ATM 'Jackpotting' Crews Sentenced for Malware-Driven Heists
Several individuals have pleaded guilty and been sentenced for their roles in sophisticated ATM 'jackpotting' schemes across the United States. These operations, often linked to transnational criminal organizations, utilize advanced malware like **Ploutus** to force ATMs to dispense cash, resulting in millions of dollars in losses.
Five Venezuelan nationals have pleaded guilty to conspiracy to commit bank larceny, following accusations that they were part of a group dedicated to robbing ATMs using malware.
A Kansas federal court sentenced **Luis Alberto Velasquez-Artigas**, 27, to nine months in prison. The other four defendants β **Royder Adrian Figuera-Perez**, 29, **Javier Mejia, Jr**, 27, **Gabriel Alexjandro Corales-Garcia**, 33, and **Italo Lizandro Corrales-Carrillo**, 26 β are currently awaiting sentencing.
According to court documents, the group traveled from Indiana to Kansas in December 2025 with the intent to rob several ATMs in Wamego and Manhattan. Their method involved 'jackpotting' β a technique where criminals break into an ATM and install malware, compelling the machine to dispense all its cash.
Their attempts to install malware on ATMs in Wamego and Manhattan failed, triggering police alarms. Surveillance cameras captured the group, leading to their arrests days later.
U.S. Attorney **Ryan Kriegshauser** stated, "Jackpotting bandits are sweeping the nation. This particular groupβs strategy was to specifically target ATMs they thought were by design more vulnerable to malware." Kriegshauser urged companies to invest in new technologies designed to prevent such attacks.
**FBI** director **Kash Patel** reported that ATM jackpotting schemes have caused over $58 million in losses since 2021. The FBI has tracked more than 1,900 ATM jackpotting incidents since 2020, with over 700 occurring in 2025 alone, accounting for more than $20 million in losses.
## Ploutus Malware at the Core of Operations
This marks the latest series of federal guilty pleas related to ATM jackpotting. In a separate case, **Juan Manuel Gouveia-Aguilera**, 27, received an eight-year prison sentence from a federal judge in Omaha, Nebraska, on August 20. Prosecutors identified him as a member of a prominent gang that used **Ploutus** malware to steal millions from hundreds of ATMs.
Gouveia-Aguilera previously pleaded guilty to charges including bank fraud and fraud in connection with computers. In addition to his prison term, he faces five years of supervised release and must pay restitution to the affected banks. Prosecutors estimate Gouveia-Aguilera was responsible for over $3.5 million in ATM losses.
Criminals typically execute these attacks by either connecting a laptop directly to the ATMβs hard drive or by replacing the existing drive with an infected one pre-loaded with **Ploutus** malware.
**Oddry Arnoldo Cabrera Torrealba** and **Carlos Javier Padron** also recently received 6.5-year sentences for their involvement in similar jackpotting schemes. At least 119 individuals have been charged in connection with this broader operation, which allegedly targeted ATMs in 47 U.S. states and several other countries.
**Rick Sabatini**, HSI Kansas City Special Agent in Charge, commented, "Gouveia-Aguilera and his alleged co-conspirators thought they could hack American ATMs, drain financial institutions, and funnel money to a violent transnational criminal organization without consequence. They were wrong."
Assistant Attorney General **A. Tysen Duva** indicated that these ATM jackpotting schemes are intended to fund violent transnational criminal organizations, such as the Venezuelan gang **Tren de Aragua**. Federal prosecutors have actively sought to link the jackpotting attacks to this group. The initial indictment against Gouveia-Aguilera and dozens of others accused the group of creating the **Ploutus** malware.
**FBI** officials previously told Recorded Future News that they believe **Anibal Alexander Canelon Aguirre**, also named in the indictment alongside Gouveia-Aguilera, was the creator of the malware.
Experts and government agencies have issued warnings about variants of the **Ploutus** malware for nearly a decade. Google researchers have previously described it as "one of the most advanced ATM malware families" they have encountered.
First detected by **Symantec** in 2013, **Ploutus** has undergone several updates. Initially deployed against ATMs across Mexico in 2013, it enabled criminals to empty machines via an external keyboard or, innovatively, by sending an SMS message β a technique Google noted had not been seen before.
While multiple companies have tracked **Ploutus** for over a decade, none could definitively confirm Aguirre as the true developer or establish direct ties between the malware's development and **Tren de Aragua**.
**Ploutus** has been used to target machines from various vendors, including **Diebold Nixdorf** and **Kalignite Platform**. **Diebold Nixdorf** issued multiple alerts in 2017 and 2018 regarding malware variants used in thefts across Mexico and the U.S.