Executive Summary

Five Venezuelan nationals pleaded guilty to conspiracy to commit bank larceny through ATM jackpotting attacks in Kansas during December 2025. The attackers attempted to install malware on ATMs in Wamego and Manhattan to force cash dispensers to empty their storage cassettes, but failed in both attempts and were arrested within days after surveillance cameras captured their activities. This case is part of a broader crackdown on the Tren de Aragua Venezuelan criminal organization, with the Justice Department charging 87 members in connection with ATM malware schemes that stole over $20 million in 2025.

ATM jackpotting attacks represent a growing physical-digital threat where criminals bypass traditional network security by gaining direct hardware access to financial infrastructure, highlighting the critical need for comprehensive security that extends beyond network perimeters to protect physical endpoints and embedded systems.

Why This Matters Now

ATM jackpotting attacks surged in 2025 with over $20 million stolen, representing a shift toward physical infrastructure attacks that bypass traditional cybersecurity defenses, requiring organizations to rethink security strategies for embedded financial systems.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

ATM jackpotting involves installing malware on an ATM's internal computer to control the cash dispenser and force it to empty money storage cassettes, typically using USB keyboards or PIN pads for command execution.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would likely reduce the scope of ATM jackpotting attacks by constraining network access paths and limiting lateral movement between banking infrastructure components. Segmentation controls could reduce the blast radius of malware propagation across financial network environments.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Network segmentation may have limited the malware's ability to establish secure communication channels with broader banking infrastructure, constraining its operational reach beyond the compromised ATM units

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Identity-aware access controls could have constrained the malware's privilege escalation attempts by limiting administrative access scope to only authenticated and authorized banking service accounts

Lateral Movement

Control: East-West Traffic Security

Mitigation: Microsegmentation controls would likely prevent any attempted lateral movement between ATM systems and other banking network components, constraining the attack scope to individual compromised units

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Enhanced visibility controls may have detected unusual command patterns and unauthorized device interactions, constraining the attackers' ability to maintain persistent control over compromised ATM systems

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Controlled egress policies could have limited the malware's ability to transmit transaction data or operational status to external systems, constraining attack coordination capabilities

Impact (Mitigations)

The constrained network access and reduced attack coordination capabilities would likely limit the overall impact scope, reducing potential financial losses and restricting compromise to isolated ATM units

Impact at a Glance

Affected Business Functions

  • ATM Cash Dispensing Services
  • Banking Transaction Processing
  • Physical Branch Security
  • Financial Loss Prevention
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: $20,000,000

Data Exposure

No customer data exposure reported. Impact limited to theft of cash from ATM machines through malware-controlled dispensing. FBI reported over $20 million stolen in 2025 surge of ATM jackpotting incidents, with 87 Tren de Aragua members charged in related schemes.

Recommended Actions

  • Implement Zero Trust Segmentation to isolate ATM networks from other financial infrastructure and prevent lateral movement in case of compromise
  • Deploy Multicloud Visibility & Control solutions to monitor anomalous ATM communications and detect unauthorized access attempts
  • Enable Egress Security & Policy Enforcement to block unauthorized outbound communications from ATM systems and prevent data exfiltration
  • Utilize Threat Detection & Anomaly Response capabilities to baseline normal ATM behavior and alert on jackpotting malware installation attempts
  • Apply Encrypted Traffic (HPE) controls to secure ATM-to-bank communications and prevent interception of financial transaction data

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image