Executive Summary
Five Venezuelan nationals pleaded guilty to conspiracy to commit bank larceny through ATM jackpotting attacks in Kansas during December 2025. The attackers attempted to install malware on ATMs in Wamego and Manhattan to force cash dispensers to empty their storage cassettes, but failed in both attempts and were arrested within days after surveillance cameras captured their activities. This case is part of a broader crackdown on the Tren de Aragua Venezuelan criminal organization, with the Justice Department charging 87 members in connection with ATM malware schemes that stole over $20 million in 2025.
ATM jackpotting attacks represent a growing physical-digital threat where criminals bypass traditional network security by gaining direct hardware access to financial infrastructure, highlighting the critical need for comprehensive security that extends beyond network perimeters to protect physical endpoints and embedded systems.
Why This Matters Now
ATM jackpotting attacks surged in 2025 with over $20 million stolen, representing a shift toward physical infrastructure attacks that bypass traditional cybersecurity defenses, requiring organizations to rethink security strategies for embedded financial systems.
Attack Path Analysis
Venezuelan criminals conducted physical ATM jackpotting attacks by gaining direct access to ATM hardware, installing malware on internal computers, attempting privilege escalation to control cash dispensers, and executing cash theft operations. The attacks failed due to technical issues and triggered alarms, leading to surveillance capture and arrests.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers gained physical access to ATM hardware in Wamego and Manhattan, Kansas, attempting to install jackpotting malware (Ploutus variant) on internal ATM computers
MITRE ATT&CK® Techniques
Hardware Additions
Phishing: Spearphishing Attachment
User Execution: Malicious File
Inter-Process Communication
Impair Defenses: Disable or Modify Tools
Defacement: External Defacement
Data Manipulation: Stored Data Manipulation
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Configuration Standards for System Components
Control ID: 2.2.1
PCI DSS 4.0 – External Penetration Testing
Control ID: 11.3.1
NYDFS 23 NYCRR 500 – Risk Assessment
Control ID: 500.09
CISA ZTMM 2.0 – Device Identity and Integrity
Control ID: Device Security
DORA – Identification and Protection
Control ID: Article 8
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Banking/Mortgage
Primary target sector for ATM jackpotting attacks using financial malware, requiring enhanced physical security, endpoint protection, and egress filtering capabilities.
Financial Services
Critical exposure to cash dispensing malware attacks targeting automated systems, necessitating zero trust segmentation and anomaly detection for ATM networks.
Computer/Network Security
Responsible for developing countermeasures against evolving ATM malware variants and implementing threat detection solutions for financial infrastructure protection.
Law Enforcement
Investigating transnational criminal organizations conducting jackpotting schemes, coordinating arrests and prosecutions of Venezuelan nationals involved in systematic attacks.
Sources
- Five Venezuelans plead guilty to ATM jackpotting attacks in UShttps://www.bleepingcomputer.com/news/security/five-venezuelans-plead-guilty-to-atm-jackpotting-attacks-in-us/Verified
- FBI Investigation Leads to Five Venezuelan Nationals Plead Guilty to Attempting to Jackpot Kansas ATMshttps://www.justice.gov/usao-ks/pr/fbi-investigation-leads-five-venezuelan-nationals-plead-guilty-attempting-jackpot-kansasVerified
- FBI: Over $20 million stolen in surge of ATM malware attacks in 2025https://www.bleepingcomputer.com/news/security/fbi-over-20-million-stolen-in-surge-of-atm-malware-attacks-in-2025/Verified
- US charges 31 more suspects linked to ATM malware attackshttps://www.bleepingcomputer.com/news/security/us-charges-31-more-suspects-linked-to-atm-malware-attacks/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely reduce the scope of ATM jackpotting attacks by constraining network access paths and limiting lateral movement between banking infrastructure components. Segmentation controls could reduce the blast radius of malware propagation across financial network environments.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Network segmentation may have limited the malware's ability to establish secure communication channels with broader banking infrastructure, constraining its operational reach beyond the compromised ATM units
Control: Zero Trust Segmentation
Mitigation: Identity-aware access controls could have constrained the malware's privilege escalation attempts by limiting administrative access scope to only authenticated and authorized banking service accounts
Control: East-West Traffic Security
Mitigation: Microsegmentation controls would likely prevent any attempted lateral movement between ATM systems and other banking network components, constraining the attack scope to individual compromised units
Control: Multicloud Visibility & Control
Mitigation: Enhanced visibility controls may have detected unusual command patterns and unauthorized device interactions, constraining the attackers' ability to maintain persistent control over compromised ATM systems
Control: Egress Security & Policy Enforcement
Mitigation: Controlled egress policies could have limited the malware's ability to transmit transaction data or operational status to external systems, constraining attack coordination capabilities
The constrained network access and reduced attack coordination capabilities would likely limit the overall impact scope, reducing potential financial losses and restricting compromise to isolated ATM units
Impact at a Glance
Affected Business Functions
- ATM Cash Dispensing Services
- Banking Transaction Processing
- Physical Branch Security
- Financial Loss Prevention
Estimated downtime: N/A
Estimated loss: $20,000,000
No customer data exposure reported. Impact limited to theft of cash from ATM machines through malware-controlled dispensing. FBI reported over $20 million stolen in 2025 surge of ATM jackpotting incidents, with 87 Tren de Aragua members charged in related schemes.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to isolate ATM networks from other financial infrastructure and prevent lateral movement in case of compromise
- • Deploy Multicloud Visibility & Control solutions to monitor anomalous ATM communications and detect unauthorized access attempts
- • Enable Egress Security & Policy Enforcement to block unauthorized outbound communications from ATM systems and prevent data exfiltration
- • Utilize Threat Detection & Anomaly Response capabilities to baseline normal ATM behavior and alert on jackpotting malware installation attempts
- • Apply Encrypted Traffic (HPE) controls to secure ATM-to-bank communications and prevent interception of financial transaction data



