ATM jackpotting attacks involve criminals dressing as ATM technicians to open ATM cabinets. The NSA TAO hardware interdiction involved intercepting Cisco equipment in transit and resealing packages. FIN7 mailed USB drives in Amazon packaging. Physical security of hardware requires verifying the identity of anyone who physically touches infrastructure equipment. Before allowing anyone access to a server room, network closet, or ATM cabinet, call the organisation they claim to represent using a phone number from your own records — not a number they provide. Require government-issued ID and a work order that you can verify.
Tags