Executive Summary
In July 2026, security researcher Matt Burch identified nine vulnerabilities in CryptWare's CryptoPro Secure Disk, a full-disk encryption and pre-boot authentication solution for Windows. These flaws could potentially allow attackers with physical access to ATMs to execute arbitrary code, bypass encryption, and steal cash. The vulnerabilities include integrity validation bypasses and improper storage of key materials, raising significant security concerns for organizations utilizing this software.
This discovery underscores the critical need for robust physical and software security measures in ATMs, especially as 'jackpotting' attacks have been on the rise, with over 700 incidents reported in 2025, resulting in more than $20 million stolen. (techcrunch.com)
Why This Matters Now
The identification of these vulnerabilities highlights the urgent need for financial institutions to reassess and strengthen their ATM security protocols to prevent potential exploitation and financial losses.
Attack Path Analysis
Attackers exploited vulnerabilities in the ATM's encryption software to gain unauthorized access, escalated privileges to control the ATM's operating system, moved laterally to manipulate financial services, established command and control to deploy malware, exfiltrated sensitive data, and ultimately caused financial loss through unauthorized cash dispensing.
Kill Chain Progression
Initial Compromise
Description
Attackers exploited vulnerabilities in the ATM's encryption software to gain unauthorized access.
Related CVEs
CVE-2020-9062
CVSS 5.3Diebold Nixdorf ProCash 2100xe USB ATMs running Wincor Probase version 1.1.30 do not encrypt, authenticate, or verify the integrity of messages between the cash and check deposit module (CCDM) and the host computer, allowing attackers with physical access to intercept and modify messages.
Affected Products:
Diebold Nixdorf ProCash 2100xe USB ATM – Wincor Probase 1.1.30
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Valid Accounts
Abuse Elevation Control Mechanism
Modify Authentication Process
Impair Defenses
Data from Local System
Application Layer Protocol
Inhibit System Recovery
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Secure storage of cryptographic keys
Control ID: 3.5.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Data Security
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Banking/Mortgage
ATM crypto vulnerabilities expose cash dispensing systems to jackpotting attacks, requiring enhanced full-disk encryption and pre-boot authentication security controls.
Financial Services
CryptoPro encryption flaws threaten financial infrastructure using Windows environments, compromising data protection and regulatory compliance across banking operations.
Computer Software/Engineering
BitLocker wrapper vulnerabilities in widely-deployed encryption software affect 500,000+ licenses across enterprises requiring immediate security patches and assessments.
Information Technology/IT
Full-disk encryption bypass vulnerabilities expose Windows fleet security, enabling plaintext mounting and cryptographic key recovery across corporate environments.
Sources
- Fresh ATM Crypto Software Bugs: Jackpot or Bust?https://www.darkreading.com/vulnerabilities-threats/atm-crypto-software-bugs-jackpot-bustVerified
- Diebold Nixdorf ProCash 2100xe USB ATM does not adequately secure communications between CCDM and hosthttps://www.kb.cert.org/vuls/id/221785Verified
- ATM makers fix flaws allowing illegal cash withdrawalshttps://www.helpnetsecurity.com/2020/08/21/atm-illegal-cash-withdrawals/Verified
- The Five Most Common ATM Security Gapshttps://www.dieboldnixdorf.com/banking/insights/blog/five-most-common-atm-security-gaps/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is relevant to this incident as it could have limited the attacker's ability to escalate privileges, move laterally, and exfiltrate data, thereby reducing the overall impact of the attack.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's initial unauthorized access may have been constrained, reducing the likelihood of successful exploitation.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges could have been limited, reducing the scope of control over the ATM's operating system.
Control: East-West Traffic Security
Mitigation: The attacker's lateral movement within the ATM's system could have been restricted, limiting access to financial services.
Control: Multicloud Visibility & Control
Mitigation: The attacker's command and control channels may have been detected and disrupted, limiting malware deployment.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's data exfiltration attempts could have been constrained, reducing the amount of sensitive data accessed.
The attacker's ability to dispense cash without authorization could have been limited, reducing financial loss.
Impact at a Glance
Affected Business Functions
- ATM Operations
- Customer Transactions
- Cash Management
Estimated downtime: 3 days
Estimated loss: $50,000
Potential exposure of transaction data and unauthorized cash withdrawals.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict unauthorized access within ATM systems.
- • Deploy Inline IPS (Suricata) to detect and prevent exploitation of known vulnerabilities.
- • Utilize Threat Detection & Anomaly Response to identify and respond to suspicious activities.
- • Enforce Egress Security & Policy Enforcement to control outbound traffic and prevent data exfiltration.
- • Enhance Multicloud Visibility & Control to monitor and manage security across all platforms.



