We’ve all had that moment at an ATM where you’re silently begging it to just work. Now picture the opposite: an ATM that works a little too well… for criminals. A recent U.S. case where five Venezuelan nationals pleaded guilty after trying (and failing) to “jackpot” ATMs in Kansas is a great reality check for banks. The story has all the ingredients—surveillance video, triggered alarms, December 2025 arrests, and even one nine‑month sentence—plus some big takeaways on how jackpotting usually works and what banks can do to make their ATMs way less tempting targets.
The Kansas jackpotting attempt: what prosecutors say happened (and what went wrong for the crew)
The Kansas case reads like one of those security videos you only notice after something sketchy happens in the background.
According to federal prosecutors, five Venezuelan nationals tried to pull off ATM jackpotting—the kind where attackers attempt to use malware to make an ATM dispense cash—in Wamego and Manhattan, Kansas.
The timeline (Wamego → Manhattan → arrests)
1) Wamego, Kansas: the install didn’t stick
Prosecutors say the group was unsuccessful installing malware on the ATM in Wamego.
And they didn’t just “fail quietly.” Their attempt triggered the alarm, police responded, and the crew didn’t return to the site.
2) Manhattan, Kansas: no payout there either
In Manhattan, the story was basically the same: they were equally unsuccessful at getting the ATM to spit out money.
Both attempts were captured on surveillance cameras—which matters, because jackpotting crews rely on time and privacy, and they didn’t get much of either.
3) December 2025: caught days later
Authorities say the five were arrested in December 2025, just days after those failed attempts in Wamego and Manhattan.
All five later pleaded guilty to conspiracy to commit bank larceny.
Who they are and where the case stands
The defendants named in reporting are Luis Alberto Velasquez-Artigas, Royder Adrian Figuera-Perez, Javier Mejia, Jr, Gabriel Alexjandro Corales-Garcia, and Italo Lizandro Corrales-Carrillo.
Velasquez-Artigas has already been sentenced to nine months in prison, while the other four were awaiting sentencing at the time of the report.
The part banks should really care about: “more vulnerable by design”
Here’s the detail that should make any ATM owner sit up a little straighter. U.S. Attorney Ryan A. Kriegshauser said “jackpotting bandits are sweeping the nation,” and that this group’s strategy was to target ATMs they believed were “by design more vulnerable to malware.”
That’s the uncomfortable truth: jackpotting crews don’t pick targets at random. They pick what they think will be easy—a machine model, setup, or location that gives them the best shot at getting hands-on access long enough to try an install.
And even though this crew walked away empty-handed, the method they attempted is the same playbook banks keep seeing—malware, physical access, and a short window to force the machine to cooperate.
How ATM jackpotting usually works (high-level, no “how-to” cheat sheet)
If you zoom out, ATM jackpotting isn’t magic. It’s criminals treating an ATM like what it really is: a specialized computer with a cash box attached.
The key idea: they’re not “hacking your account.” They’re trying to make the machine itself cough up cash.
The basic flow (what happens without the juicy step-by-step)
At a high level, jackpotting follows a pretty consistent pattern:
- Get access to the ATM’s internal computer.
This is the “hands-on” part. If attackers can physically reach the guts of the machine, their odds go way up.
- Install ATM malware on that internal computer.
Once malware is on the ATM, it can be set up to interact with the ATM’s own components—especially the cash dispenser.
- Send “dispense” commands using an input method the ATM will accept.
Reporting on jackpotting notes that criminals can control the malware using something as simple as an attached USB keyboard or even the ATM’s built-in PIN pad, then issue commands to the internal cash dispenser.
That’s the whole scam in three moves: access → install → command.
Malware families banks should recognize (seen in the wild)
“ATM malware” isn’t one thing. It’s a category with a history—and names that pop up again and again in incident reports.
Some of the better-known examples referenced in reporting include: ATMii, ATMitch, GreenDispenser, Alice, RIPPER, Skimer, SUCEFUL, and Ploutus.
You don’t need your branch team memorizing that list like trivia night. The point is simpler: this is a repeatable crime, with reusable tools.
Why old systems + weak physical access controls make this easier
Jackpotting tends to thrive when two things line up:
- A machine that’s easier to tamper with physically (think: access panels, exposed ports, predictable layouts)
- A tech stack that’s harder to keep locked down (older/unsupported operating systems and software don’t age like fine wine)
And once criminals can touch the internal computer, they can try the same general trick: plant malware and use a direct input path—USB keyboard or PIN pad—to tell the dispenser what to do.
This isn’t a one-off: the bigger wave (FBI warning, Ploutus, and organized crews)
If Section 2 made jackpotting sound “repeatable,” here’s the part that makes it feel urgent: it’s already been repeatable at scale.
The FBI’s 2025 warning: this got expensive fast
The FBI warned that criminals stole over $20 million during a surge of ATM malware / jackpotting incidents in 2025.
That number matters because it changes how you should think about risk. This isn’t petty crime. It’s organized theft with a playbook that’s paying out often enough to keep crews coming back.
Organized crews + one of the usual suspects: Ploutus
Federal cases and reporting have tied major U.S. activity to Tren de Aragua, a Venezuelan criminal organization, in a large ATM jackpotting scheme that deployed Ploutus malware to steal millions from ATMs across the United States.
Two takeaways for banks:
- This is coordinated. When a scheme stretches “across the United States,” you’re not dealing with a lone opportunist.
- It’s tool-driven. Crews reuse malware families (like Ploutus) because it’s efficient, not because it’s fancy.
The enforcement side is big too (because the footprint is big)
After that surge, reporting notes a wave of arrests connected to the Tren de Aragua-linked jackpotting activity.
In total, the Justice Department has charged 87 Tren de Aragua members, with maximum prison terms reported as ranging from 20 to 335 years each.
So when a small-town attempt hits the news, it’s not “random.” It’s a visible piece of a much larger pattern: ATM malware attacks, repeat crews, repeat tools, repeat targets.
Bank defenses that actually move the needle (practical, non-technical, and testable)
When prosecutors talk about crews picking machines that are “more vulnerable by design,” they’re basically describing a target list. Your job is to get off it.
U.S. Attorney Ryan A. Kriegshauser put it plainly: there is technology that can help thwart jackpotting, and banks should invest in updates. The trick is turning that idea into a checklist you can actually run.
Hardening + hygiene (boring stuff that stops exciting crimes)
If attackers need hands-on time at the ATM, your best wins come from reducing what they can do during that window.
1) Rank your ATM fleet by risk
- Flag models/configurations that have been common targets or are harder to update.
- Prioritize locations where someone can loiter without being noticed (yes, criminals “shop” for that).
2) Patch like you mean it
- Keep ATM software and security updates current so you’re not stuck defending yesterday’s tech with today’s threats.
- Build a simple KPI: % of ATMs fully up to date, reviewed monthly.
3) Remove “easy entry” paths
This is less “cyber” and more “don’t give them a door.”
- Tighten service-panel security and port access where possible.
- Treat every exposed access point like it’s an invitation.
Control + response (because prevention isn’t perfect)
Even a well-maintained fleet can get tested. So you want fast detection and a no-drama response.
Physical access controls that hold up in real life
- Restrict and audit who can open ATM cabinets and when.
- Make keys/credentials trackable, not “shared drawer” items.
- Use tamper-evident measures that get checked on a schedule (not “whenever someone remembers”).
Monitoring and alerts that catch jackpotting patterns
Attackers ultimately want the dispenser to do something weird—like dispense cash when it shouldn’t.
Set alerts for:
- Cabinet door / panel open events outside service windows
- Unusual dispenser behavior (unexpected dispense, repeated dispense attempts, abnormal sequences)
- ATM out-of-service changes that happen right before suspicious activity
Incident response that feels like a fire drill, not a surprise party
Have a runbook that answers, in plain language:
- Who gets paged (and who’s backup)?
- Who can remotely disable the ATM or halt dispensing?
- Who pulls surveillance footage and when?
- Who talks to law enforcement and what evidence gets preserved?
If you can’t walk through those four steps in under five minutes, you don’t have a runbook yet—you’ve got a document.


.png)
