Yesterday, during a flashy presentation at the Black Hat security conference in Las Vegas, a computer security expert showed several ways to break into ATMs.
Barnaby Jack, who is director of research at IOActive Labs, made cash pour from a machine for minutes on end. After studying four different companies’ models, he said, “every ATM I’ve looked at, I’ve found a ‘game over’ vulnerability that allowed me to get cash from the machine.” He’s even identified an Internet-based attack that requires no physical access.
The same talk was supposed to take place at last year’s Black Hat conference, but it was pulled at the last moment. In his presentation, which did not reveal the exact details of how he performed the attacks, Jack named two vendors–Triton and Tranax–and said he had been in contact with both about fixing the problems.
Jack demonstrated the attacks on two ATMs that he bought online and drove to Las Vegas from his company’s headquarters in San Jose. The hardware kit that he used in the demonstration cost less than $100 to make.
In one part of his presentation, he demonstrated a way for a thief to gain physical access to the ATM made by Triton. The device’s main circuit, or motherboard, is protected only by a door with a lock that is relatively easy to open (Jack was able to buy a key online). He then used a USB port on the motherboard to upload his own software, which changed the device’s display, played a tune, and made the machine spit out money.