Search for ATM security and you will find jackpotting: a machine emptied by a laptop wired into its dispenser, filmed on a phone, written up as the defining threat. Vendors in this market — ours included — have an interest in that story staying vivid.

The European Association for Secure Transactions publishes an annual crime report from incidents reported by its member institutions. The figures for 2025, published in April 2026, are worth reading before deciding what to spend money on.

What the figures record

Logical attacks have collapsed:

ATM malware and logical attacks were down 57% (from 3 to 1). No losses were reported.

One reported incident across the reporting membership, in a year. EAST attributes the decline to the industry adopting the countermeasure guidance it published with Europol’s support, and adds that

Given the low levels of such attacks in Europe, from 2026 onwards it is likely that EAST will stop reporting on them.

An industry body preparing to stop counting an attack class is a strong statement about where that class now sits.

Meanwhile the totals went up. Terminal-related fraud attacks rose 40%, from 14,664 to 20,465 incidents, almost entirely because of data relay attacks, which went from 381 incidents to 7,282 — an increase of 1,811%. Those attacks do not touch the machine’s software at all. In the terminal-to-terminal variety a genuine customer uses a compromised terminal; in the card-to-terminal variety the customer has been phished into disclosing account data and PIN.

And the money is somewhere else again. Physical attacks fell by half in count, to 2,986 incidents, but their losses rose 58% to €19 million, of which 71% came from explosive attacks — €13.5 million, up from €8.6 million. Reported fraud losses across all terminal fraud were €3 million.

So in the European data for 2025: logical attacks cost nothing, fraud against genuine transactions is where the incident growth is, and blowing the machine open is where the losses are.

What that does to the usual sales argument

If the reason to control engineer access to a self-service device is to stop jackpotting, the European numbers do not support the spend. That is worth saying plainly, including by a vendor selling access control.

Three things survive the numbers, though.

The decline is attributed to controls, not to attackers losing interest. EAST credits the industry’s adoption of countermeasures for driving the attacks down. A control class that works looks, in the statistics, exactly like a control class that was never needed. The distinction only shows up when it is removed — and the machines that were hardest to attack are the reason the count is one rather than fifty.

The residual attack still runs through the service area. A black box attack means opening the machine and connecting to the dispenser. Whatever else changes, physical and logical access to the interior remains the path, and the people with legitimate access to that interior are a small, identifiable population whose credentials are worth managing well.

The obligations did not decline with the incidents. PCI DSS requirement 8, ISO/IEC 27002’s access controls and the rest apply to the cardholder data environment regardless of how many attacks were reported last year. An assessor does not grade on threat frequency. We have written separately about what requirement 8 asks of an offline device and how ISO reads on the same machines.

That is a narrower argument than the one usually made, and it is the one the evidence carries.

What the figures do not say

They are reported incidents from EAST member institutions in Europe — not a census, and not global. Under-reporting is a known property of fraud statistics generally: an incident that produced no loss and no customer impact is the kind least likely to be escalated to an industry body. A single reported logical attack means the reported number is one, which is not the same as the real number being one.

The regional limit matters more. Nothing above describes deployments outside Europe, where device populations, cash logistics, network exposure and the maturity of the countermeasure guidance all differ. Anyone quoting these figures — us included — should say which market they describe.

And the figures say nothing about insider activity, which does not usually surface as an “attack” in this taxonomy at all. Access misused by someone entitled to it is recorded, if it is recorded anywhere, as something else.

The honest version

The case for controlling who signs in to a self-service machine is not that jackpotting is rampant in Europe, because by these numbers it is not. It is that the interior of the machine is the path for the attacks that remain, that the people with access to it are few and worth knowing individually, that regulators ask for it independently of the threat count, and that the current low numbers are partly a product of controls that only stay effective while they are in place.

If someone sells you a device-access product with a jackpotting video, ask them for the incident figures in your market and the year they refer to.

Sources