Beware! 3 out of 5 ATMs in India use outdated technology, prone to hacking

The worrying fact is cash loaders don't use the 'one-time combination' method, which is akin to OTP

Fake notes of ~2000 which were dispensed by an SBI ATM in south Delhi on Wednesday Photo: PTI
Fake notes of ~2000 which were dispensed by an SBI ATM in south Delhi on Wednesday Photo: PTI
BS Web Team New Delhi
Last Updated : Feb 28 2017 | 2:47 PM IST
Post-demonetisation, all ATMs across the country were recalibrated to dispense the new Rs 2,000 and Rs 500 notes. However, security issues are a prime concern, as many ATMs still rely on outdated technology.

Three out of five ATMs in India use outdated technology and lack basic security features, a Hindustan Times report said. 

Generally, cash is loaded in ATMs by logistics companies and not banks. These companies transport the currency notes from bank currency chests to branches and ATMs and maintain the machines too.  

The worrying fact is cash loaders do not use the "one-time combination" (OTC) method which is used by most developed countries. Under this system, the loaders are given a one-time combination number – a kind of password – to access the ATM. As the loading exercise is completed, the combination expires and cannot be re-used. It helps in tracking the exercise and minimises fraud.

Besides that most of the country’s 2,20,000 ATMs are not monitored by working closed-circuit television cameras (CCTV). “We have urged the banks several times to install OTC locking system at the ATMs so that monitoring improves, unfortunately most banks do not pay heed,” HT quoted NSG Rao, secretary of Cash Logistics Association as saying. He added that banks had no data on whether the CCTVs installed in ATMs were in working condition.

On a daily basis, about Rs 14,000 crore is carried by cash vans across India, the report added. 

Over 70 per cent of the 200,000 ATM machines in the country are running on Microsoft’s outdated Windows XP operating system, leaving it vulnerable to cyber attacks, a report published in The Quint in December said. 

In late 2016, following a malware-related security breach, the State Bank of India (SBI), HDFC Bank, ICICI Bank, Axis Bank and YES Bank blocked millions of debit cards that were compromised in one of the biggest data breaches in the country's financial sector. 

Recently, several cases of ATMs dispensing fake notes were reported. On Monday, ICICI Bank ordered a probe into an incident where a customer in Rohtak in Haryana reportedly got Rs 2,000 notes bearing 'Children Bank of India'.

Similarly, SBI ATMs dispensed fake Rs 2,000 notes in Uttar Pradesh's Shahjahanpur and Delhi last week.

Following the Delhi incident,  a 27-year-old man working with an ATM cash loading company was arrested on charges of exchanging five original Rs 2,000 bills with the 'Children's Bank of India' notes that were dispensed from the SBI ATM. 

One subscription. Two world-class reads.

Already subscribed? Log in

Subscribe to read the full story →
*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

Next Story