Serquo and Vigilis Defense are announcing a partnership built around a simple but important insight: knowing that ATM software behaves correctly and knowing that it cannot be turned against the bank are two different problems — and they require two different disciplines.

July 16, 2026
Two specialised firms are combining automated simulation and offensive techniques to give financial institutions what they have never had before: proof that their ATM software not only works — but cannot be broken.
The ATM threat landscape has changed faster in the past two years than in the previous decade. Jackpotting attacks surged in 2025. Malware is now polymorphic, AI-driven, and available as a service. And the window between a vulnerability's disclosure and its active exploitation has compressed from weeks to hours.
Against that backdrop, Serquo and Vigilis Defense are announcing a partnership built around a simple but important insight: knowing that ATM software behaves correctly and knowing that it cannot be turned against the bank are two different problems — and they require two different disciplines.
What each company brings to the table
Serquo has spent over 30 years building tools that let financial institutions test ATM software at scale, automatically, and before deployment. Its simulation platform exercises the full stack — XFS layer, authorization interfaces, card transaction flows — across every model in a fleet, catching the misconfigurations that quietly enable fraud before a terminal ever goes live.
Vigilis Defense, founded in Sofia in 2025, does the harder half. Once the simulator has confirmed that the software behaves as specified, Vigilis Defense's team attacks the same build the way a real adversary would: jackpotting attempts, XFS-interface abuse, command injection, relay and man-in-the-middle attacks on the authorization path, physical-logical access review. Their job is to find what the specification missed.
Together, the two firms cover the full pre-production security cycle — from automated regression and integrity validation to hands-on offensive testing — without a handoff gap in between.
Why this matters now
The numbers make the case plainly. According to ATMIA's CCMIS Q1 2026 report, 99% of global ATM crime in the first quarter of 2026 was fraud. AI-enabled fraud grew by over 1,200% in 2025 compared to traditional methods. And the average cost of a breach in the financial sector now stands at $5,56 million per incident (IBM 2025).
In that environment, deploying ATM software that has only been validated against its own specification — but never stress-tested by someone actively trying to break it — is a risk that most institutions can no longer justify.
The joint white paper
To mark the launch of the partnership, Serquo and Vigilis Defense are publishing a joint white paper: ATMs in the Age of Artificial Intelligence: When Malware Gets Smarter and Testing Becomes Essential. It covers the current threat landscape in detail, maps the evolution of ATM malware across three generations, and sets out a concrete framework of eight security controls that operators should have in place before any software deployment.
"Automated verification tools are the surest way to guarantee the integrity of installed applications and that they are configured correctly,
said Zdravko Zdravkov, CTO & Lead Researcher at Vigilis Defense.
The white paper will be available soon.
Serquo · info@serquo.com
Vigilis Defense · info@vigilisdefense.com
Experience the power of 30 year in ATM's technology innovation
Serquo offers advanced simulation and testing tools for ATM applications, designed to maximize testing efficiency. Our solutions enhance quality, reduce development times, and lower costs in deployment phase.