Venezuelan National Gets Record 8-Year Sentence for ATM Jackpotting Scheme
A 27-year-old Venezuelan national has been sentenced to 96 months in federal prison for his role in an ATM jackpotting operation that caused more than $3.5 million in losses, the U.S. Justice Department announced. Juan Manuel Gouveia-Aguilera pleaded guilty to bank fraud, bank burglary, and cyber-enabled fraud charges and was additionally ordered to serve five years of supervised release and pay restitution. The DOJ stated that this sentence is believed to be the longest federal prison term ever imposed on a single individual for ATM jackpotting offenses in the United States.
Gouveia-Aguilera's sentencing comes just weeks after two other Venezuelan nationals, Oddry Arnoldo Cabrera Torrealba and Carlos Javier Padron, each received 78-month sentences for the same scheme. All three are among 119 individuals charged in Nebraska in connection with the attacks, which authorities say were carried out on behalf of the Venezuelan transnational criminal organization Tren de Aragua (TdA). The attacks typically involved removing the outer casing of a target ATM, connecting a laptop to the machine's internal ports, and installing malware that forced the dispenser to eject all stored cash—a technique that organizations can better defend against by routinely auditing exposed services with a port scanner and segmenting ATM networks from corporate infrastructure.
The FBI previously warned of a sharp rise in malware-enabled ATM jackpotting across the United States, reporting roughly 1,900 incidents since 2020 and losses exceeding $20 million in the most recent year alone. Earlier this year, the bureau noted that threat actors are increasingly targeting standalone ATMs in retail and hospitality settings, where physical security controls may be weaker. Investigators believe the Venezuelan-linked crews exploited weak default credentials and outdated ATM firmware to gain persistent access.
The case underscores how physical-access cyberattacks remain a lucrative and underappreciated threat vector. Security teams responsible for ATM fleets and self-service kiosks should enforce hardware tamper detection, restrict USB and serial port access, and rotate administrative credentials using a strong password checker to ensure no default or compromised keys remain in use. Individuals concerned about fraud exposure from compromised banking infrastructure can also run a email breach check to confirm whether their financial account credentials have appeared in known dumps.