ATM jackpotting ring pleads guilty in Kansas
Five Venezuelans admit to failed ATM malware attacks; U.S. urges banks to adopt anti-jackpotting tech.
Five Venezuelan nationals have pleaded guilty to charges of conspiracy to commit bank larceny for a string of ATM jackpotting attempts in the United States, federal prosecutors announced Monday. The group's final effort, in Kansas, ended with surveillance cameras capturing their failed attempts and their arrest days later.
Guilty pleas and sentencing
Luis Alberto Velasquez-Artigas, 27, Royder Adrian Figuera-Perez, 29, Javier Mejia Jr., 27, Gabriel Alexjandro Corales-Garcia, 33, and Italo Lizandro Corrales-Carrillo, 26, each pleaded guilty to one count of conspiracy to commit bank larceny. Velasquez-Artigas has already been sentenced to nine months in prison, while the other four await sentencing.
Failed heists caught on camera
The defendants were arrested in December 2025, days after failing to install malware on ATMs in Wamego and Manhattan, Kansas. According to the Justice Department, the group's attempt in Wamego triggered an alarm that brought law enforcement, and the culprits never returned. In Manhattan, they were equally unsuccessful in getting the machine to dispense cash. Both attempts were captured by surveillance cameras.
“Jackpotting bandits are sweeping the nation. This particular group’s strategy was to specifically target ATMs they thought were by design more vulnerable to malware. Fortunately, there is technology to help thwart jackpotting. We at the U.S. Attorney’s Office encourage banks and other financial institutions to invest in these updates, and we’re happy to answer questions about how to do so.”
— U.S. Attorney Ryan A. Kriegshauser
How jackpotting works
In a typical jackpotting attack, criminals install malware on an ATM's internal computer, then use a USB keyboard or the machine's built-in PIN pad to issue commands that force the cash dispenser to eject money. Over the years, law enforcement has documented a range of malware families used for this purpose, including ATMii, ATMitch, GreenDispenser, Alice, RIPPER, Skimer, SUCEFUL, and Ploutus.
A surge in attacks and arrests
The FBI warned in February that criminals stole over $20 million last year in a massive surge of ATM jackpotting incidents. That warning came after a wave of arrests targeting members of the Tren de Aragua Venezuelan criminal organization, all linked to a large-scale scheme that used Ploutus malware to steal millions from ATMs across the U.S.
In total, the Justice Department has charged 87 Tren de Aragua members, who now face maximum prison terms ranging from 20 to 335 years each. In January, South Carolina federal prosecutors also announced that two Venezuelan nationals convicted of jackpotting attacks will be deported after serving their sentences.
Key numbers in the case
- $20 million: amount stolen in ATM jackpotting incidents last year, according to the FBI
- 87: Tren de Aragua members charged by the Justice Department
- 20 to 335 years: maximum prison terms the charged members face
- Five: defendants who pleaded guilty in this case
Why it matters
These guilty pleas, coming amid a broader federal crackdown on Tren de Aragua, show that ATM jackpotting remains a persistent threat that can be countered with updated technology. For banks and credit unions, the message from prosecutors is clear: investing in anti-jackpotting defenses is not optional, but a necessary step to protect both their cash and their customers' trust. As the FBI's warning suggests, the scale of losses is large enough to warrant a coordinated industry response.
Sources
- BleepingComputer Original source
Continue Reading
Cronos Restart Follows $74M Lending Exploit
Cronos blockchain resumes after price manipulation drained $74M from Tectonic lending app.
Nigerian sextortion suspects face US charges after teen deaths
Two Nigerian men extradited to the US over sextortion schemes linked to deaths of two minors face life sentences.
McKesson Breach Stakes Rise as Deadline Nears
Healthcare giant McKesson confirms data theft as ShinyHunters threat to leak by September 1.