US Cracks Down on Venezuelan Gang in Multi-Million Dollar ATM Jackpotting Scheme

Listen to this Post

Featured Image
The U.S. Department of Justice (DoJ) has unveiled one of the most significant ATM hacking crackdowns in recent years, indicting 54 individuals linked to a large-scale jackpotting conspiracy. This sophisticated operation involved deploying the Ploutus malware to manipulate ATMs across the United States, forcing them to dispense cash. The indictments allege that the perpetrators are connected to Tren de Aragua (TdA), a notorious Venezuelan gang officially designated as a Foreign Terrorist Organization by the U.S. State Department.

Massive Indictments and Criminal Charges

On December 9, 2025, the Justice Department charged 22 individuals with bank fraud, burglary, and money laundering, claiming these actors exploited ATM jackpotting to siphon millions of dollars. A separate indictment returned on October 21, 2025, added 32 more defendants, bringing counts that included conspiracy to commit bank fraud, computer fraud, multiple instances of bank burglary, and computer damage. If convicted, those involved could face prison sentences ranging from 20 to 335 years, highlighting the severity of their crimes.

The Mechanics of the Jackpotting Operation

TdA allegedly recruited a network of operatives to conduct reconnaissance on ATMs, assessing security measures before physically accessing the machines. The malware, Ploutus, was either installed via preloaded hard drives or removable thumb drives. Once deployed, it could take control of the ATM’s cash dispensing module, allowing money mules to withdraw significant sums rapidly. Ploutus also included features to delete evidence, masking its presence and misleading bank personnel.

Historical Context of Ploutus

First identified in Mexico in 2013, Ploutus exploited weaknesses in Windows XP-based ATMs, allowing cash withdrawals through SMS commands. Reports by Symantec in 2014 and FireEye in 2017 highlighted its ability to manipulate Diebold ATMs across various Windows systems. The malware required a combination of physical access, a master key, and an activation code, making the operation highly organized and dependent on insider-like coordination.

Financial and Security Impact

Since 2021, U.S. banks have reported 1,529 jackpotting incidents, with losses totaling approximately $40.73 million by August 2025. According to U.S. Attorney Lesley Woods, much of the stolen cash allegedly funded TdA’s broader criminal and terrorist activities. Acting Assistant Attorney General Matthew R. Galeotti emphasized the methodical approach of the gang, noting how surveillance, burglary, and malware installation were strategically used to launder money and support illicit operations.

What Undercode Say:

The TdA ATM jackpotting case exemplifies how cybercrime and organized crime increasingly intersect. Ploutus is not just malware—it is a sophisticated tool enabling transnational crime with tangible real-world impacts. The methodology of TdA highlights a chilling evolution of cyber-enabled theft: from opportunistic hacking to meticulously orchestrated financial crimes with clear links to terrorism and human trafficking.

The involvement of a Foreign Terrorist Organization underscores how cyber operations can be leveraged for broader criminal enterprises, including funding violent activities abroad. The recruitment of multiple individuals for reconnaissance, physical ATM access, and malware deployment demonstrates an operational model reminiscent of corporate project management, albeit with illegal objectives. This case also stresses the vulnerability of aging banking infrastructure, particularly ATMs running outdated Windows systems. The fact that Ploutus has persisted for over a decade shows how legacy systems remain high-value targets for criminals worldwide.

Moreover, the strategic distribution of stolen funds among gang members signals a highly organized financial network, paralleling legitimate money laundering techniques but without oversight. The indictment sheds light on the international reach of TdA, implying that U.S. law enforcement may face persistent challenges in curbing cross-border cybercrime. This case also serves as a wake-up call for banks and financial institutions to prioritize cybersecurity investments, employee training, and regular hardware updates.

The human factor cannot be overlooked: success depended on individuals willing to participate in high-risk, coordinated operations. Ploutus’s capability to erase digital traces suggests that traditional forensic methods are insufficient without advanced cyber intelligence and collaboration with technology experts. Law enforcement agencies will likely need to expand their technical capacities and international cooperation to counter these hybrid threats.

The scale of the losses—over $40 million in four years—is staggering, but it may only represent the tip of the iceberg. Such schemes often go unreported due to reputational damage or underestimation of the threat. Going forward, monitoring and predicting similar attacks will require an integration of cybersecurity, financial intelligence, and criminal profiling, merging digital and physical security disciplines.

Finally, this indictment highlights the blurred lines between cybercrime and traditional criminal enterprises. As gangs like TdA evolve, they increasingly exploit technological vulnerabilities to fund broader illicit networks. This trend signals an urgent need for cross-sector collaboration, not only among banks but also between international law enforcement and cybersecurity agencies, to stay ahead of sophisticated financial criminal networks.

Fact Checker Results:

✅ TdA is officially designated as a Foreign Terrorist Organization by the U.S. State Department.
✅ Ploutus malware has a documented history of ATM exploitation since 2013.
❌ Losses from jackpotting may be underreported; $40.73 million is a confirmed minimum.

Prediction:

💰 ATM jackpotting schemes will continue evolving, targeting vulnerable financial systems with more advanced malware.
🌐 Transnational gangs like TdA are likely to expand cyber-financial operations to fund illicit activities abroad.
🛡 Banks must accelerate cybersecurity modernization and monitoring to prevent future large-scale ATM thefts.

🕵️‍📝✔️Let’s dive deep and fact‑check.

References:

Reported By: thehackernews.com
Extra Source Hub (Possible Sources for article):
https://www.quora.com/topic/Technology
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2
Bing

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon