Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

US Charges 31 More Defendants in Massive ATM Hacking Probe

A total of 87 individuals, mostly Venezuelan nationals, have been charged for their role in the ATM jackpotting scheme.

ATM jackpotting

The US Justice Department has announced charges against an additional 31 individuals accused of being involved in a massive ATM jackpotting scheme that resulted in the theft of millions of dollars.

The latest round of charges brings the total number of individuals targeted in this ATM hacking probe to 87. 

The suspects are mostly Venezuelan nationals, including members of the Tren de Aragua crime syndicate, but Colombian nationals have also been targeted in the new indictment. 

The defendants face an array of charges, including conspiracy to commit bank fraud and burglary, as well as substantive counts of computer fraud and intentional damage to protected systems.

According to the DoJ, the criminal network used the Ploutus malware to bypass security systems and issue unauthorized commands to an ATM’s cash dispensing module, forcing the machine to eject currency. 

Deployment of the malware involved physical tampering, where operators gained internal access to either swap the machine’s hard drive with a pre-loaded version or infect it via an external USB device. 

Advertisement. Scroll to continue reading.

Once the ‘jackpotting’ was complete, the malware autonomously deleted traces of its own code to deceive forensic investigators and bank employees.

The Ploutus malware has been around for more than a decade, and while it hasn’t been in the news much since its peak in 2017 and 2018, it hasn’t disappeared.

Public alerts for Ploutus largely dropped off after 2022, but DoJ records confirm the malware remained in active use until at least last year.    

The DoJ announced recently that two Venezuelan nationals convicted over their role in the ATM hacking scheme will be deported. Ultimately, all individuals charged in the investigation face deportation.

Related: 574 Arrested, $3 Million Seized in Crackdown on African Cybercrime Rings

Related: Former Accenture Employee Charged Over Cybersecurity Fraud

Related: SIM Farm Dismantled in Europe, Seven Arrested

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

With "Shadow AI" usage becoming prevalent in organizations, learn how to balance the need for rapid experimentation with the rigorous controls required for enterprise-grade deployment.

Register

Delve into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization.

Register

People on the Move

Neill Feather has been named Chief Executive Officer at Point Wild.

Oasis Security has appointed Michael DeCesare as President.

Sterling Wilson has joined IGEL as Global Field CTO, Business Continuity and Disaster Recovery.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.