news.mlab.sh
Back to the feed
threat-intel

Five plead guilty in latest federal ATM jackpotting case

High
Summary

Five Venezuelan nationals have pleaded guilty to conspiracy to commit bank larceny after attempting to jackpot ATMs in Kansas and other states. The group, led by Juan Manuel Gouveia-Aguilera, utilized the Ploutus malware – a sophisticated tool developed over a decade and previously linked to the Venezuelan gang Tren de Aragua – to steal millions from ATMs. The FBI has tracked over 1,900 ATM jackpotting incidents since 2020, resulting in over $20 million in losses, and experts warn that the threat remains active.

Five Venezuelan nationals have pleaded guilty to conspiracy to commit bank larceny after attempting to jackpot ATMs in Kansas and other states. The group, led by Juan Manuel Gouveia-Aguilera, utilized the Ploutus malware – a sophisticated tool developed over a decade and previously linked to the Venezuelan gang Tren de Aragua – to steal millions from ATMs. The scheme involved physically accessing ATMs, either by attaching an external keyboard to the ATM’s hard drive or sending an SMS message, a technique previously unseen.

Juan Manuel Gouveia-Aguilera was sentenced to eight years in prison, with five years of supervised release, and must pay restitution to impacted banks. He was responsible for more than $3.5 million in ATM losses. Five other defendants are awaiting sentencing. The group allegedly targeted ATMs in 47 U.S. states and several other countries.

Federal prosecutors have sought to connect the ATM jackpotting attacks to Tren de Aragua, a violent transnational criminal organization. The FBI has tracked over 1,900 ATM jackpotting incidents since 2020 and over 700 in 2025, resulting in over $20 million in losses. Ploutus malware, initially detected by Symantec in 2013 and continuously updated since, has been used to target machines from vendors including Diebold Nixdorf and Kalignite Platform. Diebold Nixdorf issued multiple alerts in 2017 and 2018 about variants of the malware being used to steal money across Mexico and the U.S.

Experts and government agencies have warned for nearly a decade about variants of the Ploutus malware, which Google researchers previously described as “one of the most advanced ATM malware families” they've seen. The malware was initially deployed against ATMs across Mexico in 2013, allowing criminals to empty machines by either attaching an external keyboard to the ATM or by sending an SMS message. FBI officials previously told Recorded Future News that they believe the malware was created by Anibal Alexander Canelon Aguirre, who was part of the indictment that included Gouveia-Aguilera and several other Venezuelan nationals. Recorded Future News spoke to multiple companies that have tracked Ploutus for more than a decade and none could confirm whether Aguirre was the true developer of the malware or whether its development had any ties to Tren de Aragua.

Read the full article at The Record