September 3, 2026

What the Venezuelan “ATM Jackpotting” Guilty Pleas Tell Us - Could Your Bank Be Next? (and How to Stop the Next One)

by
Arjun Bhatnagar
September 3, 2026
Copy link to blog

We’ve all had that moment at an ATM where you’re silently begging it to just work. Now picture the opposite: an ATM that works a little too well… for criminals. A recent U.S. case where five Venezuelan nationals pleaded guilty after trying (and failing) to “jackpot” ATMs in Kansas is a great reality check for banks. The story has all the ingredients—surveillance video, triggered alarms, December 2025 arrests, and even one nine‑month sentence—plus some big takeaways on how jackpotting usually works and what banks can do to make their ATMs way less tempting targets.

The Kansas jackpotting attempt: what prosecutors say happened (and what went wrong for the crew)

The Kansas case reads like one of those security videos you only notice after something sketchy happens in the background.

According to federal prosecutors, five Venezuelan nationals tried to pull off ATM jackpotting—the kind where attackers attempt to use malware to make an ATM dispense cash—in Wamego and Manhattan, Kansas.

The timeline (Wamego → Manhattan → arrests)

1) Wamego, Kansas: the install didn’t stick

Prosecutors say the group was unsuccessful installing malware on the ATM in Wamego.

And they didn’t just “fail quietly.” Their attempt triggered the alarm, police responded, and the crew didn’t return to the site.

2) Manhattan, Kansas: no payout there either

In Manhattan, the story was basically the same: they were equally unsuccessful at getting the ATM to spit out money.

Both attempts were captured on surveillance cameras—which matters, because jackpotting crews rely on time and privacy, and they didn’t get much of either.

3) December 2025: caught days later

Authorities say the five were arrested in December 2025, just days after those failed attempts in Wamego and Manhattan.

All five later pleaded guilty to conspiracy to commit bank larceny.

Who they are and where the case stands

The defendants named in reporting are Luis Alberto Velasquez-Artigas, Royder Adrian Figuera-Perez, Javier Mejia, Jr, Gabriel Alexjandro Corales-Garcia, and Italo Lizandro Corrales-Carrillo.

Velasquez-Artigas has already been sentenced to nine months in prison, while the other four were awaiting sentencing at the time of the report.

The part banks should really care about: “more vulnerable by design”

Here’s the detail that should make any ATM owner sit up a little straighter. U.S. Attorney Ryan A. Kriegshauser said “jackpotting bandits are sweeping the nation,” and that this group’s strategy was to target ATMs they believed were “by design more vulnerable to malware.”

That’s the uncomfortable truth: jackpotting crews don’t pick targets at random. They pick what they think will be easy—a machine model, setup, or location that gives them the best shot at getting hands-on access long enough to try an install.

And even though this crew walked away empty-handed, the method they attempted is the same playbook banks keep seeing—malware, physical access, and a short window to force the machine to cooperate.

How ATM jackpotting usually works (high-level, no “how-to” cheat sheet)

If you zoom out, ATM jackpotting isn’t magic. It’s criminals treating an ATM like what it really is: a specialized computer with a cash box attached.

The key idea: they’re not “hacking your account.” They’re trying to make the machine itself cough up cash.

The basic flow (what happens without the juicy step-by-step)

At a high level, jackpotting follows a pretty consistent pattern:

  1. Get access to the ATM’s internal computer.

This is the “hands-on” part. If attackers can physically reach the guts of the machine, their odds go way up.

  1. Install ATM malware on that internal computer.

Once malware is on the ATM, it can be set up to interact with the ATM’s own components—especially the cash dispenser.

  1. Send “dispense” commands using an input method the ATM will accept.

Reporting on jackpotting notes that criminals can control the malware using something as simple as an attached USB keyboard or even the ATM’s built-in PIN pad, then issue commands to the internal cash dispenser.

That’s the whole scam in three moves: access → install → command.

Malware families banks should recognize (seen in the wild)

“ATM malware” isn’t one thing. It’s a category with a history—and names that pop up again and again in incident reports.

Some of the better-known examples referenced in reporting include: ATMii, ATMitch, GreenDispenser, Alice, RIPPER, Skimer, SUCEFUL, and Ploutus.

You don’t need your branch team memorizing that list like trivia night. The point is simpler: this is a repeatable crime, with reusable tools.

Why old systems + weak physical access controls make this easier

Jackpotting tends to thrive when two things line up:

  • A machine that’s easier to tamper with physically (think: access panels, exposed ports, predictable layouts)
  • A tech stack that’s harder to keep locked down (older/unsupported operating systems and software don’t age like fine wine)

And once criminals can touch the internal computer, they can try the same general trick: plant malware and use a direct input path—USB keyboard or PIN pad—to tell the dispenser what to do.

This isn’t a one-off: the bigger wave (FBI warning, Ploutus, and organized crews)

If Section 2 made jackpotting sound “repeatable,” here’s the part that makes it feel urgent: it’s already been repeatable at scale.

The FBI’s 2025 warning: this got expensive fast

The FBI warned that criminals stole over $20 million during a surge of ATM malware / jackpotting incidents in 2025.

That number matters because it changes how you should think about risk. This isn’t petty crime. It’s organized theft with a playbook that’s paying out often enough to keep crews coming back.

Organized crews + one of the usual suspects: Ploutus

Federal cases and reporting have tied major U.S. activity to Tren de Aragua, a Venezuelan criminal organization, in a large ATM jackpotting scheme that deployed Ploutus malware to steal millions from ATMs across the United States.

Two takeaways for banks:

  • This is coordinated. When a scheme stretches “across the United States,” you’re not dealing with a lone opportunist.
  • It’s tool-driven. Crews reuse malware families (like Ploutus) because it’s efficient, not because it’s fancy.

The enforcement side is big too (because the footprint is big)

After that surge, reporting notes a wave of arrests connected to the Tren de Aragua-linked jackpotting activity.

In total, the Justice Department has charged 87 Tren de Aragua members, with maximum prison terms reported as ranging from 20 to 335 years each.

So when a small-town attempt hits the news, it’s not “random.” It’s a visible piece of a much larger pattern: ATM malware attacks, repeat crews, repeat tools, repeat targets.

Bank defenses that actually move the needle (practical, non-technical, and testable)

When prosecutors talk about crews picking machines that are “more vulnerable by design,” they’re basically describing a target list. Your job is to get off it.

U.S. Attorney Ryan A. Kriegshauser put it plainly: there is technology that can help thwart jackpotting, and banks should invest in updates.  The trick is turning that idea into a checklist you can actually run.

Hardening + hygiene (boring stuff that stops exciting crimes)

If attackers need hands-on time at the ATM, your best wins come from reducing what they can do during that window.

1) Rank your ATM fleet by risk

  • Flag models/configurations that have been common targets or are harder to update.
  • Prioritize locations where someone can loiter without being noticed (yes, criminals “shop” for that).

2) Patch like you mean it

  • Keep ATM software and security updates current so you’re not stuck defending yesterday’s tech with today’s threats.
  • Build a simple KPI: % of ATMs fully up to date, reviewed monthly.

3) Remove “easy entry” paths

This is less “cyber” and more “don’t give them a door.”

  • Tighten service-panel security and port access where possible.
  • Treat every exposed access point like it’s an invitation.

Control + response (because prevention isn’t perfect)

Even a well-maintained fleet can get tested. So you want fast detection and a no-drama response.

Physical access controls that hold up in real life

  • Restrict and audit who can open ATM cabinets and when.
  • Make keys/credentials trackable, not “shared drawer” items.
  • Use tamper-evident measures that get checked on a schedule (not “whenever someone remembers”).

Monitoring and alerts that catch jackpotting patterns

Attackers ultimately want the dispenser to do something weird—like dispense cash when it shouldn’t.

Set alerts for:

  • Cabinet door / panel open events outside service windows
  • Unusual dispenser behavior (unexpected dispense, repeated dispense attempts, abnormal sequences)
  • ATM out-of-service changes that happen right before suspicious activity

Incident response that feels like a fire drill, not a surprise party

Have a runbook that answers, in plain language:

  1. Who gets paged (and who’s backup)?
  2. Who can remotely disable the ATM or halt dispensing?
  3. Who pulls surveillance footage and when?
  4. Who talks to law enforcement and what evidence gets preserved?

If you can’t walk through those four steps in under five minutes, you don’t have a runbook yet—you’ve got a document.

Free number scan to see what info about you is exposed.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
View all
Data Breaches
August 29, 2026

Could Your Organization Be Exposed by the McKesson Healthcare Data Breach—What’s Actually Confirmed vs. Still Alleged?

Data Breaches
August 29, 2026

Were Your Details Exposed in Hasbro’s Data Breach—And What Should You Do Next?

Data Breaches
August 28, 2026

Could Your Carhartt Account Be in This 12.9M Data Breach Leak?