ATM Jackpotting in 2026: Why the Cellular Router Is Urgent More than Ever
On February 19, 2026, the FBI warned that ATM jackpotting is rising across the United States. The bureau counted 1,900 jackpotting incidents since 2020, more than 700 of them in 2025 alone, with over $20 million stolen that year. Criminals opened machines with generic keys, loaded Ploutus malware, and forced them to dispense cash on command.
Most of those machines don’t sit in bank branches. A standalone ATM at the back of a gas station has two short antennas on top of the cabinet: one carries transactions to the processor, the other sends alarms to a monitoring center. Behind those antennas sits a cellular router, and nobody on site watches it overnight. The transaction data passing through it is encrypted. The router itself is a different story. This post looks at why the router is the part attackers want, how the same pattern played out in the Polish power plant attack, and how operators can secure it.
Where ATM Jackpotting Stands in 2026
According to the FBI’s FLASH alert, the current wave runs on Ploutus, malware that targets the XFS layer controlling ATM hardware and lets attackers bypass bank authorization entirely. Installation is physical: open the ATM face with a widely available key, then infect or replace the hard drive and reboot. The Hacker News reported that cash-outs can happen in minutes and often go unnoticed until the money is gone.
The FBI’s mitigations focus on the machine itself:
- Replace standard locks that generic keys can open
- Audit removable storage and process creation
- Validate the disk against a known-good gold image
- Whitelist devices and encrypt disks
All four are necessary, but none of them covers the network the machine sits on. Jackpotting empties one ATM. An attacker who controls the router can reach every machine connected to it, and everything those machines connect to.
Encryption Protects the Data, Not the Router
Payment standards require cardholder data to be encrypted when it travels over public networks, and ATM traffic to the processor is protected that way. That encryption keeps a card number from being read in transit. It does nothing to stop someone from taking over the router the traffic passes through.
A cellular router is a small computer with its own firmware, its own admin login, and its own management interface. Whoever controls it decides what the machines behind it can reach and what can reach them. That makes it an ideal base: a device that is always on, rarely inspected, and already trusted by the network.
Attackers know this. In the 2025 Verizon Data Breach Investigations Report, exploitation of edge devices and VPNs made up 22% of all vulnerability exploitation, up from 3% the year before, and ransomware appeared in 44% of breaches. A hijacked router is how a single cabinet turns into a foothold for something much larger, including ransomware across the network behind it.
The Polish Power Plant Attack Followed the Same Path
The clearest example comes from energy, not banking. In August 2026, CERT Polska disclosed how attackers breached a Polish combined heat and power plant through a private cellular network in December 2025. The sequence:
- The entry point was a remote access device. Attackers got into a wind farm through a FortiGate VPN with no multi-factor authentication and took administrative credentials.
- A cellular router became the attack base. They used SSH tunneling through a Teltonika cellular router to get onto the private APN.
- The private APN allowed lateral movement. The APN permitted client-to-client traffic, so the attackers could scan for other devices on it and found a WAGO controller still using default credentials.
- The final target was operations. From there they reached the plant’s OT network, switched controllers to STOP mode, and shut down a steam turbine.
Replace the wind farm with a gas station and the plant with a bank’s ATM network, and the path is the same: one weak entry point, one compromised router, a shared APN, and a device with default credentials on the other side. OneLayer covered the wider Poland grid attack in August, and the lesson carries over directly to any operator running machines on cellular.
When the Management Platform Is the Target
Routers are rarely managed one at a time. Operators run them through cloud management platforms that push configuration and firmware to every device at once. That makes the platform itself a high-value target.
In December 2025, a critical flaw in React Server Components, CVE-2025-55182, known as React2Shell, allowed unauthenticated remote code execution and carried the maximum CVSS score of 10.0. CISA added it to its Known Exploited Vulnerabilities catalog on December 5, and more than 30 organizations were breached within days. Digi International, a major cellular router vendor, confirmed that Digi Remote Manager was affected, patched it, and reported no evidence of compromise.
Digi moved quickly, and the issue is fixed. The point is what the platform represents. A flaw in the system that manages the routers can become a path to every router it manages, so that layer needs the same scrutiny as the devices themselves.
Three Ways the Cellular Connection Is Used Against the Machine
Each of these works differently and has to be caught differently.
1. Attackers take over the router or the platform that manages it.
This is the path described above. A hijacked router or management platform gives an attacker a trusted position on the network, with access to every machine behind it and every device on the same APN.
2. Attackers plant their own cellular device inside the machine.
Symantec documented this in 2014: criminals hid a mobile phone inside an ATM, connected it over USB, and sent two text messages to activate Ploutus and start dispensing cash, with no one standing at the machine. The 2026 FBI alert describes physical installation, not text-message triggers, and there’s no public evidence that current crews use this method. Still, security firm SISA lists unexpected cellular connectivity or SMS traffic spikes as a sign of Ploutus infection.
3. Attackers jam the signal so the machine can’t call for help.
A cellular jammer blocks the connection, so neither transactions nor alarms get through. The Electronic Security Association cites Department of Homeland Security figures showing Customs and Border Protection jammer seizures up roughly 830% since 2021. Operating or selling a jammer is illegal in the United States, but criminals use them anyway. To the processor, a jammed ATM looks exactly like one that lost power.
None of these show up on the machine itself. All three show up on the network, if someone is looking.
Why a Machine Going Offline Deserves Attention
A jammed machine and a broken machine look the same unless someone knows how that specific machine normally behaves. Every unattended device on cellular has a routine: when it checks in, how much data it sends, which servers it contacts, which cell tower it usually connects through.
Any change to that routine is worth a look. An ATM that drops offline at 2 a.m. should be treated as a possible incident, not left for the next maintenance visit. The same applies to a router that suddenly opens an SSH session, or starts talking to other devices on the APN.
Knowing Every Router, SIM, and Modem
Operators need to know every cellular identity across their machines and what each one is supposed to be doing:
- Every router, SIM, and modem should be tied to the machine it serves. That way, a second modem in a cabinet or a SIM moved into a different device is spotted right away.
- Every device should be checked against what it claims to be. Attackers spoof SIM and modem identities to make a rogue device look legitimate.
- Every machine should have a short list of allowed destinations. An ATM talks to its processor and its monitoring center. Everything else is blocked, including traffic between machines on the same private APN.
The third point is what would have stopped the Polish attack at the router. As we covered in why APNs alone are not enough for segmentation, a private APN keeps outsiders off the public internet, but it does not stop devices on the same APN from reaching each other.
Where to Start, Based on How Many Machines You Run
A few dozen machines at owned locations. That’s few enough to track by name. Start with a list, one line per machine: router, SIM, modem, carrier, and the two or three destinations it should ever reach. Then make sure offline alerts go to a person, not a queue.
Hundreds to thousands of machines across carriers. No one holds the full list. It’s split across carrier portals, the router management platform, the processor, and the field service team. Pull those into one inventory of cellular identities, and treat any identity that shows up in one source but not the others as something to investigate.
Machines on a private APN. The exposure to the public internet is handled. Next, confirm that machines can’t reach each other, and that traffic inside the APN is monitored, not only traffic at its edge.
Questions to Ask About Every Unattended Machine
- Who can log in to each router, and to the platform that manages them?
- Are router firmware and the management platform patched?
- How many SIMs and modems are out in the field, and does that count match the carrier’s?
- Would you know if a second cellular device appeared inside a cabinet?
- What is each machine allowed to talk to, and is everything else blocked?
- Can machines on the same APN reach each other?
- What does normal behavior look like for each machine and router, and who gets alerted when it changes?
Securing the Cellular Link
An unattended machine is only as secure as the router it depends on. Encrypting the transaction protects the data. Securing the router protects everything else.
Banks and ATM operators with machines spread across gas stations, convenience stores, and malls are running a private cellular network, whether they call it that or not. That network needs to be secured like one: every SIM and modem identified, every machine limited to the destinations it needs, and every change in behavior flagged. OneLayer secures exactly this kind of network. It fingerprints every SIM and modem and automatically detects spoofed identities, unauthorized device-to-device connections, and devices that appear behind a different router than the one they were onboarded to. Explore the OneLayer Bridge platform to see how it works, or read how OneLayer turns real cellular threats into automatic detections.
VP R&D, OneLayer


