CONTINUE TO SITE »
or wait 15 seconds

Bank Customer Experience Podcast

What's changed in man-in-the-middle attacks?

Man in the middle attacks are getting more sophisticated, enabling criminal groups to control much of the attack remotely. Cook Solutions Group discusses how these attacks have changed and how FIs and operators can combat these attacks.

presented by

August 14, 2026

The era of the lone criminal targeting an ATM has ended. Now, organized criminals work together to figure out vulnerabilities and target ATMs. One of their primary techniques in 2026 is man-in-the-middle attacks, which intercept communications between the host and processor to send out fraudulent transactions.

In today's episode of the Bank Customer Experience podcast, host Bradley Cooper spoke with Michael Strange, director of technology services, Cook Solutions Group, and Alyssa Luecke, fintech solutions consultant, Cook Solutions Group, about what MITM attacks are and how they have changed in 2026.

During the podcast, Strange identified that criminals are able to perform these attacks with much better efficiency and without as much risk of being on site. For example, they can install a black box device, usually a Raspberry Pi, directly into the machine and then communicate with it remotely.

Strange said that in the Pacific Northwest these attacks have become the main vector of actors. "I'd say the last 3 months, that's all we've seen. It's been almost exclusively man in the middle."

He added that criminal groups have started using Wi-Fi routers so they can control the attack remotely, as well as using server spoofing.

"They don't need the local Bluetooth connection anymore, they can have that guy off site." They can even use black boxes in bypass mode, which allows customers to do legitimate transactions in between installation of the black box and when the criminal groups device to use it.

The process of the overall attack remains the same. A group scouts out the location first, noting any cameras and the overall security of the device. They will then attempt to remove the top box to see if an alarm is triggered or any law enforcement is called. If no alarm sounds, they will replace the top box, then come back at another date to install the black box device. They can then send out cash collectors who can insert a payment card and put in a legitimate transaction. The black box will then take that legitimate transaction and approve a maximum withdrawal.

Strange said in many cases, banks only find out about this incident when they run out of cash at the ATM. Even then, Luecke said that the bank may attribute this to a busy week of cash withdrawals.

Luecke and Strange also discussed methods for how to prevent attacks, such as installing an alarm on the top hat, from which criminals can access the network cables. They can also use barriers that can block access to the top hat.

To learn more about this attack vector and ways to prevent it, listen to the podcast in full above.

More From Bank Customer Experience PodcastMore

Included In This Story

Cook Solutions Group

Simple | Secure | Service | Solutions. From ATM sales, support, and service to enterprise security solutions with Next Generation technology. ‍Think CSG First. We Make it Happen!

Request Info
Learn More




©2026 Connect Media, All rights reserved.
b'S1-NEW'