Threat Intelligence Neutral 5

5 Venezuelans Guilty as ATM Jackpotting Tops 1,900 Incidents Since 2020

Five Venezuelan nationals pleaded guilty to ATM jackpotting conspiracy after failed malware installation attempts in Kansas. The case reveals attacker tradecraft and aligns with an FBI warning that jackpotting incidents have exceeded 1,900 since 2020, with 700 in 2025 causing over $20 million in losses. Cybersecurity teams should treat these details as threat intelligence for defending financial infrastructure.

· 5 min read · Verified by 2 sources ·

Beat this week

Last 7 days · Threat Intelligence

6 stories
6.3 avg impact
0% positive
83% negative
vs prior 7 days +1 +1 story vs prior 7 days

Impact 6.3/10 (+0.1 vs prior). Counts are stories in our record, not a market forecast.

Open the change report

Coverage balance Negative coverage leads. Negative coverage exceeds positive coverage by 83 percentage points.

  • 17% neutral
  • 83% negative

This story sits in Threat Intelligence — the counts compare this beat's last 7 days with the previous 7 in our verified record, not a market forecast.

Figures are computed live from our source-verified story record (as of ) The volume change compares this window with the prior 7 days in the same record. — see our methodology for how impact and sentiment are derived.

Cybersecurity briefing

Key takeaways

5 impact
Neutralsentiment
2sources
5min read
  1. Five Venezuelan nationals pleaded guilty to ATM jackpotting conspiracy after failed malware installation attempts in Kansas.
  2. The case reveals attacker tradecraft and aligns with an FBI warning that jackpotting incidents have exceeded 1,900 since 2020, with 700 in 2025 causing over $20 million in losses.
  3. Cybersecurity teams should treat these details as threat intelligence for defending financial infrastructure.
Drawn from
  • SecurityWeek
  • BleepingComputer

In this briefing

Mentioned

Key Intelligence

Key Facts

  1. 1Five Venezuelan nationals pleaded guilty to one count of conspiracy to commit bank larceny in connection with ATM jackpotting attempts in Wamego and Manhattan, Kansas, in December 2025.
  2. 2The FBI warned in February 2026 that over 1,900 ATM jackpotting incidents have occurred since 2020, with more than 700 incidents causing over $20 million in losses in 2025 alone.
  3. 3Luis Alberto Velasquez-Artigas, 27, was sentenced to nine months in prison, while the other four defendants await sentencing.
  4. 4Juan Manuel Gouveia-Aguilera, 27, was sentenced in late August 2026 to 96 months in prison and five years of supervised release for a separate ATM jackpotting scheme.
  5. 5The failed Kansas attempts were caught on surveillance cameras, and in Wamego the malware installation attempt triggered an alarm that brought law enforcement response.
  6. 6ATM jackpotting malware families cited include ATMii, ATMitch, GreenDispenser, Alice, RIPPER, Skimer, SUCEFUL, and Ploutus.

Jackpotting bandits are sweeping the nation. This particular group’s strategy was to specifically target ATMs they thought were by design more vulnerable to malware.

Ryan A. Kriegshauser U.S. Attorney

DOJ announcement of guilty pleas

Analysis

For threat intelligence and financial-sector security teams, the guilty pleas offer a rare evidence-based look at ATM jackpotting tradecraft: physical access via ATM internal computers, malware families like Ploutus and Skimer, and command of cash dispensers through USB keyboards or PIN pads. The FBI's count of 700 incidents in 2025 alone — over $20 million in losses — shows this is not a marginal attack vector. This case provides both a baseline for detection and a reminder that basic physical alarms and surveillance can stop even coordinated jackpotting crews.

Five Venezuelan nationals have pleaded guilty in a US court to conspiracy to commit bank larceny in connection with attempted ATM jackpotting attacks in Kansas, underscoring a sharp escalation in a blended physical-cyber crime wave that the FBI says has caused more than $20 million in losses in 2025 alone. The defendants — Luis Alberto Velasquez-Artigas, 27; Royder Adrian Figuera-Perez, 29; Javier Mejia Jr., 27; Gabriel Alexjandro Corales-Garcia, 33; and Italo Lizandro Corrales-Carrillo, 26 — traveled from Indiana to Wamego and Manhattan, Kansas, in December 2025 to install malware on ATMs and remotely trigger them to dispense cash. Both attempts failed and were captured by surveillance cameras, leading to their arrests days later. Velasquez-Artigas has since been sentenced to nine months in prison, while the other four await sentencing. The guilty pleas, announced in a Department of Justice press release, provide a rare window into how ATM jackpotting crews operate and the legal consequences they face.

The malware families cited across multiple jackpotting investigations include ATMii, ATMitch, GreenDispenser, Alice, RIPPER, Skimer, SUCEFUL, and Ploutus.

The broader threat context is significant. In February 2026, the FBI warned that ATM jackpotting incidents are increasing across the United States. Since 2020, more than 1,900 such incidents have been recorded, with over 700 of them — causing more than $20 million in losses — occurring in 2025 alone. That trajectory suggests the problem is accelerating rather than stabilizing, even as law enforcement and financial institutions deploy countermeasures. The Kansas case shows both the vulnerability and the resilience of current defenses. In Wamego, the malware installation attempt triggered an alarm, prompting law enforcement to respond, and the group did not return to the site. In Manhattan, the group was equally unsuccessful in getting the ATM to dispense money. Yet the fact that the defendants were able to access ATM internal computers and make the attempt at all points to remaining security gaps.

ATM jackpotting is a distinctive form of cyber-enabled physical theft. Criminals typically gain physical access to an ATM's internal computer, then install malware by connecting a USB keyboard or using the built-in PIN pad to issue commands to the cash dispenser and empty the money storage cassette. The malware families cited across multiple jackpotting investigations include ATMii, ATMitch, GreenDispenser, Alice, RIPPER, Skimer, SUCEFUL, and Ploutus. Each family represents a different toolset and command-and-control approach, but all exploit the same fundamental weakness: once an attacker has physical access, the logical controls of the ATM can be bypassed or manipulated. This is not a purely remote cyberattack; it requires on-site presence, reconnaissance, and coordination, which makes it both harder to detect before the attempt and easier to investigate afterward through physical evidence and surveillance.

The case also highlights how law enforcement is framing ATM jackpotting as a national organized crime priority. FBI Kansas City Special Agent in Charge Chris Ormerod called jackpotting a growing trend seen nationwide. U.S. Attorney Ryan A. Kriegshauser described the defendants as "jackpotting bandits" who specifically targeted ATMs they believed were more vulnerable to malware by design. His call for banks and financial institutions to invest in technology updates reflects a clear expectation that private-sector security improvements are essential to reducing the attack surface. The sentencing disparity is also notable. Velasquez-Artigas received nine months for his role in the failed Kansas attempts, while in late August 2026, 27-year-old Juan Manuel Gouveia-Aguilera was sentenced to 96 months in prison and five years of supervised release for his involvement in an ATM jackpotting scheme. That contrast suggests courts are weighing factors such as prior involvement, scale, and the success of the conspiracy when deciding sentences.

What to Watch

For financial institutions and cybersecurity teams, the operational lesson is that ATM jackpotting requires a layered defense. Physical hardening of ATM enclosures, tamper-evident seals, enhanced surveillance with alarm integration, and real-time monitoring of dispenser activity are all critical. On the software side, endpoint detection on ATM controllers, firmware integrity checks, network segmentation, and strict USB access controls can reduce the chance of malware installation. The Kansas case demonstrates that basic alarms and surveillance can stop even determined attackers, but the sheer volume of 700 incidents in 2025 means many ATMs remain exposed. The mobility of the defendants — traveling from Indiana to Kansas — also indicates that jackpotting crews conduct targeted reconnaissance across state lines, making regional and national information sharing among banks, ATM deployers, and law enforcement essential.

Looking ahead, the guilty pleas and sentencing are likely to be followed by more prosecutions as the FBI and Department of Justice pursue additional jackpotting networks. The rise in incidents may also push regulators and standards bodies to strengthen ATM security requirements, particularly around logical access and dispenser authentication. As malware evolves and attackers refine their techniques, the line between physical and cyber intrusions will continue to blur. This case serves as both a warning and a proof point: ATM jackpotting is not a novelty but a persistent, organized threat that demands coordinated defense and aggressive enforcement.

Timeline

Timeline

  1. Failed ATM jackpotting attempts in Kansas

  2. Arrests of the five defendants

  3. FBI issues national warning on ATM jackpotting

  4. Separate ATM jackpotting conspirator sentenced

  5. DOJ announces guilty pleas and partial sentence

Source cluster

Primary reporting

2articles

Cite This Page

"5 Venezuelans Guilty as ATM Jackpotting Tops 1,900 Incidents Since 2020." Cyber Intelligence Brief, September 1, 2026. https://getcyberbrief.com/story/atm-jackpotting-guilty-pleas-1900-incidents-cyber

How we covered this story

Every story in our cybersecurity coverage is assembled from multiple primary sources, cross-referenced for factual consistency, and scored along three independent dimensions: sentiment, operational impact, and source-cluster confidence. Single-source rumors and unverifiable claims do not pass our editorial gate. When a story shows "Verified by N sources" with N≥2, the development is independently corroborated; when N=1, we mark it explicitly so readers can weigh the signal accordingly.

Impact scoring uses a 1-10 scale weighted toward regulatory, financial, and operational consequence rather than coverage volume. A topic that runs in every outlet but moves no real decisions ranks lower than a niche regulatory filing that reshapes how operators in the cybersecurity space have to behave. Read our full methodology for the scoring rubric, our glossary for term definitions, and our trends index for the longitudinal view across the beat.

Sources are only linked to a story once they clear our classification pipeline at a minimum 35 percent relevance threshold. According to that methodology, reviewed July 2026, this follows multi-source corroboration standards recommended by journalism research bodies such as the Reuters Institute for the Study of Journalism.

See something wrong in this story — a wrong fact, a broken source link, a misattributed entity? Report a data issue.