Five Venezuelan nationals have admitted guilt in a U.S. federal case involving attempts to force ATMs to dispense cash via malicious software. The defendants pleaded guilty to conspiring to commit bank larceny in connection with so-called jackpotting attacks, a scheme in which malware tricks automatic teller machines into releasing money without customer authorization. The plea followed an FBI probe targeting incidents in Kansas during December 2025.
Failed Attempts in Kansas
The scheme was tied to two failed ATM attacks in Wamego and Manhattan, Kansas. The group, originating from Indiana, is accused of traveling to these locations specifically to target machines they believed could be compromised through malware manipulation. They attempted to access physical ATMs to install software that would let them issue remote commands prompting the machines to dump cash—bypassing any legitimate transaction.
Neither of the two plots succeeded: one attempt in Wamego triggered an alarm during malware installation and netted no cash. The second attempt in Manhattan also failed; the ATM didn’t dispense money. Camera footage helped identify the group, and they were arrested just days afterward.
Scope and Consequences
The group of five—Luis Alberto Velasquez-Artigas (27), Royder Adrian Figuera-Perez (29), Javier Mejia Jr. (27), Gabriel Alexjandro Corales-Garcia (33), and Italo Lizandro Corrales-Carrillo (26)—pled guilty to conspiracy to commit bank larceny. Velasquez-Artigas has already been sentenced to nine months behind bars; the others are awaiting sentencing.
The FBI has flagged ATM jackpotting as a growing threat in the U.S. The agency recorded about 1,900 related incidents since 2020, with over 700 reported in 2025 alone. Losses from those attacks have surpassed $20 million. U.S. officials emphasized that the attackers specifically went after machines they thought had vulnerabilities in their software or internal components.
Banks have been urged to bolster defenses, including stronger security updates, protections against unauthorized software installs, and tools to prevent remote manipulation of ATM systems. Special agents noted that jackpotting—distinct from card skimming—targets the internal software, operating system, and hardware of ATMs directly.
The case was prosecuted by U.S. Attorney Jared Maag, with leadership from the FBI’s Kansas City field office.
Why this matters:Jackpotting attacks are increasing, and financial institutions may be underestimating the risk from malware targeting ATMs rather than external fraud. If internal controls and security patches lag, the attack surface widens. Going forward, regulators and banks alike should closely monitor ATM software integrity and prioritize swift responses to flagged vulnerabilities—otherwise the next jackpotting incident might not fail to pay out.