The bank heist movies of the future will probably feature more keyboards than guns. Just look at this Russian and Ukrainian hacker group that is having no problem cleaning out banks. The cybercriminals have already stolen from bank accounts, but now they're getting even more brazen and taking money straight from bank ATMs.
The attacked banks weren't in the U.S., but the tactics used by the hackers would likely work here, too. The Anunak Group hacks its way into bank systems using phishing emails full of malware, and by buying already-infected computers from other hackers. They disguised the emails to look like they came from Russian banking officials. Once inside a bank's network, the group tried to infect more banks and used other malware to access the bank's ATM system.
The hackers used that malware — along with a modified legitimate program for managing ATM cash trays — to change the denomination settings for bank notes in 52 different ATMs.
Then, when their partners tried to withdraw 100 rubles from affected ATMs, the machines actually spit out 5,000 rubles. The heists have resulted in a payday worth around $15 million. This likely isn't their first high-profile string of hacks, either.