Visualização normal

Antes de ontemStream principal
  • ✇Security Affairs
  • Five Venezuelan Nationals Plead Guilty in Kansas ATM Jackpotting Attempt Pierluigi Paganini
    Five Venezuelan nationals pleaded guilty after failed ATM jackpotting attempts in Kansas. The FBI recorded 700+ cases in 2025, causing $20M in losses. Five Venezuelan nationals have pleaded guilty after trying to steal cash from ATMs in Kansas using the popular ATM jackpotting technique. The U.S. Department of Justice announced the case on August 31, following an FBI investigation that ended with the suspects’ arrests just days after the attempted thefts. The case started in December 2025
     

Five Venezuelan Nationals Plead Guilty in Kansas ATM Jackpotting Attempt

1 de Setembro de 2026, 10:50

Five Venezuelan nationals pleaded guilty after failed ATM jackpotting attempts in Kansas. The FBI recorded 700+ cases in 2025, causing $20M in losses.

Five Venezuelan nationals have pleaded guilty after trying to steal cash from ATMs in Kansas using the popular ATM jackpotting technique. The U.S. Department of Justice announced the case on August 31, following an FBI investigation that ended with the suspects’ arrests just days after the attempted thefts.

The case started in December 2025, when the five defendants traveled from Indiana to Kansas and targeted ATMs in Wamego and Manhattan. According to court documents cited by the DOJ, their plan was to install malware directly onto the machines and then remotely trigger the infected ATMs to dispense cash, which the group would collect afterward.

“The conspirators were unsuccessful in installing the malware on the ATM in Wamego, but their attempts at installing the malware triggered the alarm causing law enforcement to respond, and the culprits didn’t return to the site. In Manhattan, the group was equally unsuccessful in getting the ATM to dispense money. Both attempted thefts were captured by surveillance cameras, and the perpetrators were arrested a few days later.”

“According to court documents, Luis Alberto Velasquez-Artigas, 27, Royder Adrian Figuera-Perez, 29, Javier Mejia, Jr, 27, Gabriel Alexjandro Corales-Garcia, 33, and Italo Lizandro Corrales-Carrillo, 26, all pleaded guilty to one count of conspiracy to commit bank larceny.” reads DoJ.

The operation failed at both locations. In Wamego, attempts to install the malware triggered the ATM’s alarm, bringing law enforcement to the site and forcing the group to leave without completing the attack; in Manhattan, the criminals again failed to make the ATM dispense money. Surveillance cameras captured both attempts, and investigators arrested the suspects a few days later.

The DOJ identifies the five defendants as Luis Alberto Velasquez-Artigas, 27; Royder Adrian Figuera-Perez, 29; Javier Mejia Jr., 27; Gabriel Alexjandro Corales-Garcia, 33; and Italo Lizandro Corrales-Carrillo, 26. All pleaded guilty to one count of conspiracy to commit bank larceny. Velasquez-Artigas has already received a nine-month prison sentence, while the other four defendants are awaiting sentencing.

The important point for financial institutions is that jackpotting doesn’t depend on a customer using a stolen card or entering fraudulent credentials. Instead, criminals attack the ATM itself, using malware to take control of its cash-dispensing function. The FBI describes this as an emerging nationwide problem and says these attacks can allow criminals to steal cash without any legitimate transaction taking place.

The numbers help explain why federal authorities are paying attention. In a February 2026 FLASH, the FBI reported 1,900 ATM jackpotting incidents since 2020, including more than 700 in 2025 alone, with losses exceeding $20 million during that year.

The Kansas case also shows that jackpotting is not simply a software problem. The criminals needed physical access to the ATM to install the malware, but their plan then relied on remote activation to make the machine release the cash. That combination of physical intrusion and remote control makes jackpotting a hybrid security problem for banks.

The DOJ says the group specifically targeted ATMs they believed were more vulnerable to malware. That’s a relevant detail because it suggests some attackers may assess ATM technology before choosing their targets, rather than simply trying the technique against random machines.

That also explains why the U.S. Attorney’s Office is urging banks and other financial institutions to take preventive action. The advice is not limited to investigating theft after the fact. Authorities are asking institutions to invest in technology and security updates designed to prevent jackpotting attempts from succeeding in the first place.

For banks, the case is a reminder that ATM security now sits at the intersection of physical security, cybersecurity and fraud prevention. Protecting the customer account isn’t enough when the criminal’s objective is to compromise the machine and make it hand over the cash itself.

The FBI has made clear that it plans to continue working with financial institutions and law-enforcement partners to identify these schemes and strengthen defenses. The Kansas case shows that the attackers don’t need a successful cash-out to attract federal attention. In this case, the alarm went off before the ATM did its part.

“Jackpotting bandits are sweeping the nation. This particular group’s strategy was to specifically target ATMs they thought were by design more vulnerable to malware,” said U.S. Attorney Ryan A. Kriegshauser. “Fortunately, there is technology to help thwart jackpotting. We at the U.S. Attorney’s Office encourage banks and other financial institutions to invest in these updates, and we’re happy to answer questions about how to do so.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, ATM jackpotting)

  • ✇Firewall Daily – The Cyber Express
  • ATM Jackpotting Gang Members Sentenced for Ploutus Malware Attacks Samiksha Jain
    Two Venezuelan nationals have been sentenced to 78 months in prison for their role in an ATM jackpotting scheme that used malware to force cash machines across the United States to dispense money illegally. The operation, which authorities say was part of a broader transnational criminal network, involved the deployment of Ploutus malware on ATMs and resulted in losses exceeding $1.5 million. Carlos Javier Padron, 36, was sentenced after pleading guilty to conspiracy to commit bank burglary and
     

ATM Jackpotting Gang Members Sentenced for Ploutus Malware Attacks

ATM jackpotting

Two Venezuelan nationals have been sentenced to 78 months in prison for their role in an ATM jackpotting scheme that used malware to force cash machines across the United States to dispense money illegally. The operation, which authorities say was part of a broader transnational criminal network, involved the deployment of Ploutus malware on ATMs and resulted in losses exceeding $1.5 million.

Carlos Javier Padron, 36, was sentenced after pleading guilty to conspiracy to commit bank burglary and computer fraud. His co-defendant, Oddry Arnoldo Cabrera Torrealba, 37, received the same sentence on June 11 after pleading guilty to identical charges.

Ploutus Malware Used to Trigger Unauthorized Cash Withdrawals

According to court documents, Padron and Torrealba were members of a criminal network responsible for carrying out ATM jackpotting attacks across the United States. Their role involved physically installing a variant of Ploutus malware on targeted ATMs.

Once activated, the malware enabled attackers to send commands directly to the ATM's cash dispensing module, allowing unauthorized withdrawals of currency. Investigators said the malware was also designed to erase traces of its presence, making it more difficult for financial institutions to detect the compromise.

The two men were arrested by the Lincoln Police Department during an ATM jackpotting incident in October 2024.

More Than $1.5 Million Ordered in Restitution

Along with their prison sentences, Padron and Torrealba were jointly ordered to pay $1,537,696 in restitution to the affected financial institutions.

Officials said the investigation uncovered a much larger criminal operation following their arrests. Authorities have since indicted 96 additional individuals connected to the conspiracy on charges including bank burglary conspiracy, money laundering, computer fraud, unauthorized access to protected computers, bank fraud, and providing material support to a designated foreign terrorist organization.

Authorities Link Scheme to Tren de Aragua

U.S. officials stated that the investigation established direct and indirect links between several indicted co-conspirators and Tren de Aragua, a transnational criminal organization that originated in Venezuela.

According to investigators, the group has expanded its operations throughout the Western Hemisphere and has been involved in crimes including drug trafficking, firearms trafficking, kidnapping, robbery, extortion, commercial sex trafficking, and financial fraud.

Authorities allege that ATM jackpotting became one of the organization's revenue-generating activities, targeting financial institutions across the United States through coordinated cyber-enabled attacks.

Justice Department Says Financial Crimes Fund Organized Crime

Assistant Attorney General A. Tysen Duva said the defendants helped deploy malware as part of a criminal network that stole millions of dollars from ATMs across the country. He added that disrupting such operations is critical to protecting financial institutions from technology-enabled fraud.

U.S. Attorney Lesley Woods for the District of Nebraska described ATM jackpotting as a significant revenue source used to finance the criminal activities attributed to the organization and said federal prosecutors would continue targeting its financial networks.

The FBI's Omaha Field Office said it continues to adapt its investigative efforts as criminal organizations increasingly rely on cyber-enabled financial crimes. Homeland Security Investigations also stated that the prosecution was intended to protect both consumers and the U.S. financial system from organized criminal activity.

Multi-Agency Investigation Continues

The investigation was led by the FBI Omaha Field Office and Homeland Security Investigations, with assistance from numerous federal, state, and local law enforcement agencies across the United States.

The case is being prosecuted by the Justice Department's Computer Crime and Intellectual Property Section, the U.S. Attorney's Office for the District of Nebraska, and Joint Task Force Vulcan.

Officials said the case forms part of a broader federal effort targeting transnational criminal organizations involved in cybercrime, financial fraud, and other organized criminal activities. The investigation into the wider network remains ongoing.

❌
❌