Cybercrime is constantly evolving and in recent years has shifted from simple theft of personal data to more complex and highly profitable attacks against financial institutions. One of the most characteristic forms of this new reality is ATM Jackpotting, a technique that allows perpetrators to literally empty automated teller machines, without requiring the use of a bank card or the making of a legitimate transaction.

The issue has been brought back to the forefront following the conclusion of one of the most significant court cases in recent years in the United States. Two Venezuelan nationals were sentenced to 78 months in prison for their participation in an organized ring that used the Ploutus malware to carry out ATM jackpotting attacks. The losses to banking institutions exceeded $1.5 million, while the investigation revealed a much larger international criminal network with dozens of accomplices.
Learn more: ATM Jackpotting gang members convicted of Ploutus malware attacks
The case that exposed a wider criminal network
The two convicted criminals, Carlos Javier Padron and Oddry Arnoldo Cabrera Torrealba, were arrested in 2024 while carrying out an ATM robbery in the state of Nebraska. Their arrest was the starting point of an extensive federal investigation that led to the indictment of 96 more people on charges including bank fraud, money laundering, unauthorized access to information systems and wire fraud.
The American authorities estimate that some of those involved had connections with the notorious criminal organization Tren de Aragua, which in recent years has reportedly expanded its activities into the field of cybercrime, utilizing advanced techniques to finance its activities.
What is ATM Jackpotting?
Unlike classic attacks that aim to steal credit card or bank account details, ATM Jackpotting has a different philosophy. The perpetrators seek to gain direct control of the machine itself.

After gaining physical access to the ATM, they install specially designed malware, such as Ploutus or other variants. The malware communicates with the cash dispensing unit and allows attackers to send commands that force the machine to dispense banknotes without any legitimate transaction taking place.
In many cases, orders are given via a mobile phone or a special electronic device, and the entire process is completed within a few seconds.
See also: ATM Jackpotting suspect added to FBI's Ten Most Wanted list
Ploutus and the evolution of attacks
Ploutus is one of the most well-known malware created exclusively for ATM attacks. It first appeared several years ago in Latin America, but has since evolved significantly, acquiring new capabilities and adapting to different types of machines.
Modern versions can erase their tracks after the attack is complete, making investigations by banks and authorities more difficult. At the same time, criminals are using increasingly sophisticated techniques to bypass ATM protection systems and limit their chances of detection.
Why are attacks increasing?
The increase in incidents is not accidental. Many ATMs are still operating with older operating systems or have inadequate physical protection, which makes it easier for perpetrators.
At the same time, the commercialization of cybercrime has made it easier to access specialized tools. The dark web is filled with ready-made software packages, installation guides, and equipment that allow even less experienced criminals to carry out such attacks.
The organized action of international criminal groups makes ATM Jackpotting particularly profitable, as a single successful attack can yield tens of thousands of euros or dollars within minutes.
See also: FBI reports 1,900 ATM Jackpotting incidents since 2020

How can banks be protected?
Effectively addressing attacks requires a combination of physical and digital security.
Experts recommend regularly updating ATM software , replacing old operating systems, encrypting communication between the machine's individual units, and installing mechanisms that detect unauthorized access inside the device.
At the same time, continuous monitoring of networks, the use of advanced anomaly detection systems and the training of technical personnel can significantly limit the risk of successful attacks.
What can citizens do?
Although Jackpotting primarily targets banks, customers can also help prevent incidents. If an ATM shows signs of tampering, unusual messages on the screen, or appears to have been damaged, it is best to avoid using it and notify the bank immediately.
Additionally, choosing ATMs located inside bank branches or in well-monitored areas reduces the chances of using machines that have been compromised.
A threat that will continue to evolve
The case in the United States is yet another reminder that organized crime is now systematically investing in technology. The ATM Jackpotting attacks demonstrate that cybercriminals are not limited to stealing data, but are now targeting critical financial infrastructure for immediate financial gain.
As malicious tools become increasingly sophisticated and accessible, strengthening cybersecurity in banking networks is the only way forward. Collaboration between banks, ATM manufacturers, cybersecurity companies and law enforcement agencies will be crucial to ensure that these types of attacks are detected early and prevented before they cause further financial losses.
