Table of Contents
An ATM jackpotting malware operation tied to the Venezuelan gang Tren de Aragua has produced two more federal prison sentences, the Justice Department said. Carlos Javier Padron, 36, was sentenced on June 25, 2026 to 78 months, and co-defendant Oddry Arnoldo Cabrera Torrealba, 37, received the same term on June 11.
Both men, Venezuelan nationals in the United States illegally, admitted deploying malware that forced bank ATMs to spit out their cash. Police in Lincoln, Nebraska arrested the pair at a jackpotting site in October 2024.
The case, run out of the District of Nebraska, has since expanded to dozens of co-defendants and become a centerpiece of the government’s effort to choke off funding for Tren de Aragua.
ATM Jackpotting Malware: Key Takeaway
- Two Venezuelan nationals each drew 78 month sentences and owe $1,537,696 in restitution for a Tren de Aragua ATM jackpotting scheme built on Ploutus malware.
This section contains affiliate links; we may earn a commission at no cost to you.
- Auvik: network monitoring and management that gives teams visibility into every device on a fleet, including remote endpoints like ATMs and branch hardware.
- Tenable: vulnerability management to find and prioritize the outdated software and exposed systems that jackpotting crews look for first.
- CyberUpgrade: cybersecurity compliance and management aimed at organizations, including financial institutions, that need to prove and improve their security posture.
- IDrive: cloud backup and recovery so that when malware tampers with a system, clean data and images are ready to restore.
What Happened
Padron and Torrealba were part of what prosecutors describe as a sophisticated criminal network responsible for ATM jackpottings across the country.
According to court documents, the group developed and deployed a variant of malware known as Ploutus, installed it on ATMs, and used it to trigger unauthorized cash withdrawals.
The pair’s specific job was hands on. The conspiracy relied on people like them to physically load the Ploutus malware onto machines in person.
Once installed and activated, the malware let co-conspirators send commands to the ATM’s cash dispensing module and force the hardware to release currency.
Torrealba also operated under an alias, “Luis Alejandro Berdugo Barraza,” according to the Justice Department.
Both defendants pleaded guilty to one count of conspiracy to commit bank burglary and one count of computer fraud and intentional damage to a protected computer. At sentencing, the court ordered them to jointly pay $1,537,696 in restitution to the multiple banks they victimized.
Who Is Affected
The direct victims were the banks whose ATMs were drained. The Justice Department stressed that jackpotting pulls cash from the machine’s own reserves, so the losses land on financial institutions rather than on individual customer accounts.
That distinction matters for the public. Officials framed the sentences partly as reassurance that consumers’ bank balances were not the target, even as the institutions themselves absorbed real losses.
The wider set of victims, in the government’s telling, includes the communities that Tren de Aragua operates in. Prosecutors argue the stolen money funds the gang’s violent activities, which extends the harm well beyond the balance sheets of the affected banks.
What Is ATM Jackpotting
ATM jackpotting is an attack that forces a cash machine to dispense all of its stored money on command, without a real card, account, or bank authorization behind the transaction. The name comes from the image of a slot machine paying out a jackpot.
The technique is not new. The late security researcher Barnaby Jack publicly demonstrated ATM jackpotting at the Black Hat conference in 2010, which drew lasting attention to how exposed these machines can be.
According to security vendor TechTarget’s analysis, the first such attacks reported in the United States surfaced years later, after the method spread from other regions.
Most ATMs run on Windows and commodity hardware. That keeps them cheap to build and manage, but it also lowers the barrier for attackers who know how to manipulate the software that controls the cash dispenser.
How Ploutus Works
Ploutus is a family of ATM malware first identified in 2013, originally in Mexico. Security researchers, including those cited in a public writeup by the New Jersey Cybersecurity and Communications Integration Cell, have tracked several variants over the years, the best known being Ploutus-D.
The malware targets the software layer that tells an ATM’s hardware what to do, known as XFS (short for eXtensions for Financial Services). In a normal withdrawal, the ATM application sends instructions through XFS and waits for the bank to authorize the transaction.
Ploutus lets an attacker supply their own commands to that layer, so the machine dispenses cash while skipping the bank’s approval entirely.
Getting the malware onto a machine requires physical access. Crews typically open the top section of the ATM, then either connect a device such as a USB drive or swap the internal hard drive for one already loaded with the malicious program.
In many versions, a temporary activation code or an attached keyboard triggers the payout.
Ploutus is also built to cover its tracks. In this case, the Justice Department noted the malware was designed to delete evidence of its own existence so that banks would have a harder time detecting that a machine had been compromised.
Background: The Nebraska Investigation
The arrests of Padron and Torrealba in October 2024 became the seed of a much larger federal case. Following the two arrests, investigators mapped a network of co-conspirators across the United States and abroad.
Since then, 96 other defendants have been indicted for related offenses, according to the Justice Department. The charges across the network include material support to a designated foreign terrorist organization, bank burglary, money laundering, bank fraud, and damage and unauthorized access to protected computers, along with conspiracies to commit those crimes.
Earlier public filings in the same investigation charted the growth of the case. A District of Nebraska announcement in January 2026 described dozens of defendants charged as the grand jury returned additional indictments, underscoring how quickly the roster expanded after the initial two arrests.
The Tren de Aragua Connection
The investigation established what prosecutors call extensive direct and indirect links between the charged co-conspirators and Tren de Aragua, often shortened to TdA.
According to court documents, TdA began as a prison gang in Venezuela in the mid-2000s and has since spread across the Western Hemisphere, including into the United States.
The organization’s listed criminal activities are broad: drug and firearms trafficking, commercial sex trafficking, kidnapping, robbery, theft, fraud, and extortion, alongside murder and assault used to advance those operations.
The government’s central claim in this case is financial. Prosecutors say TdA added ATM jackpotting as a revenue stream aimed at financial institutions, using it to steal millions of dollars in cash to fund the gang’s wider operations.
Official Statements
Justice Department officials tied the sentences directly to national security, not just bank losses. Assistant Attorney General A. Tysen Duva of the Criminal Division said the two men helped deploy sophisticated malware for a transnational network that hacked ATMs and stole millions, and that crimes like this undermine financial institutions and fuel violent organizations such as TdA. He said the investigation had disrupted the network at all levels.
U.S. Attorney Lesley Woods for the District of Nebraska used blunter language, calling jackpotting TdA’s assessed primary source of revenue for its activities. She said prosecutors would use the cases to put a chokehold on the group’s funding pipeline.
FBI officials framed the effort as an ongoing fight. Special Agent in Charge Eugene Kowel of the FBI Omaha Field Office described TdA as a violent terrorist organization that relies on varied criminal activity for revenue, and said the bureau would keep adapting as the gang changes tactics.
Homeland Security Investigations echoed the theme. Acting Special Agent in Charge Rick Sabatini of HSI Kansas City called the scheme both an attack on the American financial system and an effort to fund further violence, while crediting agents and partners with the result.
Implications of the ATM Jackpotting Crackdown
The sentences close one chapter of a sprawling case, but the details point to lessons that reach well beyond two defendants. The impact spans physical security, technology, and the economics of organized crime.
The Physical Security Gap
Ploutus depends on physical access, which reframes ATM defense as a building security problem as much as a software one. A machine in a poorly monitored location is a machine an attacker can open, tamper with, and infect in minutes.
Banks and credit unions that treat ATMs as sealed appliances are working from a false assumption. Tamper alarms, camera coverage, upgraded locks, and routine physical inspections are not optional extras here, they are the first line of defense against the initial compromise.
The Legacy Software Problem
The reliance on Windows and standard components keeps ATMs affordable, but aging or unpatched systems widen the attack surface. Reporting on the broader campaign has repeatedly pointed to older machines as favored targets.
For operators, the takeaway is uncomfortable but clear. Fleets running end of life operating systems or outdated middleware carry risk that patching alone cannot fully close, which raises hard questions about refresh cycles and hardening budgets.
Detection After the Fact
Because Ploutus deletes evidence of itself, financial institutions cannot assume a clean log means a clean machine. Anti-forensic behavior is designed precisely to defeat routine review.
That pushes defenders toward continuous monitoring, integrity checks on known good system images, and alerting on physical events like an opened cabinet or a newly attached USB device. The goal is to catch staging and tampering before cash walks out the door, not to reconstruct it afterward.
Following the Money
The prosecution’s strategy is notable for treating a technical crime as a financing case. By charging material support to a foreign terrorist organization alongside computer and bank offenses, prosecutors link ATM losses to a national security objective.
That framing signals how the government intends to pursue similar networks: disrupt the revenue, and you degrade the organization behind it. For financial institutions, it also means an ATM breach may now sit inside a far larger federal investigation than the dollar figure alone would suggest.
Wrapping Up
The 78 month sentences handed to Carlos Javier Padron and Oddry Arnoldo Cabrera Torrealba mark a concrete result in a case that keeps growing. Both men pleaded guilty, both owe more than $1.5 million in shared restitution, and both were part of a network the government links to Tren de Aragua.
The technical core of the scheme, the Ploutus malware and the jackpotting method it enables, is well understood and preventable with the right mix of physical and digital controls. The persistent risk comes from machines that are old, exposed, or lightly monitored.
For banks, credit unions, and the agencies pursuing these cases, the message is consistent. Jackpotting is both a security failure and a funding stream for violent crime, and closing it takes attention to the ATM cabinet and the code inside it at the same time.
This section contains affiliate links; we may earn a commission at no cost to you.
- Auvik: keep continuous eyes on distributed devices and spot anomalies across a network fast.
- Tenable: identify unpatched and end of life systems before attackers can exploit them.
- CyberUpgrade: manage security posture and compliance in one place, useful for regulated financial teams.
- IDrive: maintain reliable backups so tampered systems can be restored to a clean state.
- Tresorit: keep sensitive investigation and incident records in encrypted cloud storage.
Conclusion
Standing back, this case shows the collision of two very different threats. On one side is a low tech entry point, someone with a key and a thumb drive at a cash machine. On the other is a transnational organization that turns those small physical breaches into millions of dollars.
The prison terms, the restitution order, and the wave of related indictments together signal a coordinated federal push, tying ATM security to a broader campaign against Tren de Aragua’s finances.
The lasting lesson for defenders is simple. Treat every ATM as both a computer and a vault, watch the cabinet and the code, and assume that determined crews will keep probing for the machine that no one is watching.
Questions Worth Answering
What is ATM jackpotting?
- It is an attack that uses malware or hardware to force an ATM to dispense all of its stored cash without a valid card, account, or bank authorization.
Who was sentenced in this case?
- Carlos Javier Padron, 36, and Oddry Arnoldo Cabrera Torrealba, 37, both Venezuelan nationals in the United States illegally, each received 78 months in federal prison.
How much restitution do they owe?
- The court ordered the two men to jointly pay $1,537,696 in restitution to the multiple victim banks.
What malware did they use?
- They deployed a variant of Ploutus, an ATM malware family first seen in 2013 that manipulates the ATM’s cash dispensing controls to force unauthorized withdrawals.
How does Ploutus force an ATM to dispense cash?
- It targets the XFS software layer that controls ATM hardware, letting attackers issue their own commands to the cash dispenser and skip the bank’s normal authorization step.
Were customer bank accounts affected?
- No. According to prosecutors, the stolen cash came from the banks’ own ATM reserves rather than from individual customer accounts.
What is Tren de Aragua’s role?
- Prosecutors say the network is linked to Tren de Aragua, a Venezuelan gang designated a foreign terrorist organization, and that jackpotting served as a revenue source for the group.
How large is the overall investigation?
- After the two initial arrests in October 2024, an additional 96 defendants were indicted for related offenses across the United States and abroad.
What charges did the two men plead guilty to?
- Each pleaded guilty to one count of conspiracy to commit bank burglary and one count of computer fraud and intentional damage to a protected computer.
How can banks defend against jackpotting?
- Defenses combine physical measures such as tamper alarms, cameras, upgraded locks, and inspections with technical controls like continuous monitoring, system integrity checks, and prompt patching of aging ATM software.