Full Report
Federal law enforcement continued to warn about ATM jackpotting gangs as it announced guilty pleas from five Venezuelan nationals.
Analysis Summary
# Incident Report: Multi-State ATM Jackpotting Campaign
## Executive Summary
A transnational criminal organization, allegedly linked to the Venezuelan gang Tren de Aragua, executed a widespread "jackpotting" campaign targeting ATMs across 47 U.S. states. Using variants of the Ploutus malware, the group physically compromised machines to trigger unauthorized cash dispensed, resulting in over $58 million in losses since 2021. The incident culminated in the recent guilty pleas and sentencing of several Venezuelan nationals involved in the Kansas and Nebraska operations.
## Incident Details
- **Discovery Date:** December 2025 (Kansas specific cases)
- **Incident Date:** Ongoing; Significant activity peak in 2025
- **Affected Organization:** Multiple financial institutions and ATM providers
- **Sector:** Banking / Financial Services
- **Geography:** 47 U.S. States and several international locations
## Timeline of Events
### Initial Access
- **Date/Time:** December 2025 (Kansas Incident)
- **Vector:** Physical Breach
- **Details:** Attackers physically broke into ATM enclosures to gain access to the internal hardware components.
### Lateral Movement
- **Details:** Attackers bypassed hardware security to connect external devices (laptops) to the ATM’s hard drive or replaced the existing hard drive with a pre-loaded, infected drive.
### Data Exfiltration/Impact
- **Details:** Deployment of Ploutus malware, designed to interface with the ATM's XFS (Extensions for Financial Services) layer to command the dispenser to eject all available currency.
### Detection & Response
- **Discovery:** Silent police alarms were triggered during failed installation attempts in Wamego and Manhattan, Kansas.
- **Response Actions:** Local law enforcement and the FBI utilized surveillance footage to identify the suspects' vehicle, leading to arrests within days.
## Attack Methodology
- **Initial Access:** Physical tampering/break-in of the ATM chassis.
- **Persistence:** Installation of malware (Ploutus) on the ATM hard drive; in some cases, replacing the physical drive entirely.
- **Privilege Escalation:** Exploiting the lack of authentication between the ATM’s computer and the cash dispenser.
- **Defense Evasion:** Targeting older or "vulnerable by design" ATM models; using encrypted or obfuscated malware variants.
- **Credential Access:** Not applicable (attacks target the hardware/dispenser rather than user accounts).
- **Discovery:** Reconnaissance of ATM locations in rural or less-monitored areas (e.g., Wamego, Kansas).
- **Lateral Movement:** Physical-to-Digital interface (Laptop/External Drive to ATM BUS).
- **Collection:** Manual collection of dispensed cash.
- **Exfiltration:** Physical removal of currency ("Jackpotting").
- **Impact:** Financial loss via unauthorized currency dispensing and physical damage to ATM hardware.
## Impact Assessment
- **Financial:** Estimated $58 million in total losses since 2021; over $20 million in 2025 alone. One individual was linked to $3.5 million in personal responsibility.
- **Data Breach:** None (Primary objective is theft of physical currency, not PII).
- **Operational:** Disruption of ATM services and costs associated with repairing physically damaged machines.
- **Reputational:** Increased public concern regarding the physical security of banking infrastructure.
## Indicators of Compromise
- **Network indicators:** N/A (Ploutus often operates offline once installed).
- **File indicators:** Ploutus malware variants (e.g., Ploutus-D).
- **Behavioral indicators:** Suspicious individuals lingering at ATMs with laptops; physical signs of tampering on ATM casing; unexpected "Out of Service" messages followed by rapid cash depletion.
## Response Actions
- **Containment:** Law enforcement arrests of key operatives; seizure of infected hardware.
- **Eradication:** Implementation of newer ATM security technology that prevents unauthorized software from interfacing with the dispenser.
- **Recovery:** Restitution orders for convicted individuals; replacement of compromised hard drives.
## Lessons Learned
- **Hardware Vulnerability:** Physical access remains the weakest link for many legacy ATM models.
- **Transnational Links:** These operations are increasingly used to fund violent transnational criminal organizations (e.g., Tren de Aragua).
- **Proactive Alarms:** Rapid response to "silent" physical tampering alarms was critical in the Kansas arrests.
## Recommendations
- **Hardware Hardening:** Upgrade ATMs to include encrypted communication between the ATM PC and the cash dispenser.
- **Physical Security:** Enhance ATM enclosures and install anti-tampering sensors that trigger immediate law enforcement notification.
- **Software Integrity:** Implement Trusted Platform Modules (TPM) and Full Disk Encryption (FDE) to prevent unauthorized hard drive replacements or malware side-loading.
- **Surveillance:** Ensure high-definition CCTV coverage of all ATM kiosks, including license plate recognition in surrounding parking areas.