What if a single unpatched software update could cost you millions? What if AI tools on the dark web let anyone attack your ATM network?
In this episode of ATM TALKS, host Franco sits down with Nancy Daniels, a 40-year veteran of the ATM industry who has worked for three major OEMs including Hyosung and has spoken at ATMIA, NACK, and other industry conferences on cybersecurity. Nancy started her career working on nuclear weapons during the Cold War. When the Cold War ended, she needed a job—and ended up in the ATM industry. Four decades later, she's one of the most respected voices on ATM security.
The threat landscape has changed. Physical smash-and-grab attacks are down. Cyber attacks are up. In 2025, the largest cyber attack in ATM history impacted nearly 14,000 machines. Criminal networks are now using AI tools to attack ATM networks at scale. And here's the scary part: AI has lowered the barrier to entry. You don't need to be a sophisticated hacker anymore. Joe Criminal can download an AI tool off the dark web and attack your RMS system.
In this episode, Nancy reveals:
The three basics every operator must do: Change default passwords. Keep software updated on both the ATM and your RMS system. Enable TLS encryption between your ATM and processor.
Why default passwords are on the dark web: Manufacturers ship machines with default passwords. Those are publicly available online. Change them immediately. Don't use your birthday or "password123."
The firewall myth: Your router is not a firewall. You need a separate firewall device ($800-$1,000) to protect your RMS system from outside intrusion. It's a simple, one-time investment.
RMS vulnerabilities: Your remote management software is convenient and necessary—but it's also your biggest vulnerability. Turn it off when not in use. Protect it with a firewall. Update it regularly.
Skimmers are old news: Chip and PIN made skimming harder. Criminals have moved to POS terminals where they get 100 swipes a day instead of 150 a month. Large banks have stopped installing anti-skimming devices because they now protect fraud at the software level.
Buying used machines is safe: Change the password and update the software immediately. You can save $500+ per machine. A well-maintained ATM can last 10-15 years. Nancy has seen 20-year-old Hyosung machines still dispensing $20 bills in New York bodegas.
The shift to Linux: ATMs run on Microsoft Windows. That's a security risk. The industry is shifting to Linux operating systems, which are inherently more secure and extend machine life.
Tap and withdraw is coming: The pin pad's days are numbered. Magstripes (invented in 1963) are going away. The future is tap and withdraw—pre-staged transactions on mobile devices. Better security, better customer experience.
Regulators don't understand the industry: Eleven separate federal agencies are involved with ATM networks. They work at cross-purposes. The FBI, Secret Service, and FinCEN understand. Others don't. Nancy spends time in Washington lobbying for better regulation and enforcement.
Cash is alive and well: The underground cash economy is $1.9 trillion—15% of GDP. Hairdressers, nail technicians, servers, gardeners. Over 50% of transactions are in cash for people making under $25,000 (30% of the U.S. population). Federal Reserve data shows cash in circulation grows 3-4% every year.
The human factor: Social engineering, deepfakes, and voice mimicry are real threats. If something feels off, trust your gut. Double verify. People have instincts that AI systems don't.
Connect with Nancy Daniels. Find her speaking at ATMIA, NACK, and industry events. She continues to lobby in Washington for better regulation and enforcement.
Subscribe to ATM TALKS for weekly conversations with operators, innovators, and industry leaders shaping the future of cash.