GBHackers

Five Plead Guilty to Using ATM Jackpotting Malware in Cash Theft Scheme


Five Venezuelan nationals have pleaded guilty in a federal case involving attempts to deploy ATM jackpotting malware against cash machines in Kansas. This case highlights a growing cyber-physical threat targeting financial institutions across the United States.

The case arose from an FBI investigation into an alleged scheme to force automated teller machines (ATMs) to dispense cash without legitimate customer transactions.

The defendants, Luis Alberto Velasquez-Artigas, 27; Royder Adrian Figuera-Perez, 29; Javier Mejia Jr., 27; Gabriel Alexandro Corales-Garcia, 33; and Italo Lizandro Corrales-Carrillo, 26, each pleaded guilty to one count of conspiracy to commit bank larceny.

Five Plead Guilty to Using ATM Jackpotting Malware

According to court documents, the group traveled from Indiana to Kansas in December 2025 and targeted ATMs in Wamego and Manhattan. Their alleged operation involved physically installing malware on the machines before remotely sending a command intended to trigger the cash-dispensing mechanism.

The conspirators initially attempted to compromise an ATM in Wamego; however, they were unable to install the malware successfully. Their activity triggered the ATM’s alarm system, prompting a law enforcement response and preventing them from completing the attack.

A second attempt in Manhattan also failed when the ATM did not dispense money as intended. Surveillance cameras captured both theft attempts, allowing investigators to identify the suspects. Authorities arrested the group several days later.

Velasquez-Artigas has been sentenced to nine months in prison, while the other four defendants are awaiting sentencing. The case was investigated by the FBI and prosecuted by Assistant U.S. Attorney Jared Maag.

ATM jackpotting is a cyber-enabled cash-theft technique in which attackers manipulate an ATM’s software or hardware to cause the machine to dispense large amounts of cash. Unlike conventional ATM fraud, such as card skimming or credential theft, jackpotting directly targets the machine’s cash-dispensing controls.

U.S. Attorney Ryan A. Kriegshauser noted that criminals are increasingly selecting ATM models they believe are more vulnerable to malware-based attacks.

He urged banks and financial institutions to implement technology and security updates designed to prevent unauthorized software installation and block manipulation of dispensing functions.

The FBI reported in February 2026 that ATM jackpotting activity has increased nationwide. Since 2020, authorities have recorded approximately 1,900 incidents, with more than 700 occurring in 2025 alone, resulting in losses exceeding $20 million.

Financial institutions can reduce exposure to jackpotting by strengthening both the physical and software layers of their ATM infrastructure. Key controls include restricting access to internal ATM ports, deploying application allowlisting, using signed software and firmware, monitoring for unauthorized hardware changes, and ensuring machines receive vendor security updates.

Banks should also configure real-time alerts for unusual cash-dispensing events, repeated failed service attempts, alarm activations, and unauthorized access to ATM cabinets. Surveillance coverage and rapid coordination with local law enforcement are essential, especially for remote or low-traffic ATM locations.

This Kansas case underscores that jackpotting attacks depend on a combination of physical access, malware deployment, and remote control, making layered ATM security critical to preventing cash theft before a machine can be manipulated.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC



Source link