What began as a December 2025 announcement of 54 federal defendants has grown into a wider, still-developing U.S. prosecution of alleged ATM-jackpotting crews. Prosecutors say members and associates of the Venezuelan transnational criminal organization Tren de Aragua used physical access and a Ploutus malware variant to make ATMs dispense cash without legitimate transactions. By January 2026, the Justice Department said 87 people had been charged at that stage; later releases reported additional defendants, guilty pleas and sentences. The FBI separately warned that malware-enabled ATM jackpotting was increasing nationwide.
The case in brief
- What prosecutors allege: Crews physically accessed ATMs, deployed malware and issued unauthorized commands to the machines’ cash-dispensing systems.
- Malware involved: A variant of Ploutus, an ATM-malware family associated with forced cash dispensing.
- Initial announcement: Two Nebraska indictments charged 32 people on October 21, 2025, and 22 people on December 9, 2025. The Justice Department announced the combined 54-defendant case on December 18, 2025 (DOJ).
- Later developments: An additional January indictment brought the announced total to 87; subsequent releases described more charges and related cases.
- Losses: DOJ later reported more than $6 million in losses to financial institutions and at least $1.74 million in attempted additional losses (February 20, 2026 DOJ release).
These are allegations unless and until proved in court. Defendants are presumed innocent.
What ATM jackpotting means
ATM jackpotting is the forced dispensing of cash from an ATM through malware, unauthorized hardware or both. The target is the cash held inside the machine, not necessarily customers’ cards or account credentials. The FBI describes attacks in which criminals exploit physical or software weaknesses to deploy malware and make an ATM release money without a legitimate banking transaction (FBI flash, February 19, 2026).
That makes jackpotting different from several other ATM crimes:
Recommended Free Tools
#1 Best Overall
| Crime | Primary objective |
|---|---|
| Jackpotting | Force the ATM to dispense its internal cash. |
| Skimming | Capture card data or PINs for later fraudulent transactions. |
| Cash trapping | Block the cash outlet and retrieve cash after the customer leaves. |
| ATM burglary | Break into the safe or cash cassette, potentially without malware. |
| Backend compromise | Attack ATM-management systems or networks rather than the machine directly. |
What Ploutus does inside an ATM
“Ploutus” is a malware family, not one uniform program. In this case, prosecutors allege that a Ploutus variant issued unauthorized commands to the ATM’s Cash Dispensing Module—the hardware that physically presents banknotes—causing the machine to release currency. DOJ also alleged that the malware could delete evidence of its presence (January 26, 2026 DOJ release).
Public charging documents do not establish a complete version number, source-code lineage, list of affected ATM models or every technical feature of the variant. They also do not show that every defendant installed malware or performed the same role.
Rank #2
- Made in USA - Proudly produced in Ohio by a Veteran-owned business
- Comprehensive Coverage: This BookFactory log book includes essential fields such as post/shift, time of change, date, weather conditions, and a designated space for detailed notes. This ensures that all relevant information is captured and easily accessible.
- Sturdy Cover: The trans-lux cover protects the log book from wear and tear, ensuring its longevity and maintaining the integrity of your recorded data.
- Essential Security Tool: This log book is an indispensable tool for any organization that values security and accountability. It helps to prevent misunderstandings, improve communication, and ensure a smooth transition between shifts.
- Wire-O with Trans-lux cover, 100 Pages, Dimensions 8.5" x 11" - (Security-Pass-Down) Reorder SKU: LOG-100-7CW-PP(Security-Pass-Down)
How prosecutors say the attacks worked
The alleged sequence combines physical intrusion with software manipulation. The following is a defensive summary, not an attack procedure:
- Reconnaissance: Crews inspected target ATMs and noted external security features.
- Physical access: They allegedly opened an ATM hood or service door.
- Alarm testing: According to the charging documents, suspects waited nearby to see whether the opening triggered an alarm or police response.
- Malware deployment: Alleged methods included removing and replacing the ATM’s hard drive or connecting an external device to install a preloaded program.
- Cash-out: Operators issued commands that caused the cash-dispensing mechanism to release money.
- Concealment and division: Prosecutors allege that evidence could be deleted and that proceeds were divided according to predetermined shares.
The public releases do not provide malware commands, bypass instructions or a universal remediation method.
Who was charged and what they face
DOJ described the defendants as Venezuelan and Colombian nationals, including alleged members or associates of Tren de Aragua. One named defendant, Jimena Romina Araya Navarro, was described by prosecutors as an alleged Tren de Aragua leader and had previously been sanctioned by the Treasury Department’s Office of Foreign Assets Control. Those descriptions are prosecutorial allegations; they do not establish that every defendant belonged to the organization.
The indictments included allegations of:
- Conspiracy to commit bank fraud and bank fraud.
- Conspiracy to commit bank burglary and computer fraud.
- Bank burglary.
- Damage to computers.
- Conspiracy to commit money laundering.
- In some cases, conspiracy to provide material support to a designated terrorist organization.
The December announcement cited possible statutory maximum imprisonment terms ranging from 20 to 335 years. Those are maximum penalties authorized by statute, not predicted or imposed sentences for every defendant (DOJ, December 18, 2025). Prosecutors also alleged that some proceeds supported Tren de Aragua; that allegation remains distinct from a proven finding in each individual case.
Rank #4
Case timeline
| Date | Development |
|---|---|
| October 21, 2025 | First Nebraska indictment charged 32 defendants. |
| December 9, 2025 | Second Nebraska indictment charged 22 defendants. |
| December 18, 2025 | DOJ publicly announced the combined 54-defendant case. |
| January 26, 2026 | An additional indictment against 31 people brought DOJ’s announced total to 87 at that stage; the release described Ploutus deployment and Cash Dispensing Module commands (DOJ). |
| February 20, 2026 | DOJ announced six more defendants and reported losses exceeding $6 million, plus at least $1.74 million in attempted losses (DOJ). |
| April 13, 2026 | A Michigan defendant pleaded guilty in a related ATM-jackpotting case (DOJ). |
| June 3, 2026 | In a separate Nevada case, two men were accused of installing a digital device on an ATM and stealing approximately $76,000 (DOJ). |
| June 26, 2026 | Two defendants were sentenced after pleading guilty. DOJ said 96 other defendants had been indicted in the broader conspiracy and related offenses, a figure that overlaps the evolving case structure rather than replacing every earlier count (DOJ). |
How much money was involved?
The figures refer to different scopes and should not be combined:
- This prosecution: DOJ’s February release put losses to victim financial institutions above $6 million, with at least $1.74 million in attempted additional losses.
- Broader U.S. activity: The FBI reported approximately 1,900 ATM-jackpotting incidents since 2020, including more than 700 incidents and over $20 million in losses during 2025 alone (FBI, February 19, 2026).
The FBI’s national 2025 number covers the wider phenomenon, not just the Nebraska-centered prosecution.
Free tools Windows power users keep installed
One-click scans. No signup required.
What banks and ATM operators should evaluate
The alleged chain shows why ATM security is both a physical-security and cybersecurity problem. The FBI flash is the authoritative source for its recommended technical measures; practical review areas include:
- Service-door, enclosure and internal-component tamper protection.
- Secure boot, storage-integrity checks and controls against unauthorized drive changes.
- Restrictions on removable media and external devices.
- Application allowlisting and endpoint monitoring where the ATM vendor permits them.
- Network segmentation between ATMs, management systems and corporate networks.
- Alerts for cash dispensing outside normal transaction patterns.
- Vendor and third-party maintenance authentication, logging and supervision.
- Rapid preservation of drives, logs, video and other evidence after an incident.
No public release establishes that every affected ATM lacked any particular control. ATM operators should validate changes against manufacturer certification, processor requirements and the machine’s supported operating environment.
What customers need to know
Jackpotting primarily steals cash held by the financial institution. It is not automatically a card-data breach or account takeover. The cited charging documents do not establish that customer card credentials or account balances were compromised in every incident. Customers may nevertheless encounter an unavailable ATM, transaction disruption or delayed service while a machine is secured and investigated.
What remains unknown
- The complete list of affected ATM manufacturers and models.
- The precise Ploutus variant and its full technical lineage.
- A complete public victim list and incident-by-incident loss breakdown.
- The exact role assigned to each defendant.
- Whether every alleged incident used the same deployment method.
Those gaps matter because “ATM hacking” is a broad media label. The public allegations describe a particular combination of physical access, malware deployment and forced cash dispensing—not a single universal attack against every ATM.
Legal status
Indictments and criminal complaints are accusations. Guilty pleas and sentences apply only to the defendants and charges resolved in those proceedings. Every other defendant is presumed innocent unless proven guilty beyond a reasonable doubt.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




