World News 8 min read

The $40.73 Million ATM Attack Network Targeting American Banks

National Security & Finance • October 1, 2026

The $40.73 Million ATM Attack Network Targeting American Banks

Treasury says a Tren de Aragua-linked network used malware, international crews, cryptocurrency, and front companies to turn cash machines into a source of criminal revenue. The lesson reaches far beyond one gang.

Executive Takeaways

  • On September 30, the Treasury Department sanctioned ten targets tied to an alleged Tren de Aragua ATM-jackpotting and money-laundering network.
  • Treasury reported $40.73 million in U.S. losses across more than 1,500 alleged jackpotting attacks as of August 2025.
  • Since October 21, 2025, the Justice Department has indicted 98 people for alleged roles in ATM-jackpotting schemes.
  • The operation combined physical access to machines, remotely activated malware, cash crews, cryptocurrency transfers, and cross-border financial facilitators.
  • For banks, retailers, and ATM operators, the strategic issue is layered defense: physical security, software integrity, cash-dispense monitoring, rapid incident response, and financial tracing must work together.

Main Analysis

What Treasury Announced

The U.S. Treasury Department’s Office of Foreign Assets Control, or OFAC, designated ten people and companies on September 30 in connection with a fraud scheme that Treasury describes as a key revenue source for Tren de Aragua. The action names individuals in Venezuela and Mexico, two Mexico-based companies, and a high-ranking Tren de Aragua figure associated with illicit gold mining and other criminal activity.

Treasury identifies Anibal Alexander Canelon Aguirre, known as “Prometheus,” as the alleged organizer and engineer of malware used in ATM-jackpotting attacks. He is also listed by the FBI among its Ten Most Wanted fugitives. The department says associates helped deploy crews, steal cash from U.S. financial institutions, and move proceeds through cryptocurrency and other channels.

The sanctions action does not decide criminal guilt. Several people named by Treasury have been indicted, and an indictment is an allegation that must be proven in court. OFAC designations operate under separate executive authorities and impose blocking consequences. Keeping those legal categories distinct is essential to accurate reporting.

How Jackpotting Works—Without the Hype

ATM jackpotting is a cyber-enabled cash theft. Treasury’s public description says facilitators first survey potential machines, then obtain physical access and install malware. The software can be activated remotely to bypass normal controls and command the machine to dispense cash until it is empty or the operation is interrupted. Other participants collect the cash and move it through the network.

The important point is not a technical trick. It is the combination of domains. A successful attack can require physical intrusion, software compromise, remote coordination, money pickup, laundering, and international transfers. A bank that treats the event only as vandalism may miss the cyber indicator. A security team that treats it only as malware may miss the cash crew, surveillance pattern, or financial network.

Treasury says the alleged proceeds were transferred among members and associates to conceal their origin, including through cryptocurrency. Cryptocurrency does not make funds invisible. Public ledgers can preserve transaction trails, but attribution can be difficult when criminals use multiple wallets, intermediaries, exchanges, cash conversion, and false identities. Investigators therefore combine blockchain analysis with bank records, device evidence, travel data, corporate ownership, and human intelligence.

An ATM attack begins at one machine, but the defense succeeds only when physical security, cyber telemetry, cash controls, and financial intelligence become one system.

The Numbers and What They Mean

Treasury reports $40.73 million in U.S. losses across more than 1,500 alleged jackpotting attacks as of August 2025. That averages roughly $27,000 per reported attack, but the average should not be mistaken for a standard loss. Individual events can vary by machine capacity, response time, location, and whether a crew is interrupted.

The department also says DOJ has indicted 98 individuals since October 21, 2025. Treasury’s September 30 action is narrower: ten designated targets. Those figures measure different things. One counts alleged attacks and losses, one counts criminal defendants across cases, and one counts the targets in a specific sanctions action.

Treasury further states that the administration has taken more than 30 actions against over 300 people and entities linked to transnational criminal organizations since 2025. That broader enforcement count shows the scale of the campaign, but it does not by itself measure deterrence. The decisive metrics are lower losses, disrupted crews, frozen funds, successful prosecutions, safer machines, and reduced ability to rebuild.

Why Sanctions Are Part of a Bank-Security Case

OFAC used Executive Order 13581, as amended, which targets significant transnational criminal organizations and their supporters, and Executive Order 13224, as amended, which targets terrorists and their supporters. Tren de Aragua had previously been sanctioned as a transnational criminal organization and identified by the State Department as a Foreign Terrorist Organization.

As a result of the new action, covered property and interests in property in the United States or under U.S. persons’ possession or control must be blocked and reported. Entities owned 50 percent or more, directly or indirectly and in aggregate, by blocked persons are also blocked. That means compliance teams must investigate ownership rather than rely only on exact-name screening.

Sanctions can restrict access to banks, exchanges, businesses, and cross-border payment channels. Criminal cases can imprison convicted participants. Cybersecurity measures can harden the machines. Asset tracing can expose wallets and front companies. Each tool addresses a different part of the same system.

Confirmed Facts Versus RedWaveBrief Analysis

Confirmed by official records: Treasury designated ten targets; it reported $40.73 million in losses across more than 1,500 attacks as of August 2025; DOJ has indicted 98 people since October 2025; and the OFAC notice identifies several digital-currency addresses associated with designated individuals.

RedWaveBrief analysis: the threat is best understood as an operational supply chain for theft. Malware is one input. Physical access, cash collection, identity cover, transportation, companies, wallets, exchanges, and leadership are others. A defense that breaks several links at once is more likely to impose lasting cost than a single control applied after an ATM is emptied.

There is also a practical warning against overgeneralization. Treasury identified specific people, companies, and addresses. It did not say that ordinary Venezuelan or Mexican businesses, migrants, or cryptocurrency users are suspicious. Risk decisions should follow evidence, behavior, ownership, and transaction context—not nationality.

Three Conditional Scenarios

Base case: banks and ATM operators strengthen monitoring, law enforcement continues arrests and sanctions, and the named network loses familiar channels. Attackers adapt, but operating costs and detection risk rise.

Upside case: investigators combine cash-machine telemetry, physical evidence, wallet tracing, travel records, and beneficial ownership to identify entire crews before attacks occur. Exchanges and foreign partners freeze proceeds, and reported losses fall materially.

Downside case: criminal groups recruit new cash crews, rotate wallets and companies, target older machines, and exploit fragmented reporting. Institutions patch visible weaknesses without integrating cyber, fraud, sanctions, and physical-security teams, allowing the model to persist.

What It Means for Banks, Businesses, and Households

Banks and ATM operators should inventory machine models, software versions, remote-access pathways, service vendors, cash thresholds, and physical locations. Alerts should connect unusual dispense commands, cabinet access, device restarts, service-mode activity, and nearby surveillance. High-risk events should reach cyber, fraud, physical security, and law enforcement at the same time.

Retailers and independent ATM hosts should know who services each machine and verify unexpected maintenance visits. Staff should not attempt to confront suspected criminals. They should follow safety procedures, preserve video and logs, contact the operator, and notify law enforcement when appropriate.

Households generally are not directly liable when a machine is forced to dispense bank cash without debiting a customer account. Still, consumers should avoid damaged or tampered machines, shield PIN entry, use transaction alerts, and report unexpected account activity promptly. Those basic habits address more common forms of ATM fraud even though jackpotting itself targets the machine’s cash.

Investors should focus on operational resilience rather than sensational headlines. Relevant questions include the age of an institution’s ATM fleet, outsourcing arrangements, cyber and physical controls, insurance coverage, incident disclosures, and whether fraud, sanctions, and security data are integrated.

What to Watch

  • Additional indictments, arrests, extraditions, wallet identifications, or front-company designations.
  • Whether reported U.S. jackpotting losses decline after machine hardening and coordinated enforcement.
  • Financial institutions’ adoption of real-time dispense anomaly detection and stronger service-vendor controls.
  • Foreign cooperation in Mexico, Venezuela, and other jurisdictions used for leadership, laundering, or company ownership.
  • Court outcomes, which will test the criminal allegations separately from the sanctions record.

Action Checklist

  • Banks: connect ATM telemetry with fraud, cyber, sanctions, and physical-security workflows.
  • ATM operators: patch supported systems, restrict remote access, and verify service technicians.
  • Retailers: preserve camera coverage and escalate unexplained cabinet access or maintenance.
  • Consumers: avoid visibly damaged machines and enable account alerts.
  • Investors: ask about fleet age, vendor oversight, loss trends, and incident-response integration.

Choose Our Next Deep Dive

Vote for the next RedWaveBrief analysis: ATM fleet security, cryptocurrency tracing, the OFAC 50 Percent Rule, or front-company ownership.

Ask the Analyst

Send the bank-security, sanctions, cyber-fraud, or cryptocurrency question you want us to investigate next.

Sources & Methodology

  • U.S. Treasury — Tren de Aragua financial-network sanctions and ATM-jackpotting findings
  • OFAC — September 30 SDN list updates and digital-currency identifiers
  • U.S. Department of Justice — ATM-jackpotting charges and investigative findings

We treated Treasury and OFAC as the primary sources for the sanctions action, named targets, loss total, attack count, and legal consequences. Criminal charges are described as allegations, not convictions. The approximate per-attack figure is a simple calculation using Treasury’s aggregate numbers. Operational recommendations and scenarios are RedWaveBrief analysis. Accessed October 1, 2026.

Read Also

Treasury Targets the Supply Chains Behind Iran’s Missiles and Drones

14k Active Readers
68+ Countries
47% Open Rate
×2 Per Week

“RedWaveBrief cuts through the performative outrage of mainstream political media. Every issue reads like a classified analyst’s memo — dense, sharp, no wasted words.”

— D.K., Senior Policy Advisor Washington D.C. · Subscriber since Issue #001

Free · Twice a Week · No Spam

Clarity in a World
Engineered for Confusion

14,000 analysts, advisors, and decision-makers read RedWaveBrief every Tuesday and Friday. Dense. Actionable. No noise.