3Corns

ATM Crypto Software Flaws Uncovered

Vulnerabilities in Microsoft's BitLocker encryption layer could leave organizations — and potentially ATMs — exposed to attack

A security researcher has uncovered nine flaws in a program used to protect both ATMs and corporate systems — but he and Diebold Nixdorf, one of the world's biggest ATM makers, don't see eye to eye on what those flaws actually mean.

At Black Hat USA 2026, Matt Burch, a principal security researcher at Atredis Partners, plans to unveil nine previously unknown vulnerabilities in CryptWare's CryptoPro Secure Disk. The product — CryptoPro for short — handles full-disk encryption and pre-boot login for Windows machines, and oddly enough, it's sold both to general corporate clients and to ATM makers.
Black Hat USA:

Nobody's disputing the vulnerabilities themselves. What's up for debate is how much they actually matter. Burch calls CryptoPro a "foundational" piece of the security stack Diebold relies on. Diebold, for its part, told Dark Reading that's not the case.

Put simply: either Burch has found a path to draining hundreds of thousands of dollars out of ATMs, or he's flagged bugs in a fairly ordinary piece of enterprise software.

The Fragile Shield Protecting ATMs From Attack

ATMs are built like tanks at the bottom and like tin cans up top. That's because the bottom houses the cash, while the top houses the computer — and manufacturers, according to Burch, simply don't treat that upper section as much of a security concern. It's often built from cheaper steel, or even plastic, compared to the fortified vault below.

While cracking open the vault is a major undertaking, getting into the top "head unit" is far more realistic for a would-be thief. Burch walks through how the locking system works: a solenoid connects to a cable that pulls levers on both sides of the ATM's casing to release the front panel. Someone could get to that cable either by prying the machine open or working a tool into the mechanism.

Once inside, Burch explains, ATMs run a layered software setup on top of Windows, loaded with banking configurations that let the machine dispense cash. Setting that up is a fairly involved process — but functionally, it all comes down to one dynamic link library, tied to something called XFS, or "extension for financial services." XFS is the bridge between the ATM, the customer, and the bank, and it's the piece that actually authorizes money to come out.

That means thieves don't need to worry about safecracking at all — they just need to pry the machine open and slip in malware that talks directly to XFS. The best-known strain of this malware is Ploutus. Since the earliest wave of these so-called "jackpotting" attacks hit the U.S. in 2017, they've steadily escalated. Of the roughly 2,000 incidents reported to the FBI since 2020, over 700 happened in 2025 alone — adding up to more than $20 million stolen.

Where the New Security Bugs Crash the Party

Every ATM manufacturer builds its own proprietary defenses against jackpotting. Diebold's version comes bundled into its all-in-one Vynamic Security Suite (VSS).

One piece of that suite is hard disk encryption (HDE), which relies on a third-party tool called CryptoPro Secure Disk — the very software where Burch found his vulnerabilities.

Two of those flaws centered on the pre-boot decryption process. If decryption hit a failure state, the system would fall back to mounting the drive in plaintext instead of failing securely. Compounding that, the check for whether a disk was using LUKS encryption was shallow enough that an attacker could spoof it — making an unencrypted disk appear encrypted, and once again tricking the system into mounting it in plaintext.

On top of that, Burch discovered that CryptoPro stored its own encryption keys and configuration data directly on the disk, rather than somewhere better protected. Paired with the plaintext bug, this gave him a clear view into the program's most sensitive secrets. He also found a weakness in CryptoPro's Secure Boot implementation that would let an attacker boot their own custom Linux environment on the ATM, bypassing the vendor's intended setup entirely.

Taken together, these flaws gave the researcher a full path to compromise: he could execute his own code on the ATM before it even finished booting, pull the keys needed to unlock its Windows environment, and then drain cash using a typical jackpotting method.

ATMs: Fact vs. Fiction

Dark Reading reached out to CryptoPro resellers CryptWare and CPSD, along with ATM maker Diebold Nixdorf, seeking their reaction to the findings. Neither encryption vendor responded, but Diebold Nixdorf pushed back on the researcher's conclusions.

Mike Jacobsen, who leads corporate communications for Diebold, told Dark Reading the company doesn't rely on BitLocker at all, and by extension doesn't use CryptoPro Secure Disk for BitLocker either — meaning, in his view, the research doesn't apply to Diebold's systems.

That said, Jacobsen admitted Diebold's Vynamic Security HDE incorporates certain CryptoPro components. He wouldn't go into detail about how that integration works when pressed further. Burch suggested this likely means Diebold leans on a different cryptographic approach within CryptoPro's toolkit rather than the specific product under scrutiny. Notably, CryptoPro Secure Disk does appear in Diebold's VSS license agreements from both 2018 and 2024.

After Burch flagged the vulnerabilities, Diebold brought in CryptoPro's engineering team to evaluate the real-world risk to its machines. Jacobsen said the joint assessment found minimal practical danger overall, though he acknowledged that two of the nine reported flaws (he didn't specify which) could theoretically affect Diebold's HDE under specific circumstances. It looks like Diebold rolled out fixes for those two issues in a software update last December, without much fanfare.

Whether the real number affecting Diebold machines is two or all nine, the bigger picture is that CryptoPro has a substantial footprint beyond just ATMs — it's also common in enterprise Windows environments. The company states on its website that it has sold over half a million licenses spanning 20 industries and five continents.

Conclusion:

Burch's broader point applies to all of these organizations, not just ATM operators: encryption is only as good as how well you protect the keys behind it. Storing the key alongside the encrypted data undermines the entire security model — comparable to locking a box but leaving the key taped to it.

3Corns - Articles, Security, Splitter

🔗 Source(s):

  • Dark Reading: https://www.darkreading.com/vulnerabilities-threats/atm-crypto-software-bugs-jackpot-bust
  • MSN Article: https://www.msn.com/en-us/money/technologyinvesting/crims-hit-a-20m-jackpot-via-malware-stuffed-atms/ar-AA1WGNH4