The U.S. Treasury Department has sanctioned eight members of Tren de Aragua for ATM jackpotting thefts across the United States. Officials estimate over 1,500 attacks stole $40.73 million from U.S. financial institutions as of August 2025, with proceeds laundered to members abroad. The action centers on alleged Ploutus developer Anibal Alexander Canelon Aguirre, known as Prometheus.

How the attack works

Investigators describe a physical-access workflow aimed at bank and credit union automated teller machines. Operators open the ATM chassis or service panel, connect storage or input devices, and install jackpotting malware from families including ATMii, ATMitch, GreenDispenser, Alice, RIPPER, Skimer, SUCEFUL, and Ploutus.

Once resident, the malicious code issues dispense commands to the cash-dispenser unit, causing the machine to eject cash without legitimate transactions. Control and cleanup are performed through an attached USB keyboard or the built-in PIN pad, which can also be used to remove traces from the system.

Background on earlier variants is available in reports on ATMii, self-deleting ATM malware, Alice, and Ploutus.

Individuals and crypto addresses designated

The Office of Foreign Assets Control designated Anibal Alexander Canelon Aguirre, known as Prometheus, and six of his associates: Eric Gabriel Cardenas Arzola, Jose Dario Galeano Bazurto, Anthony Wuiliam Hernandez Guerrero, Carlos Javier Martinez Armenta, Oscar Leonardo Martinez Pirona, and Alejandro Mejia Castillo.

Aguirre is accused of creating the Ploutus malware used in the ATM operations and has been on the FBI's list of Ten Most Wanted Fugitives since March. Details on his arrest and court appearance are described in this court appearance report.

According to OFAC, Prometheus's network is based in Mexico and Venezuela but directs its cash-out operations at U.S.-based automated teller machines, where malware is installed to trigger unauthorized dispensing. The agency says the cash is then laundered and moved to TdA members in various countries.

According to TRM Labs, Treasury also placed seven TRON addresses on its Specially Designated Nationals and Blocked Persons List (SDN List). Those addresses received approximately USD 6.1 million in total inflows since March 2022 and forwarded funds to other TdA-associated addresses.

Scale and related enforcement

OFAC estimates that, as of August 2025, TdA members stole $40.73 million from U.S. financial institutions across over 1,500 alleged ATM jackpotting attacks.

Treasury designated TdA as a Transnational Criminal Organization in July 2024, and the Department of State designated it as a Foreign Terrorist Organization in February 2025. OFAC described the latest sanctions as part of a sustained, whole-of-government campaign that has produced over 30 actions against more than 300 individuals and entities tied to transnational criminal organizations since 2025.

Since October 2025, the U.S. Justice Department has charged 98 suspects linked to the TdA gang and involved in ATM jackpotting schemes, who now face maximum prison terms ranging from 20 to 335 years each. Additional charging details are in this report on 31 more suspects charged.

After a wave of arrests of Tren de Aragua Venezuelan criminal organization members, the FBI warned in February that criminals had stolen over $20 million in 2025 amid a sharp rise in ATM hacking incidents, as detailed in this FBI warning report.

Most recently, in early September, five Venezuelan nationals pleaded guilty after failing to install malware in ATM jackpotting attempts in Wamego and Manhattan, Kansas, as detailed in this guilty plea report.

Technical background — general jackpotting concepts

This section is general background on this attack class, not specific findings about this incident.

Jackpotting typically requires physical access, weak chassis locks, exposed USB ports, unencrypted hard drives, or dispenser units that accept unauthenticated commands. Defenses therefore focus on physical hardening, boot-media control, full-disk encryption, allow-listing, disabling autorun from removable media, and alerting on chassis-door openings, unexpected processes, and large dispenses outside service windows.

A generic illustration of the hardening approach on Windows-based ATMs is to inventory USB device usage and restrict removable storage through policy, for example:


# Generic example only — not from this incident
# Audit removable devices, then enforce deny via policy/GPO/MDM
Get-PnpDevice -Class USBSTOR | Select-Object Status, FriendlyName, InstanceId

Operators commonly combine those controls with network segmentation for ATM fleets, outbound traffic monitoring, centralized logging that survives local deletion attempts, and video-correlated review of maintenance-mode access.