Venezuelan Gets Record Federal ATM Sentence
Juan Manuel Gouveia-Aguilera sentenced to 96 months for ATM jackpotting, with DOJ citing $3.5 million in losses.
The U.S. Justice Department announced on Friday that a Venezuelan national has been sentenced to eight years in federal prison for his role in an ATM jackpotting scheme. The case highlights a growing trend of financially motivated cybercrime that targets cash machines directly, with losses mounting into the millions.
Record Sentence in ATM Case
Juan Manuel Gouveia-Aguilera, 27, was sentenced to 96 months in prison, followed by five years of supervised release, and was ordered to pay restitution. He had pleaded guilty to charges of bank fraud, bank burglary, and cyber-enabled fraud.
“The Court found Gouveia-Aguilera to be responsible for more than $3.5 million in losses and this sentence is believed to be the longest federal sentence imposed for an individual’s role in ATM jackpotting,” the DOJ said in its announcement.
The case is part of a broader crackdown that has ensnared more than a hundred individuals across the United States.
More Sentences in Same Scheme
Gouveia-Aguilera’s sentencing comes just weeks after two other Venezuelan nationals, Oddry Arnoldo Cabrera Torrealba and Carlos Javier Padron, each received 78-month prison sentences for their involvement in ATM jackpotting.
These defendants are among 119 individuals charged in Nebraska for ATM jackpotting offenses. The Justice Department said the suspects are believed to work on behalf of the Venezuelan organization Tren de Aragua (TdA).
How ATM Jackpotting Works
The attacks typically involve removing the targeted ATM’s outer casing and connecting a laptop to install malware. The malware then enables the attackers to instruct the ATM to dispense all its cash.
This hands-on approach requires physical access to the machine, but the payoff can be immediate and substantial, with each attack yielding thousands of dollars in cash.
FBI Warning Earlier This Year
Earlier this year, the FBI warned of an increase in malware-enabled ATM jackpotting attacks in the United States. The agency said roughly 1,900 ATM jackpotting attacks had been reported since 2020, with incidents recorded last year resulting in losses that exceeded $20 million.
These figures underscore the scale of the problem, even as enforcement efforts continue.
Broader Context of Cyber-Enabled Financial Crime
The case is part of a larger pattern of cyber-enabled financial crimes that blend physical intrusion with digital tools. While the DOJ’s announcement focuses on the individual sentence, the trend of ATM jackpotting has drawn attention from law enforcement and financial institutions alike.
The investigation that led to the charges in Nebraska appears to be a coordinated effort, involving multiple agencies and resulting in a significant number of indictments.
What This Means for ATM Operators
For banks and credit unions, the persistence of these attacks serves as a reminder of the need for robust physical security measures and cybersecurity defenses. The technique of installing malware via a laptop requires attackers to have physical access to the machine, so securing the immediate surroundings of ATMs could be as important as software protections.
Consumers may experience disruptions in cash access during such attacks, but the direct financial impact is typically borne by financial institutions. Still, the frequency of these schemes suggests that ATM operators must remain vigilant against both physical tampering and malware-based attacks.
Why It Matters
The record sentence for Gouveia-Aguilera signals that U.S. courts are treating ATM jackpotting as a serious financial crime with significant consequences. While this case concludes with a lengthy prison term, the underlying threat persists, as the FBI’s data shows hundreds of attacks each year. For financial institutions, this may mean investing more in ATM hardening and monitoring to prevent future losses, and for the public, it raises questions about the security of everyday banking infrastructure.
Sources
- SecurityWeek Original source
Continue Reading
Notion, PDFs, and PaaS: Token Theft's New Shape
Threat actor Doubloon Dredger exploits Notion and device codes to steal authentication tokens, researchers say.
Agent Tesla Variant Counters Detection With Emoji
New Agent Tesla v4 infostealer uses emoji obfuscation to evade detection and target finance departments.
Rust Supply Chain Attack Tied to North Korea
Wiz links a crates.io compromise to Sapphire Sleet, warning of broad developer exposure.