Security1 distinct publisher3 min readPublished
Prosecutors in Kansas say the group crossed state lines to reach ATMs it believed were architecturally softer, which makes the machine on the street the control that mattered. The FBI counts 700 such incidents in 2025.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The mechanism sits inside the cabinet. Court records in the Ploutus cases describe operators cabling a laptop to the ATM's hard drive, or pulling the drive and inserting one already loaded with the malware [11]. Everything after that is a dispense command.
The crew chose targets by model, not by proximity. U.S. Attorney Ryan Kriegshauser said this group specifically targeted ATMs it thought were by design more vulnerable to malware [5], and the December 2025 run fits that: the men drove from Indiana to Kansas to reach machines in Wamego and Manhattan [3]. The driving was overhead against a target list defined by model. Kriegshauser also said technology now exists that can stop jackpotting, and urged companies to invest in it [6].
In Kansas the crew got nothing. Both installs failed and set off police alarms, surveillance cameras caught the group, and arrests followed days later [4]. The alarms went off, but only after the attempt was already underway.
Volume is where the travelling business model shows. The FBI has tracked more than 1,900 jackpotting incidents since 2020, of which more than 700 fell in 2025 and involved over $20m in losses [8]. That is roughly 37% of the six-year incident count inside one year [16]. FBI director Kash Patel put cumulative losses above $58m since 2021 [7], so 2025 carried about a third of the money [17]. Divide $20m by 700 and the average successful hit is near $28,600 [18], a per-machine figure a fleet owner can hold against a retrofit quote.
Sentences so far track physical outcomes rather than ambition. Velasquez-Artigas, 27, received nine months for a run that emptied no machines, while his four co-defendants await sentencing [2]. Juan Manuel Gouveia-Aguilera, tied by prosecutors to more than $3.5m in ATM losses, was sentenced in Omaha on August 20 to eight years plus five years of supervised release and restitution [9], one defendant accounting for about 6% of the national loss total [19]. Oddry Arnoldo Cabrera Torrealba and Carlos Javier Padron drew 6.5 years each, at least 119 people have been charged, and the group allegedly hit ATMs in 47 states and several other countries [10].
The tooling is older than this network. Symantec detected Ploutus in 2013 against ATMs in Mexico, where operators emptied machines using an attached external keyboard or an SMS message, and Google has called it one of the most advanced ATM malware families it has seen [15]. Prosecutors say the proceeds funded violent transnational groups including Tren de Aragua, and that this group created Ploutus [12]. FBI officials told Recorded Future News they believe Anibal Alexander Canelon Aguirre wrote it [13], but companies that have tracked the family for more than a decade told the same outlet they could not confirm that [14]. The guilty pleas remove the drivers who executed these attacks, but the malware code and the target list of vulnerable ATM models remain in use.
Ranked by verification strength, evidence, and original report placement.
U.S. Attorney Ryan Kriegshauser said Monday that jackpotting bandits are sweeping the nation and that this group's strategy was to specifically target ATMs they thought were by design more vulnerable to malware.
Five Venezuelan nationals pleaded guilty to conspiracy to commit bank larceny after prosecutors accused them of being part of a group dedicated to robbing ATMs using malware.
A Kansas federal court sentenced Luis Alberto Velasquez-Artigas, 27, to nine months in prison; the other four defendants, Royder Adrian Figuera-Perez, 29, Javier Mejia Jr, 27, Gabriel Alexjandro Corales-Garcia, 33, and Italo Lizandro Corrales-Carrillo, 26, are awaiting sentencing.
According to court documents, the men drove from Indiana to Kansas in December 2025 to rob several ATMs in Wamego and Manhattan through jackpotting, in which criminals break into an ATM and install malware that lets them empty it.
Both attempted malware installations in Wamego and Manhattan failed and triggered police alarms; the group was caught on surveillance cameras and all were arrested days later.
Kriegshauser said there is now technology that can help stop jackpotting attacks and urged companies to invest in it as soon as possible.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 31, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
product
A dozen states, no marquee targets: the water hacks show where the attack surface actually is1 distinct publisher
security
Congress asks GAO to price CISA's missing third, before the next 900 cuts land1 distinct publisher
product
The UK plant that went dark for four days was too small to have to tell anyone1 distinct publisher
security
CISA finally counts the water intrusions: 100-plus exposed systems behind cellular modems2 distinct publishers
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Court record solid, target-selection claim bare
The case spine here is documentary — pleas, a sentence, court filings on the December drive from Indiana — and that part holds. The national numbers do not sit on the same footing: $58 million comes from an FBI director's statement and the 1,900/700 tallies from the Bureau itself, with no methodology attached. And the assertion this story is built around, that the crew hunted for ATMs weaker by design, is one line of a prosecutor's press remarks with no model, vendor or flaw behind it, in a case where both installations failed.
The technique is in wide, counted use
Read as prevalence rather than product uptake, this is unusually well quantified for a crime story: more than 1,900 incidents tracked since 2020, over 700 last year, 119 people charged, machines hit in 47 states and abroad. The Kansas crew is a footnote inside that volume — two failed attempts — while the Omaha defendant alone accounts for roughly 6% of the money the FBI attributes to the entire scheme. Ploutus has been operating against production ATM fleets since 2013 and is still the tool of choice.
Podium language outruns the forensics
"Jackpotting bandits are sweeping the nation" is doing more work than the Kansas file supports, where two installs failed and alarms went off. Same pattern one level up: the indictment credits this group with creating Ploutus and a senior Justice official routes the proceeds to Tren de Aragua, yet the malware's long-time trackers would back neither claim. The overstatement is the government's, not the reporting's — The Record prints the skepticism in the same piece, which is why this lands as a modest gap rather than a wide one.
Announcers with something to announce
Nearly every voice in this story is prosecuting the case it describes: a U.S. Attorney, a Justice Department official, the FBI director, an HSI agent in charge — several speaking while four defendants still await sentencing. The Tren de Aragua thread carries obvious political value beyond the ATM losses. And note what the U.S. Attorney does next: he tells companies to buy anti-jackpotting technology immediately without naming it, which converts a criminal case into a procurement push nobody in the piece is asked to justify.
One newsroom, floored by court filings
Confidence sits mid-range for a specific reason: the underlying facts are the kind that end up in a docket and are hard to get wrong, but there is no second account anywhere in our coverage to test the FBI's arithmetic or the prosecutor's framing. The reporter's own decade of Ploutus sourcing raises it; the absence of any operator, bank or vendor voice, and of any detail on what the targeted machines actually were, keeps it from going higher.