What is not reported is how they accessed the internals of the ATM's. You cannot just walk up to one and slip in a disk or plug in a keyboard...
Did they steal them? Have an inside man with access to the internals to plant the malware and plug in a Bluetooth keyboard dongle so they could later just drive up and do the thefts?
You have to check the second link that I attached here as there is the description on how the criminals attacks the ATM,
The Ploutus ATM malware family, first detected in 2013 by Symantec as Backdoor.Ploutus, allows attackers to withdraw cash from an ATM machine on command. The malware is installed by accessing the ATM’s CD-ROM drive and inserting a new boot disk that delivers the Ploutus variant. After connecting an external keyboard to the ATM machine, threat actors must press ‘F8’ to display the hidden trojan window. Once visible, numerous commands can be executed such as pressing ‘F1’ to generate ATM ID, ‘F2’ to activate ATM ID, and ‘F3’ to dispense cash.
So the attackers goes to the root, the ATM's CD-ROM and compromised it with a new boot disk that have the malware, then connecting a external keyboard to control everything. So there is no inside man, it's that the attack are sophisticated. Although there is still some questions on how they know the exploit to begin with. They could have a blue print of the machine itself to study and have someone with technical abilities to come up with this kind of exploits.