Listen to this Post

In a sweeping cybercrime case that has reverberated through financial and law-enforcement circles, two Venezuelan nationals have been convicted in the United States for deploying sophisticated malware to drain cash from bank ATMs across the southeastern states. Prosecutors say the pair used a long-standing threat tool to bypass security safeguards and force machines to spit out bills — leaving banks on high alert and triggering a much broader investigation involving dozens of alleged accomplices connected to Venezuela’s notorious criminal syndicate Tren de Aragua.
SecurityWeek
+1
the Original
Luz Granados (34) and Johan Gonzalez-Jimenez (40), both Venezuelan nationals, were convicted in federal court for their roles in an “ATM jackpotting” scheme that siphoned cash from older-model automatic teller machines in South Carolina, Georgia, North Carolina, and Virginia.
https://www.wistv.com
The pair approached unattended ATMs at night, removed their outer shells, and connected laptops to install malware that forced the machines to dispense all available cash, taking money directly from bank reserves rather than customer accounts.
BleepingComputer
Granados was sentenced to time served and ordered to pay $126,340 in restitution, while Gonzalez-Jimenez received 18 months in prison and must pay $285,100 before facing deportation. Both are slated for removal from the U.S. after completing their sentences.
SecurityWeek
The malware used in the attacks is identified as Ploutus, a decades-old but still potent ATM attack tool that authorities say has re-emerged in recent thefts.
SecurityWeek
These convictions follow a broader wave of indictments: a federal grand jury in Nebraska recently returned charges against 54 individuals allegedly tied to a similar multi-state jackpotting operation that used the same malware and targeted dozens of machines nationwide.
Newsmax
Prosecutors have also linked the network of defendants to the Venezuelan transnational gang Tren de Aragua, which U.S. officials designated as a Foreign Terrorist Organization and allege uses proceeds from such schemes to fund criminal and violent activities.
Wikipedia
What Undercode Says: Insight and Analysis
The Growing ATM Jackpotting Phenomenon
ATM jackpotting isn’t a simple break-in and theft like traditional bank robbing — it blends physical access with malware sophistication. Attackers must physically remove ATM components, plug in external devices, and deploy malware like Ploutus to assume control of cash dispensers. While Ploutus was first seen more than a decade ago, its resurgence shows that legacy malware families remain active threats when combined with opportunistic criminal networks.
uaf.gob.ni
Why This Case Matters
The convictions of Granados and Gonzalez-Jimenez are significant not just because of the money lost, but because they reveal how organized crime is increasingly exploiting cyber-physical attack vectors. By targeting cash infrastructure rather than customer accounts, the attackers avoid many traditional security layers. Banks often harden networks and encrypt data, but the physical layer — the ATM hardware — remains an attractive weak point if operators fail to secure access points.
The Register
Moreover, the alleged involvement of Tren de Aragua elevates the stakes. What might once have been seen as opportunistic theft is now framed by authorities as part of a larger criminal enterprise that allegedly funnels illicit proceeds into broader illegal activities. With over 200 suspected members of this network arrested across the U.S. in 2025 alone, Tren de Aragua’s reach is under intense federal scrutiny.
infobae
Law Enforcement and Legal Strategies
The sentences in this case — especially the deportation orders — signal a dual approach by U.S. authorities: prosecute the immediate crimes and disrupt future activity by removing noncitizens involved in sophisticated financial schemes. The restitution orders also reflect an effort to hold perpetrators financially accountable, though real recovery of stolen funds is always challenging in cybercrime cases.
https://www.wistv.com
In the broader crackdown, federal indictments tied to ATM malware extend beyond simple theft charges to include money laundering, bank fraud, and even providing material support to criminal and terrorist organizations. Prosecutors are leveraging multi-state task forces to weave together disparate incidents, forcing courts to grapple with complex cybercrime linked to transnational networks.
Newsmax
Implications for Banks and Security Teams
Financial institutions must treat ATM jackpotting as a persistent threat. Beyond standard network defenses, physical security — tamper-resistant casings, surveillance, intrusion detection — is a frontline defense against jackpotted machines. Integrating real-time monitoring with anomaly detection tools can help spot unusual commands or unexpected cash dispensation orders that betray malware exploitation.
uaf.gob.ni
Collaboration with law enforcement is also critical. Sharing threat intelligence, incident patterns, and malware signatures can accelerate defensive updates and help law enforcement build robust cases against perpetrators. Banks that silo their information slow down responses and leave gaps for attackers to exploit.
show.it
Fact Checker Results
• Verified: Two Venezuelan nationals were convicted of using malware to force ATMs to dispense cash and are slated for deportation.
SecurityWeek
• Verified: The malware used was Ploutus, a known ATM jackpotting tool with a long history.
SecurityWeek
• Contextual Note: While authorities allege Tren de Aragua involvement, some experts dispute definitive linkage between the Venezuelan government and the gang’s operations.
Wikipedia
Prediction
With the spotlight on ATM jackpotting and organized cybercrime, we’re likely to see expanded security standards for ATM manufacturers and operators, potentially including mandatory tamper sensors and encrypted hardware modules. Financial regulators may push guidelines requiring more rigorous physical and logical defenses, while law enforcement continues international cooperation to disrupt transnational cybercrime networks like Tren de Aragua. Expect further indictments and preventive measures as criminal syndicates adapt and authorities respond with deeper surveillance and cross-agency data sharing. Continuous investment in AI-driven threat detection will become a norm, aiming to catch malware-driven attacks before they exploit hardware vulnerabilities.
🕵️📝✔️Let’s dive deep and fact‑check.
References:
Reported By: x.com
Extra Source Hub (Possible Sources for article):
https://www.quora.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
Bing
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon




