Five Venezuelan nationals have pleaded guilty to conspiracy to commit bank larceny after being accused of robbing ATMs using malware. A federal court in Kansas sentenced Luis Alberto Velasquez-Artigas, 27, to nine months in prison, while the other four defendants—Royder Adrian Figuera-Perez, 29, Javier Mejia, Jr., 27, Gabriel Alexjandro Corales-Garcia, 33, and Italo Lizandro Corrales-Carrillo, 26—are awaiting sentencing. According to court documents, the group traveled from Indiana to Kansas in December 2025 to rob ATMs in Wamego and Manhattan through a method known as jackpotting, where criminals install malware to empty the machines.
Their attempts to install the malware on ATMs in Wamego and Manhattan failed, triggering police alarms. The group was captured on surveillance cameras and arrested shortly thereafter. U.S. Attorney Ryan Kriegshauser noted, “Jackpotting bandits are sweeping the nation,” emphasizing that this group specifically targeted ATMs they believed were more vulnerable to malware. He urged companies to invest in technology that can help prevent such attacks.
ATM Jackpotting Trends
FBI Director Kash Patel reported that ATM jackpotting schemes have resulted in losses exceeding $58 million since 2021. The FBI has tracked over 1,900 incidents of ATM jackpotting since 2020, with more than 700 occurring in 2025 alone, leading to losses of over $20 million.
This case is part of a broader trend of federal guilty pleas related to ATM jackpotting. Another individual, Juan Manuel Gouveia-Aguilera, was sentenced to eight years in prison for his involvement in a gang that used Ploutus malware to steal millions from ATMs. Prosecutors indicated that Gouveia-Aguilera was responsible for over $3.5 million in losses.
Connection to Transnational Crime
Assistant Attorney General A. Tysen Duva stated that these ATM jackpotting schemes were intended to fund violent transnational criminal organizations, including the Venezuelan gang Tren de Aragua. Federal prosecutors have sought to link these attacks to Tren de Aragua, alleging that the group was responsible for the creation of the Ploutus malware.
Experts have warned about the Ploutus malware for nearly a decade, with Google researchers describing it as one of the most advanced ATM malware families. First detected in 2013, Ploutus has evolved and has been used to target ATMs from various vendors, including Diebold Nixdorf.
For more details, see the full report by The Record.
Follow Cyber Warriors Middle East for further global cybersecurity developments.



