Five plead guilty in latest federal ATM jackpotting case
Five Venezuelan nationals have pleaded guilty to conspiracy to commit bank larceny after prosecutors accused them of being part of a group dedicated to robbing ATMs using malware.
A Kansas federal court sentenced Luis Alberto Velasquez-Artigas, 27, to nine months in prison while the other four defendants — Royder Adrian Figuera-Perez, 29, Javier Mejia, Jr, 27, Gabriel Alexjandro Corales-Garcia, 33, and Italo Lizandro Corrales-Carrillo, 26 — are awaiting sentencing.
According to court documents, the men drove from Indiana to Kansas in December 2025 to rob several ATMs in Wamego and Manhattan through jackpotting — a process in which criminals break into an ATM and install malware that allows them to empty it.
They tried to install the malware on ATMs in Wamego and Manhattan but both attempts failed and triggered police alarms. The group was caught on surveillance cameras and all of them were arrested days later.
“Jackpotting bandits are sweeping the nation. This particular group’s strategy was to specifically target ATMs they thought were by design more vulnerable to malware,” U.S. Attorney Ryan Kriegshauser said Monday.
Kriegshauser added that there is now technology that can help stop jackpotting attacks and urged companies to invest in them as soon as possible.
FBI director Kash Patel said in a statement last week that the ATM jackpotting scheme has caused losses of over $58 million since 2021.
The FBI said it has tracked more than 1,900 ATM jackpotting incidents since 2020 and over 700 in 2025 that involved more than $20 million in losses.
Ploutus malware
This is the latest set of federal guilty pleas in recent weeks related to ATM jackpotting schemes.
Another man, Juan Manuel Gouveia-Aguilera, 27, was sentenced to eight years in prison by a federal judge in Omaha, Nebraska, on August 20 after prosecutors said he was one of several members of a prominent gang to use the Ploutus malware to steal millions from hundreds of ATMs.
He previously pleaded guilty to several charges including bank fraud, fraud in connection with computers and more. In addition to eight years in prison, Gouveia-Aguilera will have five years of supervised release and will have to pay restitution to the banks impacted.
Prosecutors said Gouveia-Aguilera was responsible for more than $3.5 million in ATM losses. In many cases, criminals either link a laptop to the ATM’s hard drive or replace it with an infected drive pre-loaded with the Ploutus malware.
Oddry Arnoldo Cabrera Torrealba and Carlos Javier Padron also were recently given 6.5-year sentences for their connections to the jackpotting scheme. At least 119 people have been charged for their alleged roles. The group allegedly targeted ATMs in 47 U.S. states and several other countries.
“Gouveia-Aguilera and his alleged co-conspirators thought they could hack American ATMs, drain financial institutions, and funnel money to a violent transnational criminal organization without consequence. They were wrong,” said HSI Kansas City Special Agent in Charge Rick Sabatini on August 21.
Assistant Attorney General A. Tysen Duva said the ATM jackpotting schemes were meant to help fund violent transnational criminal organizations like Venezuelan gang Tren de Aragua.
Federal prosecutors have sought to connect the ATM jackpotting attacks to Tren de Aragua. In the initial indictment charging Gouveia-Aguilera and dozens of others, prosecutors accused the group of being responsible for the creation of Ploutus malware.
FBI officials previously told Recorded Future News that they believe the malware was created by Anibal Alexander Canelon Aguirre, who was part of the indictment that included Gouveia-Aguilera and several other Venezuelan nationals.
Experts and government agencies have warned for nearly a decade about variants of the Ploutus malware, which Google researchers previously said “is one of the most advanced ATM malware families” they've seen.
Ploutus was first detected by Symantec in 2013 and has gone through several updates since then. It was initially deployed against ATMs across Mexico in 2013, allowing criminals to empty machines by either attaching an external keyboard attached to the ATM or by sending an SMS message, a technique that had never been seen before, according to Google.
Recorded Future News spoke to multiple companies that have tracked Ploutus for more than a decade and none could confirm whether Aguirre was the true developer of the malware or whether its development had any ties to Tren de Aragua.
Ploutus has been used to target machines from a variety of vendors, including Diebold Nixdorf, Kalignite Platform and others. Diebold Nixdorf issued multiple alerts in 2017 and 2018 about variants of the malware being used to steal money across Mexico and the U.S.
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.



