Nine Security Flaws Found in ATM Encryption Software, and Nobody Agrees How Bad It Is

A researcher found serious bugs in software that locks ATM hard drives. The world's biggest ATM maker says they don't matter. The researcher disagrees. The truth is somewhere uncomfortable.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 4 min read
Illustration: a modern bank ATM machine
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Security researcher Matt Burch publicly disclosed nine vulnerabilities in CryptoPro Secure Disk, full-disk encryption software used on ATMs and corporate Windows computers, ahead of a presentation at Black Hat USA 2026.
  • Diebold Nixdorf, the world's largest ATM manufacturer, confirmed in 2025 that two of the nine flaws are "theoretically applicable" to its own ATM security software and quietly issued a fix in December 2025.
  • More than 700 ATM jackpotting attacks (where criminals force a machine to spit out cash) were reported to the FBI in 2025 alone, stealing more than $20 million.
  • CryptoPro's vendor claims more than 500,000 software licences sold across 20 industries, meaning the flaws could matter well beyond ATMs.
  • Diebold declined to fully explain how it uses CryptoPro, leaving the real-world impact of the remaining seven vulnerabilities unresolved.

ATMs are basically two machines bolted together. The heavy steel bottom is the vault; the lighter top section is a regular Windows PC that talks to your bank and tells the machine how much cash to push out. That top half, security researcher Matt Burch points out, is often made of cheaper steel or even plastic, and its lock is operated by a simple cable you can reach through a gap with the right tool.

Once someone physically opens that top section, they can wire in malware targeting the part of the ATM's software responsible for dispensing cash. That technique, nicknamed "jackpotting," has been a growing problem in the United States since 2017. Burch's new research adds a software angle to that physical threat.

Could criminals actually use these bugs to steal cash?

Possibly, though the full answer depends on which software an ATM is actually running. Burch found nine vulnerabilities in CryptoPro Secure Disk, designed to encrypt (scramble and lock) the hard drive of a Windows computer so nobody can read the contents without the right password. Under certain failure conditions the software defaults to mounting drive volumes in plaintext, effectively leaving the door unlocked. He also found that the secret keys used to scramble the drive were stored on the same disk they were supposed to protect, which is roughly equivalent to taping a house key to the front door.

Combined, those weaknesses let Burch get his own code running on a test ATM during pre-boot, recover the decryption keys, and execute a standard jackpotting attack. Our earlier piece on GreatXML's BitLocker bypass covered similar terrain: Windows full-disk encryption failing not because the algorithm broke but because the plumbing around it was trusted too much.

Diebold Nixdorf, whose Vynamic Security Suite is the security software used on the company's ATMs, told Dark Reading it disagrees with the severity of Burch's findings. Mike Jacobsen, Diebold's senior director of corporate communications, told Dark Reading the vulnerabilities "pose little to no additional risk" in a real-world environment. The same spokesperson acknowledged two of the nine flaws are "theoretically applicable" to Diebold's own hard-drive encryption component. Diebold appears to have patched those two issues in a December 2025 update without a public announcement, and declined to explain exactly how it uses CryptoPro inside its products.

That silence is the part worth watching.

Should you worry if you're not a bank?

Yes, if your organisation runs Windows machines with CryptoPro Secure Disk installed. The vendor claims more than 500,000 licences across five continents and 20 industries, so ATMs are just one slice of the exposure. The failure mode here is a familiar one: encryption software that stores its own key material on the same disk it's supposed to protect isn't really protecting anything.

Burch frames it plainly. "If you give someone a lockbox and then the key is right next to the box, it defeats the purpose of having the box locked to begin with," he told Dark Reading.

For ordinary bank customers, there's no action needed today. Jackpotting targets the machine, not customer accounts or card data. Report unfamiliar activity near an ATM's top panel to bank staff.

Operational takeaway: Verify that encryption keys on any Windows fleet are stored separately from the data they protect, ideally in a hardware security module, not on the same drive.

The broader judgement here is that Diebold's "little to no additional risk" line is doing a lot of work for a company that won't say how deeply CryptoPro is embedded in its stack. Seven of nine vulnerabilities remain publicly unaddressed for Diebold customers. Watch whether CryptWare or CPSD, which didn't respond to Dark Reading, say anything before Black Hat USA 2026.

© 2026 Threat Vectr