Attacks/Breaches

2/5/2018
06:00 PM
50%
50%

Two Suspects Arrested in 'Jackpotting' Attack in Connecticut

The men were charged in federal court for alleged bank fraud using malware that empties cash from ATM machines.

US federal authorities have arrested and charged two men for alleged ATM "jackpotting" activity at a bank in Connecticut. Alex Alberto Fajin-Diaz, 31, a citizen of Spain, and Argenys Rodriguez, 21, of Springfield, Mass., were detained on Jan. 27 in Cromwell, Conn., near a compromised ATM machine that was under attack.

Citizens Bank contacted police after noticing an attack underway on its ATM, which was spitting out $20 bills. Police found Fajin-Diaz and Rodriguez nearby with more than $90,000 in cash in $20 bills. Their vehicle contained tools and electronic devices typically used in ATM jackpotting attacks.

Federal, state, and local law enforcement agencies already had been investigating jackpotting attacks in Connecticut and other states. Diebold Nixdorf and NCR, two of the world's largest ATM vendors, late last year warned their US customers about jackpotting attacks, where cybercriminals infect the machines with malware inserted into the machines that ultimately programs them to rapidly dispense cash.

The two ATM jackpotting suspects, if found guilty, face a possible sentence of 30 years in prison.

Read more on the ATM jackpotting bust here

 

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Google Engineering Lead on Lessons Learned From Chrome's HTTPS Push
Kelly Sheridan, Staff Editor, Dark Reading,  8/8/2018
White Hat to Black Hat: What Motivates the Switch to Cybercrime
Kelly Sheridan, Staff Editor, Dark Reading,  8/8/2018
PGA of America Struck By Ransomware
Dark Reading Staff 8/9/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-3937
PUBLISHED: 2018-08-14
An exploitable command injection vulnerability exists in the measurementBitrateExec functionality of Sony IPELA E Series Network Camera G5 firmware 1.87.00. A specially crafted GET request can cause arbitrary commands to be executed. An attacker can send an HTTP request to trigger this vulnerability...
CVE-2018-3938
PUBLISHED: 2018-08-14
An exploitable stack-based buffer overflow vulnerability exists in the 802dot1xclientcert.cgi functionality of Sony IPELA E Series Camera G5 firmware 1.87.00. A specially crafted POST can cause a stack-based buffer overflow, resulting in remote code execution. An attacker can send a malicious POST r...
CVE-2018-12537
PUBLISHED: 2018-08-14
In Eclipse Vert.x version 3.0 to 3.5.1, the HttpServer response headers and HttpClient request headers do not filter carriage return and line feed characters from the header value. This allow unfiltered values to inject a new header in the client request or server response.
CVE-2018-12539
PUBLISHED: 2018-08-14
In Eclipse OpenJ9 version 0.8, users other than the process owner may be able to use Java Attach API to connect to an Eclipse OpenJ9 or IBM JVM on the same machine and use Attach API operations, which includes the ability to execute untrusted native code. Attach API is enabled by default on Windows,...
CVE-2018-3615
PUBLISHED: 2018-08-14
Systems with microprocessors utilizing speculative execution and Intel software guard extensions (Intel SGX) may allow unauthorized disclosure of information residing in the L1 data cache from an enclave to an attacker with local user access via a side-channel analysis.