US prosecutors unsealed a federal grand jury indictment charging 31 additional defendants for allegedly participating in an ATM “jackpotting” conspiracy that used Ploutus malware to force ATMs to dispense cash until empty. Court filings and DOJ statements describe a hands-on tradecraft: crews surveilled target ATMs, opened housings to test alarm response, then either swapped hard drives with preloaded ones or used USB devices to deploy the malware; the tooling also supported evidence deletion to hinder investigations. Authorities allege the operation stole at least $5.4 million from 63 ATMs (many at credit unions) over a period spanning Feb 2024–Dec 2025, with proceeds split and moved among participants to facilitate laundering.
The DOJ and reporting link parts of the conspiracy to Tren de Aragua (TdA), a Venezuelan transnational criminal organization that the US Treasury’s OFAC designated as a Foreign Terrorist Organization (per the cited coverage), and the latest indictment follows earlier rounds of charges against dozens of suspects for related conduct (including bank fraud, bank burglary, computer fraud, and damage to computers). Separate reporting in this set covers unrelated law-enforcement actions involving an alleged hitman-for-hire website in Romania and arrests in the Netherlands tied to a $1.6M NFT theft; those cases do not appear connected to the Ploutus ATM malware conspiracy.

See the reporting duties and controls this puts on the clock.
8 events from the most recent confirmed update back to the earliest known activity.
South Carolina prosecutors announced that two Venezuelan nationals convicted in a similar ATM jackpotting scheme will be deported after serving their sentences.
The U.S. Department of Justice announced a new federal grand jury indictment charging 31 additional people in the ATM jackpotting conspiracy, bringing total charges in the operation to 87 people over roughly six months.
DOJ alleges the conspiracy stole at least $5.4 million from at least 63 ATMs, mostly owned by credit unions, during attacks conducted from February 2024 through December 2025.
Federal prosecutors brought another round of charges against 22 additional individuals linked to the ATM malware operation.
The U.S. Treasury's OFAC designated Tren de Aragua as a Foreign Terrorist Organization, a move later cited by DOJ in describing the ATM thefts as supporting TdA activity.
An earlier federal indictment was returned against 32 defendants tied to the Ploutus-based ATM jackpotting conspiracy.
According to DOJ allegations, the conspiracy began attacking U.S. ATMs in February 2024, using surveillance and alarm-response testing before deploying Ploutus malware.
Symantec first detected the Ploutus ATM malware, which would later be used in jackpotting attacks that spread beyond Mexico to multiple ATM vendors.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcebleepingcomputer.com
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.