Bank of America insider to admit planting malware on ATMs

ATM cash machineA worker at Bank of America is expected to plead guilty tomorrow to charges that he installed malware onto his employer’s ATM cash machines that allowed him to withdraw cash without being noticed.

According to prosecutors, 37-year-old Rodney Reed Caverley of Charlotte, North Carolina, was a member of the bank’s IT staff when he infected the ATMs, giving himself the opportunity to make fraudulent withdrawals for a period of seven months until October 2009.

Precise details of how much money is believed to have been stolen have not yet been made public, but it is believed to be at least $200,000.

A spokeswoman with Bank of America says that the firm’s staff detected the problem through their internal systems, and that customers accounts were never at risk. Hopefully the case will act as a handy reminder to all financial firms to keep a watchful eye on who they employ in their IT departments with responsibility for designing and maintaining their computer systems.

Sign up to our free newsletter.
Security news, advice, and tips.

Caverley faces up to five years in jail if found guilty.

ATM theft allegations

This isn’t the first time that the Clu-blog has reported on hackers having ATM cash machines in their sites, of course.

For instance, last October a 23-year-old pizza delivery boy escaped jail after using information he found on the internet to hack into ATMs and change their settings to allow him to steal money, and a year ago Sophos discovered used by Russian hackers in an audacious attempt to steal money.

It’s not known presently whether the malware allegedly installed by Caverley is a variant of that seen in the Russian cases.

Graham Cluley is an award-winning keynote speaker who has given presentations around the world about cybersecurity, hackers, and online privacy. A veteran of the computer security industry since the early 1990s, he wrote the first ever version of Dr Solomon's Anti-Virus Toolkit for Windows, makes regular media appearances, and is the co-host of the popular "Smashing Security" podcast. Follow him on Twitter, Mastodon, Threads, Bluesky, or drop him an email.

What do you think? Leave a comment

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.