Five Plead Guilty in $58M ATM Jackpotting Scheme Using Ploutus Malware
Five Venezuelan nationals have pleaded guilty to conspiracy to commit bank larceny in a federal Kansas court after prosecutors accused them of being part of a coordinated group that targeted ATMs using jackpotting malware. Luis Alberto Velasquez-Artigas, 27, was sentenced to nine months in prison, while co-defendants Royder Adrian Figuera-Perez, 29, Javier Mejia Jr., 27, Gabriel Alexjandro Corales-Garcia, 33, and Italo Lizandro Corrales-Carrillo, 26, await sentencing. According to court documents, the men drove from Indiana to Kansas in December 2025 to compromise ATMs in Wamego and Manhattan by physically breaching the machines and installing malware designed to dispense cash on demand. Both attempts failed and triggered police alarms, but the group was identified through surveillance footage and arrested days later.
This case is part of a broader federal crackdown on ATM jackpotting operations linked to the Ploutus malware strain. In a separate ruling, Juan Manuel Gouveia-Aguilera, 27, received an eight-year sentence from a federal judge in Omaha, Nebraska, on August 20 after being held responsible for more than $3.5 million in ATM losses tied to hundreds of compromised machines. He pleaded guilty to bank fraud, computer fraud, and related charges and was ordered to pay restitution and serve five years of supervised release. Co-conspirators Oddry Arnoldo Cabrera Torrealba and Carlos Javier Padron were each sentenced to 6.5 years. Federal prosecutors have charged at least 119 individuals connected to the scheme, which allegedly struck ATMs across 47 U.S. states and several foreign countries.
The technical tradecraft typically involves either connecting a laptop directly to an ATM's internal hard drive or swapping it out for an infected drive pre-loaded with Ploutus, a payload that has been circulating in Latin American financial crime circles for over a decade. According to FBI Director Kash Patel, the wider ATM jackpotting campaign has generated more than $58 million in losses since 2021, with the bureau documenting over 1,900 incidents since 2020 — including 700-plus cases in 2025 alone representing more than $20 million. U.S. Attorney Ryan Kriegshauser warned that jackpotting bandits are actively sweeping the nation and urged ATM operators to deploy newer anti-tampering defenses. Operators concerned about exposed network services on payment infrastructure can run a quick port scanner to verify that management interfaces are not publicly reachable, while consumers can use a email breach checker to confirm whether banking credentials tied to compromised ATMs have surfaced on the dark web.
"Gouveia-Aguilera and his alleged co-conspirators thought they could hack American ATMs, drain financial institutions, and funnel money to a violent transnational criminal organization without consequence. They were wrong," said HSI Kansas City Special Agent in Charge in a statement following the sentencing. The string of guilty pleas signals escalating federal coordination against physical-cyber hybrid attacks targeting financial infrastructure, a category that continues to challenge defenders because it blends on-site intrusion with malware deployment.