Listen to this Post

Introduction: When an ATM Becomes the Target
An ATM is designed to do one simple thing: give customers access to their money. But in recent years, criminals have discovered a dangerous way to turn these machines against the financial institutions that operate them. Instead of stealing cards, guessing PINs, or physically breaking into cash machines, sophisticated crews can attack the computer inside an ATM and force it to dispense cash on command.
This technique, commonly known as ATM jackpotting, has become an increasingly serious cybersecurity and physical-security threat. It combines malware, unauthorized physical access, social engineering, and carefully planned movements to transform a protected banking terminal into an automated cash dispenser for criminals.
The latest case highlights just how persistent the threat has become. Five Venezuelan nationals have pleaded guilty in the United States to participating in attempts to steal money from ATMs using malware. Their operations in Kansas ultimately failed, but surveillance footage, alarms, and law-enforcement investigations helped bring the alleged conspirators to justice.
The case also comes against the backdrop of a much larger wave of ATM jackpotting attacks across the United States, with federal authorities warning that criminals stole more than $20 million through these schemes during the previous year.
The important lesson is not simply that several criminals were arrested. It is that an ATM is no longer just a physical machine containing cash. It is a computer connected to a highly valuable financial process—and that computer must be defended accordingly.
Five Defendants Plead Guilty
Five Venezuelan nationals have pleaded guilty to one count of conspiracy to commit bank larceny in connection with ATM jackpotting attempts.
The defendants identified in the case are 27-year-old Luis Alberto Velasquez-Artigas, 29-year-old Royder Adrian Figuera-Perez, 27-year-old Javier Mejia Jr., 33-year-old Gabriel Alejandro Corales-Garcia, and 26-year-old Italo Lizandro Corrales-Carrillo.
Velasquez-Artigas has already been sentenced to nine months in prison. The remaining defendants were awaiting sentencing at the time described in the original report.
The guilty pleas bring a legal conclusion to one part of the investigation, but the broader threat remains far from over.
The Dangerous Idea Behind ATM Jackpotting
ATM jackpotting works by attacking the computer system that controls an automated teller machine rather than directly attacking a customer’s bank account.
A compromised ATM can potentially be manipulated into treating unauthorized commands as legitimate instructions. If attackers succeed in gaining control of the machine’s internal computer, they may attempt to communicate with the cash dispenser and instruct it to release banknotes.
That is why the term “jackpotting” is so appropriate. Criminals are effectively trying to make the ATM behave like a slot machine that pays out whenever they issue the right command.
Unlike traditional ATM theft, this approach can allow attackers to extract large quantities of cash without needing thousands of stolen payment cards or customer PINs.
Malware Has Become a Major Weapon
Over the years, researchers and law-enforcement agencies have identified numerous malware families associated with ATM jackpotting.
Examples mentioned in connection with these attacks include ATMii, ATMitch, GreenDispenser, Alice, RIPPER, Skimer, SUCEFUL, and Ploutus.
These malware families demonstrate how ATM attacks have evolved from crude physical theft into specialized cybercrime.
The
The technical details vary between malware families and ATM models, but the underlying concept is remarkably consistent: gain access to the machine’s computing environment, bypass its normal controls, and abuse its legitimate cash-dispensing functionality.
Physical Access Still Matters
One of the most interesting aspects of ATM jackpotting is that it sits directly between cybersecurity and physical security.
A criminal does not necessarily need to remotely compromise a bank’s entire network. In some scenarios, physical access to an ATM can provide an attacker with an opportunity to interact directly with the machine’s internal hardware.
Attackers have historically used devices such as USB keyboards or interacted with built-in ATM input mechanisms to deliver commands after compromising the system.
This makes physical security just as important as firewalls and endpoint protection.
A perfectly secured corporate network does not automatically protect an ATM that an attacker can physically manipulate.
The Kansas Attempts Failed
The five defendants were arrested in December 2025, after unsuccessful ATM jackpotting attempts in Wamego and Manhattan, Kansas.
The Wamego operation reportedly failed before the criminals could successfully install the malware.
More importantly, their activity triggered an alarm.
That alarm gave law enforcement an opportunity to respond, and the attackers did not return to the location.
The Manhattan attempt also failed to make the ATM dispense cash.
Both incidents were captured by surveillance cameras, creating valuable evidence that investigators could use to identify and eventually arrest the suspects.
Surveillance Became a Critical Defense
The Kansas incidents demonstrate why modern ATM security cannot rely entirely on software.
The criminals may have been attempting to exploit a technological weakness, but traditional security systems—including alarms and cameras—helped stop the operation.
This is a powerful reminder that cybersecurity is rarely about a single layer of defense.
An alarm can stop an intrusion that software fails to detect.
A camera can identify an attacker that an antivirus system never sees.
A bank employee can notice suspicious activity that an automated monitoring system misses.
The strongest security strategy combines all of these layers.
A Warning From Federal Authorities
U.S. Attorney Ryan A. Kriegshauser described ATM jackpotting criminals as a growing nationwide problem and emphasized that attackers deliberately search for ATMs they believe are more vulnerable to malware.
His warning also pointed toward an important defensive strategy: financial institutions need to invest in technologies and security updates capable of preventing jackpotting.
The message is straightforward.
ATM security cannot remain static while criminal techniques evolve.
Financial institutions have to continuously update operating systems, harden physical interfaces, monitor unusual behavior, restrict unauthorized devices, and ensure that ATM software cannot be easily manipulated.
The $20 Million Warning
The case becomes even more significant when viewed alongside a warning issued by the FBI in February.
According to the report, criminals stole more than $20 million during the previous year through a major increase in ATM jackpotting activity.
That figure illustrates why the threat deserves attention from financial institutions, law enforcement, cybersecurity professionals, and ATM manufacturers.
A single successful attack can potentially generate a significant financial loss in a very short period of time.
When criminal groups coordinate attacks against multiple ATMs, the damage can multiply rapidly.
The Tren de Aragua Connection
Federal investigations have also connected a major wave of ATM jackpotting activity to members of the Venezuelan criminal organization Tren de Aragua.
Authorities have alleged that members of the organization participated in large-scale ATM jackpotting operations involving Ploutus malware.
The use of a specialized malware family illustrates the increasingly professional nature of ATM crime.
This is not simply a matter of someone breaking open an ATM with a crowbar.
It can involve reconnaissance, malware, physical access, transportation, surveillance avoidance, cash collection, and coordination between multiple participants.
The more organized these operations become, the more important layered defenses become.
Dozens of Defendants Charged
The broader investigation has resulted in the Justice Department charging 87 alleged Tren de Aragua members in connection with criminal activity described in the case.
The defendants face potentially severe penalties, with maximum prison terms varying significantly depending on the charges.
These prosecutions also demonstrate that authorities are attempting to attack the criminal ecosystem rather than treating each ATM theft as an isolated incident.
That distinction matters.
When multiple attacks are connected to organized criminal networks, investigators can potentially identify common infrastructure, transportation patterns, money trails, accomplices, and repeat offenders.
Deportation After Conviction
The United States has also pursued immigration consequences in related ATM jackpotting cases.
In January, federal prosecutors in South Carolina announced that two Venezuelan nationals convicted in connection with jackpotting attacks would be deported after completing their sentences.
This reflects a broader approach in which criminal prosecution and immigration enforcement can intersect when foreign nationals are convicted of serious crimes.
Why ATM Jackpotting Is Different From Card Fraud
Traditional ATM fraud usually targets customers.
Criminals might steal payment cards, capture PINs, use skimmers, or obtain account credentials through phishing and malware.
Jackpotting takes a different path.
Instead of trying to withdraw a small amount from many customer accounts, criminals attempt to attack the ATM itself.
The victim therefore becomes the bank or ATM operator rather than an individual customer.
This changes the economics of the attack.
A successful jackpotting operation can potentially extract large quantities of cash from one physical location without compromising hundreds of individual bank accounts.
The ATM Is Essentially an Embedded Computer
One reason jackpotting remains possible is that modern ATMs are sophisticated computing platforms.
They contain operating systems, applications, network connections, peripheral devices, storage, authentication mechanisms, and specialized hardware.
The cash dispenser is simply one component of that larger system.
From a cybersecurity perspective, that means ATM manufacturers and financial institutions have to think about ATMs like highly specialized endpoints.
They require secure configurations, controlled software execution, patch management, application allowlisting, logging, physical tamper protection, and continuous monitoring.
Treating an ATM as “just a cash machine” is an increasingly dangerous mindset.
Deep Analysis: Understanding the Defensive Attack Surface
The First Layer: Physical Security
Financial institutions should begin with physical controls.
ATM cabinets, maintenance ports, USB interfaces, service panels, and internal components should be protected against unauthorized access.
Tamper detection should generate alerts when critical components are opened or manipulated.
Security cameras should cover ATM areas and provide sufficient visibility for investigators.
The Second Layer: Application Control
ATMs should run only authorized software.
Application allowlisting can help prevent unknown executables or unauthorized programs from running.
This is particularly important because jackpotting malware often attempts to operate within the ATM’s software environment.
The Third Layer: Device Control
Unauthorized USB devices should be restricted wherever operationally possible.
If a maintenance process requires external devices, banks should establish strict controls around who can use them, which devices are permitted, and when they can be connected.
The Fourth Layer: Network Isolation
ATM networks should be strongly segmented from ordinary corporate environments.
An attacker who compromises an ATM should not automatically gain a pathway into critical banking systems.
Network segmentation can reduce the potential blast radius of a successful intrusion.
The Fifth Layer: Monitoring
Security teams should monitor ATMs for unusual behavior.
Unexpected software changes, suspicious processes, unusual administrative activity, repeated errors, unexplained cash-dispensing events, and physical tampering should all trigger investigation.
Defensive Command Examples
For Linux-based ATM infrastructure or security monitoring systems, administrators can use defensive commands such as:
Review currently running processes
ps aux
Review listening network services
ss -tulpn
Check recent authentication activity
last
Review system authentication logs
journalctl --since "24 hours ago" | grep -Ei "auth|login|sudo"
Find recently modified executable files
find /usr /opt -type f -perm /111 -mtime -1 2>/dev/null
Generate SHA-256 hashes for approved files
sha256sum /path/to/application
These commands are examples for authorized defensive investigation. Actual ATM environments are highly specialized, and administrators should follow the platform manufacturer’s security guidance rather than blindly applying generic Linux procedures.
Windows-Based Monitoring
Where ATM infrastructure relies on Windows-based systems, defenders can use PowerShell to investigate running processes and services:
List running processes
Get-Process
List running services
Get-Service | Where-Object {$_.Status -eq "Running"}
Review recent Windows events
Get-WinEvent -LogName System -MaxEvents 100
Review security events
Get-WinEvent -LogName Security -MaxEvents 100
The goal is not simply to collect logs.
The goal is to establish a baseline and identify behavior that does not belong.
Why Legacy Systems Create Risk
Many specialized financial systems operate for years because replacing them is expensive and operationally difficult.
That creates an uncomfortable security problem.
A machine may still be functioning perfectly from a business perspective while running software that is increasingly difficult to secure.
Legacy operating systems, outdated applications, unsupported drivers, weak administrative controls, and obsolete interfaces can create opportunities for attackers.
This is one reason ATM modernization should be considered a security investment rather than merely an infrastructure upgrade.
Patch Management Is Not Optional
Security updates can address vulnerabilities that criminals may otherwise exploit.
But patching an ATM fleet is more complicated than patching ordinary office computers.
Banks must consider hardware compatibility, transaction availability, vendor certification, uptime requirements, and regulatory obligations.
Nevertheless, complexity cannot become an excuse for permanent stagnation.
Institutions need a structured process for testing and deploying security updates across ATM fleets.
The Human Element Remains Important
Technology alone cannot eliminate jackpotting.
Employees responsible for ATM maintenance need training to recognize suspicious behavior.
Physical access procedures must be documented.
Service credentials should be tightly controlled.
Maintenance sessions should be logged.
Third-party technicians should be authenticated and monitored.
An attacker who obtains legitimate maintenance credentials may be able to bypass defenses that would stop an ordinary intruder.
Credentials Can Become a Weak Link
One of the most important lessons from modern cybersecurity is that valid credentials can be just as dangerous as malware.
If criminals acquire legitimate credentials, defenders may struggle to distinguish malicious activity from authorized maintenance.
Financial institutions should therefore implement strong authentication, privileged-access management, credential rotation, least-privilege principles, and detailed auditing.
Administrative accounts should never have broader permissions than necessary.
Jackpotting Is Also an Intelligence Problem
Stopping these attacks requires more than protecting individual ATMs.
Banks need visibility across their entire ATM fleet.
If suspicious activity appears at one machine, security teams should be able to determine whether similar activity is occurring elsewhere.
Centralized logging can help identify patterns.
Threat intelligence can help identify known ATM malware.
Physical security teams can correlate camera footage with cybersecurity alerts.
The combination of these signals can reveal attacks much earlier.
Criminals Look for Weak Machines
The statement that attackers deliberately seek vulnerable ATMs is particularly important.
Cybercriminals do not necessarily need to compromise the strongest target.
They only need to find a weak one.
If an ATM fleet contains thousands of machines, a small number of poorly configured systems could become attractive targets.
That creates a fleet-wide security challenge.
The weakest ATM may effectively become the entry point for an expensive incident.
The Economics Favor Automation
Criminal organizations are constantly looking for ways to make theft more scalable.
ATM jackpotting fits that model.
Once a group understands a particular ATM platform, the same knowledge may potentially be applied to other machines using similar configurations.
Specialized malware can also make the process more repeatable.
That is why a successful jackpotting campaign should be treated as a potential indicator of a broader threat rather than an isolated event.
Banks Need More Than Antivirus
Traditional antivirus software has a role, but it should not be the only defense.
Specialized ATM environments require multiple controls working together.
These can include application allowlisting, secure boot, endpoint monitoring, hardware tamper detection, network segmentation, strong authentication, centralized logging, physical surveillance, and behavioral monitoring.
A criminal should have to defeat several independent security mechanisms rather than one.
The Importance of Secure Boot
Secure Boot and related platform-integrity mechanisms can help prevent unauthorized software from executing during the system startup process.
When properly implemented, they make it harder for an attacker to replace critical system components with malicious versions.
The effectiveness of such controls depends heavily on configuration and key management.
A security feature that exists only on paper does not provide meaningful protection.
Cash Dispensing Should Be Monitored
Banks should pay particular attention to unusual cash-dispensing behavior.
A machine that suddenly begins dispensing large quantities of cash outside normal customer patterns should be treated as a high-priority security event.
Behavioral detection can potentially identify suspicious activity faster than traditional signature-based malware detection.
This is especially important because attackers may modify malware or use previously unknown variants.
Physical and Digital Evidence Must Work Together
The Kansas case demonstrates the value of combining cybersecurity evidence with physical evidence.
Digital logs can reveal what happened inside a machine.
Cameras can show who was physically present.
Alarm systems can establish when suspicious activity occurred.
Access records can show which personnel were authorized to interact with the ATM.
Together, these sources create a much stronger investigative picture.
The Bigger Cybersecurity Lesson
ATM jackpotting is a reminder that cybersecurity increasingly extends into the physical world.
The same principles that protect servers and cloud infrastructure also matter for machines sitting on a street corner.
Every connected device can become part of an attack surface.
Every outdated operating system can become a liability.
Every unnecessary service can increase risk.
And every poorly protected physical interface can give an attacker an opportunity to cross the boundary between the digital and physical worlds.
What Undercode Say:
1. ATM Jackpotting Is a Hybrid Threat
ATM jackpotting is particularly dangerous because it combines cybercrime with physical crime.
2. The ATM Is the Endpoint
Banks should treat every ATM as a specialized endpoint requiring continuous security monitoring.
3. Physical Access Changes Everything
A criminal standing directly in front of a machine has opportunities that a remote attacker may not have.
4. Malware Makes Theft Scalable
Specialized malware can turn a complicated physical robbery into a repeatable technical operation.
5. Criminals Are Becoming More Specialized
The existence of dedicated ATM malware demonstrates the professionalization of financial cybercrime.
6. Legacy Technology Is a Risk
Older systems may continue working perfectly while becoming increasingly difficult to secure.
7. Security Updates Matter
Vendor-supported security updates should be treated as part of the ATM’s lifecycle rather than optional improvements.
8. Network Isolation Is Critical
An ATM should never have unnecessary access to sensitive corporate systems.
9. A Compromised ATM Should Stay Contained
Segmentation limits the damage if an individual machine is compromised.
10. Physical Security Is Cybersecurity
Locks, alarms, cameras, and tamper sensors can prevent digital attacks from becoming physical theft.
11. Cameras Remain Extremely Valuable
The Kansas incidents show that old-fashioned surveillance can complement sophisticated cybersecurity.
12. Alarms Can Stop the Attack Early
A triggered alarm can prevent attackers from completing the malware installation process.
13. Banks Need Centralized Visibility
Security teams should be able to monitor large ATM fleets from a central platform.
14. One Weak ATM Can Attract Criminals
Attackers often search for the easiest target rather than the most valuable one.
15. Fleet Security Must Be Consistent
Security standards should be applied across every ATM rather than only high-value locations.
16. Credentials Deserve Special Protection
Legitimate maintenance credentials can become extremely powerful weapons if stolen.
17. Least Privilege Should Apply Everywhere
Administrative access should be limited to precisely what technicians need.
18. Logging Should Be Comprehensive
Banks need enough telemetry to reconstruct suspicious activity after an incident.
19. Behavioral Detection Is Becoming More Important
Security teams cannot depend exclusively on known malware signatures.
20. Attackers Can Change Their Malware
New variants may evade traditional detection systems.
21. Hardware Security Matters
Secure hardware configurations can prevent some classes of unauthorized modification.
22. Secure Boot Can Strengthen Trust
The system should verify critical components before allowing them to execute.
23. USB Ports Should Be Controlled
External interfaces can become dangerous when physical access is not properly restricted.
24. Maintenance Needs Strong Governance
Every maintenance session should have a clear owner, authorization, and audit trail.
25. Third Parties Increase Complexity
Banks must also consider the security practices of vendors and contractors maintaining ATM fleets.
26. Jackpotting Is an Intelligence Challenge
Detecting one attack can provide clues about attacks against other machines.
27. Threat Intelligence Can Accelerate Defense
Knowledge about ATM malware families can help defenders identify suspicious behavior faster.
28. Law Enforcement Benefits From Better Telemetry
Detailed records can help investigators connect separate incidents to the same criminal network.
29. Criminal Networks Create Economies of Scale
Once attackers understand a particular ATM platform, that knowledge may potentially be reused.
- Financial Loss Is Only Part of the Damage
Banks can also face operational disruption, investigation costs, reputational damage, and customer concern.
31. ATM Security Should Be Risk-Based
Not every ATM faces identical threats, but every machine should meet a strong baseline.
32. Geographic Patterns Matter
Repeated attacks in particular areas can help investigators identify organized activity.
33. Timing Can Reveal Coordination
Multiple incidents occurring within a narrow period may indicate a coordinated campaign.
34. Security Teams Should Practice Incident Response
Banks need predefined procedures for isolating compromised ATMs and preserving evidence.
35. Detection Speed Matters
The faster suspicious cash dispensing is detected, the less money criminals may be able to steal.
36. Prevention Is Cheaper Than Recovery
Replacing compromised equipment and investigating theft is usually more expensive than maintaining adequate security controls.
37. Cybersecurity and Physical Security Must Collaborate
Neither department can fully solve ATM jackpotting independently.
38. ATM Manufacturers Also Carry Responsibility
Security must be designed into the hardware and software rather than added only after attacks occur.
39. The Threat Will Continue Evolving
As banks improve their defenses, criminals will search for new weaknesses and new ways to bypass controls.
- The Real Lesson Is Bigger Than ATMs
The same principle applies to payment terminals, smart kiosks, industrial systems, medical devices, and other connected machines: when a computer controls something valuable in the physical world, cybersecurity becomes physical security too.
✅ Five Defendants Pleaded Guilty
The supplied article identifies five Venezuelan nationals and states that each pleaded guilty to one count of conspiracy to commit bank larceny.
✅ The Kansas Attempts Were Unsuccessful
The source states that the Wamego and Manhattan ATM attacks failed to produce the intended cash theft and that both incidents were captured by surveillance systems.
✅ ATM Jackpotting Uses Malware
The description of jackpotting as an attack involving malware designed to manipulate an ATM’s cash-dispensing capabilities is consistent with the central technical explanation provided in the source.
✅ Multiple ATM Malware Families Have Been Reported
The article names ATMii, ATMitch, GreenDispenser, Alice, RIPPER, Skimer, SUCEFUL, and Ploutus as malware associated with ATM jackpotting activity.
⚠️ The $20 Million Figure Requires Context
The supplied article attributes the more-than-$20-million figure to an FBI warning concerning the previous year’s ATM jackpotting activity. Because the figure is time-dependent, it should be presented with its original reporting date and source when published independently.
⚠️ Criminal-Organization Attribution Should Be Carefully Worded
The supplied report links a major ATM jackpotting scheme to members of Tren de Aragua. Such allegations should be attributed to U.S. authorities rather than presented as proof that every person associated with the organization participated in ATM attacks.
⚠️ Sentencing Details Can Change
Velasquez-Artigas is described as having received a nine-month sentence, while the other defendants were awaiting sentencing in the source. Final sentencing information should therefore be updated if the article is republished later.
Prediction
(+1) ATM Security Will Become More Layered
Financial institutions are likely to increase investment in ATM hardening, application allowlisting, secure boot, tamper detection, network segmentation, and centralized behavioral monitoring as jackpotting becomes more sophisticated.
The future of ATM defense will probably not depend on one magical security product.
Instead, banks will build several defensive layers around every machine.
An attacker may still find a vulnerability, but successfully converting that vulnerability into cash theft will become increasingly difficult.
(+1) AI Will Improve ATM Threat Detection
Artificial intelligence and behavioral analytics could increasingly help financial institutions identify unusual dispensing patterns, suspicious maintenance behavior, anomalous software activity, and coordinated attacks across large ATM fleets.
The strongest use of AI here will not necessarily be replacing security teams.
It will be helping them recognize weak signals across thousands of machines that would be nearly impossible to correlate manually.
(+1) Physical Security Will Become More Cyber-Aware
ATM surveillance systems, tamper sensors, access-control systems, and cybersecurity platforms are likely to become more tightly integrated.
An unusual physical event could automatically trigger a cybersecurity investigation.
Likewise, suspicious software activity could cause security personnel to inspect the physical machine.
That convergence could make jackpotting significantly harder to execute unnoticed.
(-1) Criminals Will Search for Older ATMs
As modern machines become harder to compromise, criminals may increasingly concentrate their efforts on older, poorly maintained, or inadequately monitored ATM fleets.
This could create an uneven security landscape in which outdated machines become preferred targets.
(+1) Jackpotting Will Remain a Major Financial-Crime Concern
The arrest of individual attackers does not eliminate the underlying economics.
ATMs continue to hold physical cash, making them attractive targets.
As long as criminals can find machines with exploitable weaknesses, jackpotting will remain an area of concern for banks, ATM manufacturers, law enforcement, and cybersecurity researchers.
The Kansas case ultimately ended without the criminals successfully emptying the targeted ATMs. But the larger warning is impossible to ignore: the next ATM attack may not fail.
The financial industry therefore has a choice—wait for criminals to discover the next weak machine, or assume that every ATM is already being tested by someone looking for a way in. The institutions that choose the second approach will be far better prepared for the future of ATM security.
Condense the repetitive analysis section
Add a stronger reader-focused conclusion
▶️ Related Video (82% Match):
🕵️📝Let’s dive deep and fact‑check.
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
References:
Reported By: www.bleepingcomputer.com
Extra Source Hub (Possible Sources for article):
https://www.digitaltrends.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube




