A significant victory for federal prosecutors has been achieved with the guilty pleas of five Venezuelan nationals involved in a coordinated campaign to compromise Automated Teller Machines (ATMs) nationwide through advanced malware, a tactic commonly known as jackpotting. This development underscores the persistent threat posed by transnational criminal organizations to critical financial infrastructure and highlights ongoing efforts by law enforcement to dismantle such networks.
The individuals, identified as Luis Alberto Velasquez-Artigas (27), Royder Adrian Figuera-Perez (29), Javier Mejia, Jr. (27), Gabriel Alexjandro Corales-Garcia (33), and Italo Lizandro Corrales-Carrillo (26), each entered a plea of guilty to one count of conspiracy to commit bank larceny. Their admissions of guilt mark a pivotal moment in the ongoing battle against sophisticated financial cybercrime, specifically targeting the vulnerable points within the physical banking system. While Velasquez-Artigas has already received a nine-month prison sentence, the remaining defendants await their respective judicial determinations.
The modus operandi of these criminal syndicates, and specifically the group now facing justice, involved meticulous planning to exploit perceived security weaknesses in ATM hardware and software. As articulated by U.S. Attorney Ryan A. Kriegshauser, the conspirators deliberately sought out machines that they believed were inherently susceptible to malware injection. This targeted approach, rather than indiscriminate attempts, suggests a level of reconnaissance and technical understanding aimed at maximizing their illicit gains. The U.S. Attorney’s Office has actively advocated for financial institutions to bolster their defenses through technological upgrades, offering guidance on how to implement robust anti-jackpotting measures. This proactive stance reflects a broader recognition among law enforcement of the evolving nature of cyber-enabled financial crime.
ATM jackpotting, a term derived from the visual spectacle of an ATM dispensing all its cash as if hitting a lottery jackpot, represents a sophisticated form of theft that marries physical intrusion with cyber exploitation. At its core, jackpotting involves compelling an ATM to eject its entire cash contents by manipulating its internal dispensing mechanism. This is typically achieved by installing malicious software directly onto the ATM’s internal computer system. Once the malware is embedded, it can be remotely controlled or activated via an attached USB keyboard or even the machine’s built-in PIN pad, allowing criminals to issue commands that override normal security protocols and empty the cash cassettes.
The history of ATM malware is a grim testament to the ingenuity of criminal enterprises. Over the past decade, a rogues’ gallery of malware families has emerged, each designed with specific functionalities to facilitate jackpotting. Notable examples include ATMii, ATMitch, GreenDispenser, Alice, RIPPER, Skimer, SUCEFUL, and Ploutus. These malwares vary in their sophistication, methods of infection, and the types of ATMs they target. Some require direct physical access to the ATM’s internal components to install the malware, often involving drilling or prying open access panels. Others leverage network vulnerabilities, social engineering, or even supply chain compromises to infect machines remotely. The constant evolution of these threats necessitates a dynamic and adaptive security posture from financial institutions.
The specific incidents leading to the arrests of these five individuals occurred in December 2025. Surveillance footage from Wamego and Manhattan, Kansas, captured the defendants attempting to install malware into ATMs. In Wamego, their efforts to inject the malicious code triggered an alarm system, prompting a law enforcement response and causing the perpetrators to abandon their attempts. Similarly, in Manhattan, the group was unsuccessful in compelling the ATM to dispense cash. These failed attempts, meticulously documented by security cameras, proved crucial in their subsequent apprehension just days later. The Justice Department emphasized that while the conspirators did not succeed in stealing money in these specific instances, their intent and actions constituted a serious federal offense.

This string of arrests and guilty pleas is part of a larger, concerted effort by U.S. federal agencies to combat a surge in ATM jackpotting attacks. The Federal Bureau of Investigation (FBI) issued a stark warning in February, revealing that over $20 million had been illicitly obtained through such schemes in the preceding year alone. This alarming figure underscores the significant financial impact these attacks have on the banking sector and, by extension, on consumers.
A critical dimension to this escalating threat involves the increasing participation of transnational organized criminal groups, particularly those originating from Venezuela. The recent arrests are closely linked to a broader crackdown on the "Tren de Aragua," a notorious Venezuelan criminal organization. This syndicate has been implicated in a massive ATM jackpotting operation across the United States, predominantly deploying the Ploutus malware to siphon millions from ATMs. The Justice Department’s comprehensive response has led to charges against a staggering 87 members of Tren de Aragua, with potential prison sentences ranging from 20 to 335 years, reflecting the severe nature and extensive scope of their criminal activities. This aggressive prosecution highlights the commitment of U.S. authorities to dismantle these sophisticated international networks.
The implications of these jackpotting attacks extend far beyond the immediate financial losses. For financial institutions, the costs are multifaceted, encompassing not only direct cash theft but also significant expenses related to forensic investigations, system remediation, security upgrades, and potential reputational damage. Public confidence in the security of their banking services can be eroded, leading to decreased trust and a potential shift in consumer behavior. The constant need to invest in advanced security technologies and employee training places a considerable burden on bank operating budgets.
From a law enforcement perspective, these cases underscore the complex challenges associated with investigating and prosecuting transnational cybercrime. The cross-border nature of these organizations necessitates robust international cooperation, intelligence sharing, and coordinated enforcement actions. The ability to track, identify, and apprehend individuals operating across different jurisdictions requires sophisticated investigative techniques and strong partnerships with international agencies. The successful prosecution of these five Venezuelan nationals serves as a testament to the effectiveness of such collaborative efforts.
Looking ahead, the landscape of ATM security is expected to continue evolving in response to ever-more sophisticated threats. Criminal groups will undoubtedly adapt their tactics, potentially leveraging advancements in artificial intelligence and machine learning to refine their malware, identify new vulnerabilities, and evade detection. Financial institutions must remain vigilant, adopting a multi-layered security approach that includes enhanced physical security measures, advanced anti-malware solutions, continuous monitoring for anomalous activity, and regular software updates. The integration of behavioral analytics and AI-driven anomaly detection systems could play a crucial role in identifying and mitigating jackpotting attempts before they succeed.
Proactive threat intelligence sharing among banks, law enforcement agencies, and cybersecurity firms will also be paramount. Understanding emerging threat vectors, criminal methodologies, and specific malware signatures can enable financial institutions to implement preventative measures before they become targets. Furthermore, the global nature of these criminal syndicates necessitates a sustained commitment to international collaboration, including treaties for extradition and mutual legal assistance, to ensure that perpetrators cannot simply escape justice by crossing borders.
The recent guilty pleas represent a critical step in disrupting a pervasive and costly form of financial crime. They send a clear message that law enforcement agencies are equipped and determined to pursue those who seek to exploit vulnerabilities in the financial system, regardless of their origin or the sophistication of their methods. However, the ongoing battle against ATM jackpotting and other forms of cyber-enabled financial fraud will require continuous innovation, investment, and collaboration to safeguard the integrity of global financial infrastructure. The push for deportation of convicted foreign nationals, as seen in South Carolina where two Venezuelan nationals convicted of jackpotting are slated for deportation after serving their sentences, further illustrates the comprehensive strategy being employed to deter and punish these criminal acts.







