Skip to main content
← Back to blog

ATM Jackpotting Is Both a Physical and Cyber Risk

What the FBI’s 2026 warning means for cannabis retailers that host or operate ATMs.

By Alex Castrillo3 min readFact-checked August 28, 2026
ATM Jackpotting Is Both a Physical and Cyber Risk

ATM jackpotting combines physical access, software abuse, and cash theft. Retailers that host an ATM should know who owns it, who services it, and who receives an alert when its enclosure or software changes.

What the evidence supports

The FBI reported 1,900 ATM jackpotting incidents since 2020, including more than 700 incidents and over $20 million in losses during 2025. Its February 2026 FLASH explains that actors exploit physical and software vulnerabilities and deploy malware that forces machines to dispense cash.

Why it matters to a Connecticut operator

The FBI figures describe U.S. ATM incidents generally, not cannabis dispensaries specifically. The relevant operator action is to manage the ATM as a third-party technology and cash-handling risk.

Operator checklist

  • Record ATM owner, model, software support status, service vendor, and emergency contact.
  • Restrict and monitor physical access to ports, cabinets, and service areas.
  • Require service visits to be scheduled and verified with the vendor.
  • Preserve camera footage and device logs and contact law enforcement promptly after suspicious activity.
Scope note: This briefing separates documented facts from practical recommendations. It is cybersecurity guidance, not legal advice or a statement that every recommended control is expressly required by Connecticut cannabis regulations.

Primary sources

About the author

Alex Castrillo

Founder of CannaShield. Working cyber incident response analyst and vCISO for licensed cannabis operators. Writes on cannabis breach analysis, GRC, cyber insurance readiness, and email-spoofing risk.

CannaShield on LinkedIn →

Make the risk concrete.

Start with the free CannaShield Email Security Scorecard to see whether your domain can be spoofed and whether DMARC, SPF, and DKIM are giving attackers room to impersonate your cannabis business.

Run the free scorecard →

Keep sharpening the cannabis security picture.