November 11, 2019
Researchers at New York-based Red Balloon Security Inc. identified two vulnerabilities in retail cash machines manufactured by Nautilus Hyosung America.
Nobody has reported instances of hackers taking advantage of the vulnerabilities, which would have allowed someone with ill intent to steal cash and customer data from the ATMs, and Nautilus Hyosung has already issued a patch, the companies said in a joint press release on Monday.
A subsidiary of South Korea-based Hyosung Corp, Nautilus manufacturers ATMs for the U.S. market and has more than 140,000 installed ATMs throughout the country. According to an estimate by Red Balloon, more than 80,000 of those are vulnerable. The researchers said that the flaws only affected retail versions of Nautilus ATMs, not ones used in financial institutions.
On Sept. 4., less than a week after Red Balloon first reported the vulnerabilities, Hyosung issued firmware security updates to mitigate the possible threats and notified all of its commercial customers to immediately update their ATMs with the patches. Further, Red Balloon said it's working with Nautilus to improve the security of its ATMs.
"We commend Nautilus Hyosung America for its fast and diligent response to these disclosures, and for taking the appropriate steps to fix these problems," Ang Cui, CEO of Red Balloon, said in the release. "If left unaddressed, the vulnerabilities we discovered could have created a potential for exploitation."
The vulnerabilities
According to a report in Bloomberg, one of the ATM vulnerabilities uncovered by Red Balloon targets an ATMs remote management system. It would enable a hacker to collect data from any card entered into an ATM as the transaction takes place.
The other vulnerability was in the software that powers the ATM's peripherals. Red Balloon researchers found a hacker could inject malware and use that to jackpot the ATM, telling the machine to spew cash.
Hyosung Americas is a global human experience maker that bridges the physical and virtual worlds. We do this by harnessing our unique combination of a manufacturer’s soul with an innovator’s mindset to build a platform of integrated products, services, and ideas that improve life’s day-to-day interactions for everyone.