Five Venezuelans Plead Guilty to Attempted ATM Malware Jackpotting Attacks

Five Venezuelan nationals have pleaded guilty to conspiracy to commit bank larceny after an FBI investigation uncovered their attempt to “jackpot” ATMs in Kansas using malware designed to force cash dispensers to empty their vaults.

According to the U.S. Attorney’s Office for the District of Kansas, Luis Alberto Velasquez-Artigas (27), Royder Adrian Figuera-Perez (29), Javier Mejia Jr. (27), Gabriel Alexjandro Corales-Garcia (33), and Italo Lizandro Corrales-Carrillo (26) traveled from Indiana to Kansas in December 2025 to target ATMs in Wamego and Manhattan.

Court documents describe a two-stage operation: one conspirator would physically install malware on the targeted ATM, and the group would later transmit a remote command instructing the machine to dispense cash for collection.

Five Venezuelans Plead Guilty

The scheme faltered at both locations. In Wamego, the attempt to install malware triggered an alarm, prompting a law enforcement response before the crew could return.

In Manhattan, the group successfully approached the machine but failed to force a cash dispensing. Surveillance footage captured both attempts, leading to the group’s arrest within days.

Velasquez-Artigas has already been sentenced to nine months in prison; the remaining four defendants await sentencing.

Jackpotting is a physical-cyber hybrid attack in which criminals gain direct access to an ATM’s internals, often via an endoscope, service key, or exposed port, to deploy malware or a malicious hardware implant such as a “black box.”

According to the DOJ, once installed, the malware issues commands that bypass the machine’s normal transaction authentication, causing it to eject stored currency without a corresponding account withdrawal.

An FBI report cited in the release found jackpotting incidents have accelerated sharply, with roughly 1,900 cases recorded since 2020 and more than 700 incidents in 2025 alone, resulting in over $20 million in losses.

U.S. Attorney Ryan A. Kriegshauser noted that this Kansas cell specifically scouted ATM models it deemed more susceptible to malware installation, underscoring how jackpotting crews often reconnoiter hardware before striking.

FBI Kansas City Special Agent in Charge Chris Ormerod said the case reflects a nationwide pattern in which “criminal actors exploit vulnerabilities in ATM technology to access and steal the cash contained inside the machines,” frequently without any legitimate transaction ever occurring, complicating institutions’ ability to trace how funds disappeared.

Kriegshauser urged banks and financial institutions to invest proactively in anti-jackpotting technology, offering the U.S. Attorney’s Office as a resource for guidance on implementation.

Recommended defenses typically include tamper-detection sensors, firmware whitelisting, encrypted communication between the ATM’s core and dispenser, physical lock hardening, and rapid alarm response protocols.

Give your security team the visibility and context to investigate suspicious activity faster and contain threats before business impact grows. Strengthen Your Investigations with ANY.RUN

Tamilselvan
Tamilselvanhttps://cyberpress.org/
Tamilselvan is an Investigative cybersecurity journalist dedicated to breaking stories on ransomware cartels, data breaches, and state-sponsored espionage.

Trending News

Related Stories