Riek is senior vice president, information security, at Cardtronics.
Become a member to unlock exclusive content, connect with industry experts, and gain access to valuable resources. If your employer is an institutional member, activate your ProSight membership benefits with a simple email address.