The U.S. Treasury Department's Office of Foreign Assets Control (OFAC) sanctioned 10 individuals and several companies. These entities are implicated in a scheme that used malware to drain cash from ATMs. The sanctions target Venezuelan nationals and their controlled companies involved in laundering the stolen funds.
U.S. officials have tracked at least 1,500 attacks attributed to this scheme, resulting in total losses of $40.7 million. The malware, identified as Ploutus, forces ATMs to dispense all available cash. The FBI previously identified Anibal Alexander Canelon Aguirre as the developer of the Ploutus malware, who is accused of deploying teams across the U.S. to target ATMs, often in remote areas.
The sanctions directly link the ATM jackpotting scheme to Tren de Aragua, a Venezuelan criminal group, which the Treasury Department claims uses it as a key source of revenue. The Justice Department has also cited extensive direct and indirect links between the Ploutus malware and Tren de Aragua. Proceeds from the ATM thefts were allegedly transferred to Tren de Aragua members and laundered via cryptocurrency or through companies in Mexico and other countries.
Blockchain analysis firm Chainalysis reported that the proceeds from ATM jackpotting flow through similar channels as drug trafficking money. Their analysis found that wallets associated with Tren de Aragua had exposure to laundering operations used by Colombian and Mexican drug cartels, as well as a Venezuelan national charged with laundering one billion dollars. The network utilized shared laundering infrastructure, including stablecoins, to service multiple criminal organizations across Latin America.
These sanctions are part of ongoing U.S. government actions against the ATM jackpotting scheme. Previously, 98 individuals have been indicted for their roles in the malware scheme, and five men pleaded guilty to related charges last month. Prosecutors and the Treasury Department have shared evidence, including videos and photos, showing individuals installing the malware by connecting laptops to ATMs.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
The US Treasury Department has sanctioned Anibal Alexander Canelon Aguirre, known as 'Prometheus,' the alleged developer of Ploutus malware used in ATM jackpotting attacks, along with his network and two Mexico-based companies. This action blocks their US assets and prohibits transactions with them, aiming to disrupt the financial infrastructure supporting the Tren de Aragua (TdA) criminal organization.
The U.S. Treasury Department sanctioned 10 individuals and several companies for their involvement in an ATM malware scheme that caused $40.7 million in losses across 1,500 attacks. This scheme is identified as a key revenue source for the Venezuelan criminal group Tren de Aragua, with proceeds laundered through cryptocurrency and companies in Mexico.