Five Venezuelan citizens have admitted to conspiracy to commit bank larceny after attempting to use sophisticated malware to empty ATMs across Kansas. The arrests highlight a growing trend of 'jackpotting' attacks targeting vulnerable financial infrastructure.
- Five Venezuelan nationals pleaded guilty to conspiracy to commit bank larceny via ATM jackpotting.
- The group targeted specific ATMs believed to be vulnerable to malware installations.
- The FBI reports over $20 million stolen last year through similar jackpotting schemes.
- The case is linked to a broader crackdown on the 'Tren de Aragua' criminal organization.
In a significant blow to transnational cyber-enabled crime, five Venezuelan nationals—Luis Alberto Velasquez-Artigas, Royder Adrian Figuera-Perez, Javier Mejia, Jr, Gabriel Alexjandro Corales-Garcia, and Italo Lizandro Corrales-Carrillo—have pleaded guilty to conspiracy to commit bank larceny. The group was involved in a series of "jackpotting" attacks, a sophisticated method of theft where malware is used to force an ATM to dispense all its cash.
The defendants were apprehended in December 2025 following failed attempts in Wamego and Manhattan, Kansas. Surveillance footage played a critical role in the investigation, capturing the suspects attempting to install malicious software on the machines. While their attempts in Kansas were unsuccessful, the triggered alarms alerted law enforcement, leading to their swift arrest.
The Mechanics of ATM Jackpotting
ATM jackpotting is not a simple physical break-in but a digital assault. Criminals install specialized malware—such as Ploutus, GreenDispenser, or RIPPER—onto the ATM's internal computer. Once the malware is active, the attackers use a USB keyboard or the machine's own PIN pad to send direct commands to the cash dispenser, effectively "jackpotting" the machine by emptying the money storage cassettes.
| Attack Method | Mechanism | Target |
|---|---|---|
| Traditional Skimming | Physical card reader overlay | Customer Credit Card Data |
| Jackpotting | Internal Malware Installation | Bank's Cash Reserve |
Why This Matters
BozokMedia analysis shows that this case is not an isolated incident but part of a systemic vulnerability in legacy banking hardware. The involvement of the Tren de Aragua organization suggests a highly organized, international approach to financial crime. As the FBI reports losses exceeding $20 million annually, the shift from targeting individuals (skimming) to targeting the institutions themselves (jackpotting) represents a dangerous escalation in cyber-crime strategy.
"Jackpotting bandits are sweeping the nation, specifically targeting ATMs they believe are designed to be more vulnerable to malware." - U.S. Attorney Ryan A. Kriegshauser.
Historical Background and Global Context
The crackdown on Venezuelan gangs in the US has intensified. The Justice Department has already charged 87 members of the Tren de Aragua organization, with some facing sentences up to 335 years. This surge in activity reflects the geopolitical instability in Venezuela, which has pushed organized crime syndicates to export their operations to North America, leveraging both physical violence and digital expertise.
Frequently Asked Questions
What is the difference between skimming and jackpotting?
Skimming steals user data from the card slot, while jackpotting uses malware to force the machine to dispense cash directly from the bank's vault.
Are banks protected against these attacks?
Yes, but only if they update their software and hardware. U.S. authorities are urging banks to invest in the latest security patches to thwart malware installations.