A Critical Vulnerability in ATM Security Software Raises Concerns Over Jackpotting Attacks
Researchers have discovered a set of nine vulnerabilities in CryptWare CryptoPro Secure Disk, a full-disk encryption and pre-boot authentication solution used by both corporations and ATM manufacturers. The security flaws, revealed by principal researcher Matt Burch at the Black Hat USA 2026 conference, could potentially allow attackers to steal cash from ATMs or compromise corporate data.
The affected software is marketed as a robust security tool for protecting sensitive information on Windows-based systems. However, Burch’s findings suggest that it may not be as secure as claimed. The researcher has identified weaknesses in the way CryptoPro decrypts hard drives during pre-boot, which could allow hackers to access plaintext data even if the disk appears encrypted.
Moreover, Burch found that CryptoPro stores its own key material and configuration values on the disk itself, rather than in a more secure location. This makes it easier for attackers to gain access to the program’s most sensitive secrets. Additionally, he discovered vulnerabilities in the Secure Boot setup, which could enable an attacker to run their own code on the system.
The implications of these findings are significant, especially given the prevalence of jackpotting attacks on ATMs. Since 2017, over $20 million has been stolen from ATMs in the US alone, with more than 700 reported cases in 2025. The use of proprietary security software by ATM manufacturers, such as Diebold’s Vynamic Security Suite (VSS), is intended to prevent these types of attacks.
However, Burch’s research suggests that even these advanced security tools may not be sufficient to protect against sophisticated hackers. If an attacker can gain access to the vulnerable components of CryptoPro, they could potentially exploit them to steal cash from ATMs or compromise corporate data.
The discovery of these vulnerabilities highlights the need for ATM manufacturers and corporations to reassess their security protocols and ensure that they are using robust encryption methods to protect sensitive information. It also underscores the importance of regular software updates and patches to prevent exploitation by hackers.
For individuals, this finding serves as a reminder to be cautious when using ATMs or handling sensitive financial data. While the likelihood of being directly affected by these vulnerabilities is low, it’s essential to remain vigilant and report any suspicious activity to authorities. By staying informed about emerging security threats and taking proactive steps to protect ourselves, we can mitigate the risks associated with jackpotting attacks and other types of cybercrime.
Source: Dark Reading — 2026-07-10