US Charges 87 in ATM Jackpotting Conspiracy Linked to Venezuelan Crime Syndicate
Summary
Hide ▲
Show ▼
The US has charged 87 individuals in a conspiracy involving ATM jackpotting fraud, linked to the Venezuelan crime syndicate Tren de Aragua. The defendants allegedly used Ploutus malware to hack ATMs, causing $40.73 million in losses by August 2025. The conspiracy involved surveillance, malware deployment, and money laundering to fund further criminal activities. In July 2025, the U.S. government sanctioned key members of Tren de Aragua, including Hector Rusthenford Guerrero Flores, for their involvement in various criminal activities. Two Venezuelan nationals, Luz Granados and Johan Gonzalez-Jimenez, were convicted of stealing hundreds of thousands of dollars from U.S. banks using ATM jackpotting and will be deported after serving their sentences. The FBI reported 1,900 ATM jackpotting incidents since 2020, with 700 occurring in 2025, and losses of more than $20 million in 2025 due to these incidents.
Timeline
-
20.02.2026 12:08 1 articles · 12h ago
FBI Warns of $20 Million in ATM Jackpotting Losses in 2025
The FBI warned that Americans lost more than $20 million last year amid a massive surge in ATM "jackpotting" attacks, in which criminals use malware to force cash machines to dispense money. According to a Thursday FBI flash alert, more than 700 ATM jackpotting incidents were reported last year alone in a significant spike compared to the roughly 1,900 total incidents reported across the United States since 2020. These attacks can be carried out in minutes and target the software layer controlling an ATM's physical hardware, using malicious tools such as the Ploutus malware. Most often, they go undetected by financial institutions and ATM operators until the cash is already gone.
Show sources
- FBI: Over $20 million stolen in surge of ATM malware attacks in 2025 — www.bleepingcomputer.com — 20.02.2026 12:08
-
20.02.2026 10:05 2 articles · 14h ago
FBI Reports 1,900 ATM Jackpotting Incidents Since 2020
The FBI reported 1,900 ATM jackpotting incidents since 2020, with 700 occurring in 2025. Losses in 2025 exceeded $20 million. Cybercriminals exploit physical and software vulnerabilities to deploy malware, often using generic keys to access ATMs. Ploutus malware exploits the eXtensions for Financial Services (XFS) layer to bypass bank authorization. The FBI recommends tightening physical security, auditing devices, changing default credentials, configuring automatic shutdown modes, enforcing device allowlisting, and maintaining logs to mitigate risks.
Show sources
- FBI Reports 1,900 ATM Jackpotting Incidents Since 2020, $20M Lost in 2025 — thehackernews.com — 20.02.2026 10:05
- FBI: Over $20 million stolen in surge of ATM malware attacks in 2025 — www.bleepingcomputer.com — 20.02.2026 12:08
-
27.01.2026 18:27 1 articles · 24d ago
Tren de Aragua Designated as Foreign Terrorist Organization
The U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) designated the Tren de Aragua (TdA) gang as a Foreign Terrorist Organization in December. The gang, which grew from a prison gang to a transnational criminal organization, has been involved in sophisticated malware attacks on ATMs across the United States.
Show sources
- US charges 31 more suspects linked to ATM malware attacks — www.bleepingcomputer.com — 27.01.2026 18:27
-
23.01.2026 18:38 1 articles · 28d ago
Conviction and Deportation of Venezuelan Nationals
Luz Granados and Johan Gonzalez-Jimenez, two Venezuelan nationals, were convicted of stealing hundreds of thousands of dollars from U.S. banks using ATM jackpotting. They were sentenced to 18 months in federal prison and ordered to pay restitution before deportation. The defendants connected laptops to ATMs and installed malware to bypass security protocols, forcing the machines to dispense all available cash. The stolen funds came directly from the banks rather than individual customer accounts, affecting institutions in South Carolina, Georgia, North Carolina, and Virginia.
Show sources
- US to deport Venezuelans who emptied bank ATMs using malware — www.bleepingcomputer.com — 23.01.2026 18:38
-
19.12.2025 13:20 6 articles · 2mo ago
US Charges 54 in ATM Jackpotting Conspiracy
The FBI reported 1,900 ATM jackpotting incidents since 2020, with 700 occurring in 2025. Losses in 2025 exceeded $20 million. Cybercriminals exploit physical and software vulnerabilities to deploy malware, often using generic keys to access ATMs. Ploutus malware exploits the eXtensions for Financial Services (XFS) layer to bypass bank authorization. The FBI recommends tightening physical security, auditing devices, changing default credentials, configuring automatic shutdown modes, enforcing device allowlisting, and maintaining logs to mitigate risks.
Show sources
- US Charges 54 in Massive ATM Jackpotting Conspiracy — www.infosecurity-magazine.com — 19.12.2025 13:20
- U.S. DOJ Charges 54 in ATM Jackpotting Scheme Using Ploutus Malware — thehackernews.com — 20.12.2025 15:48
- US to deport Venezuelans who emptied bank ATMs using malware — www.bleepingcomputer.com — 23.01.2026 18:38
- US charges 31 more suspects linked to ATM malware attacks — www.bleepingcomputer.com — 27.01.2026 18:27
- FBI Reports 1,900 ATM Jackpotting Incidents Since 2020, $20M Lost in 2025 — thehackernews.com — 20.02.2026 10:05
- FBI: Over $20 million stolen in surge of ATM malware attacks in 2025 — www.bleepingcomputer.com — 20.02.2026 12:08
Information Snippets
-
A federal grand jury in Nebraska indicted 22 individuals on December 9 and 32 on October 21 for their roles in the conspiracy.
First reported: 19.12.2025 13:203 sources, 5 articlesShow sources
- US Charges 54 in Massive ATM Jackpotting Conspiracy — www.infosecurity-magazine.com — 19.12.2025 13:20
- U.S. DOJ Charges 54 in ATM Jackpotting Scheme Using Ploutus Malware — thehackernews.com — 20.12.2025 15:48
- US to deport Venezuelans who emptied bank ATMs using malware — www.bleepingcomputer.com — 23.01.2026 18:38
- US charges 31 more suspects linked to ATM malware attacks — www.bleepingcomputer.com — 27.01.2026 18:27
- FBI: Over $20 million stolen in surge of ATM malware attacks in 2025 — www.bleepingcomputer.com — 20.02.2026 12:08
-
If convicted, defendants face imprisonment ranging from 20 to 335 years.
First reported: 19.12.2025 13:203 sources, 4 articlesShow sources
- US Charges 54 in Massive ATM Jackpotting Conspiracy — www.infosecurity-magazine.com — 19.12.2025 13:20
- U.S. DOJ Charges 54 in ATM Jackpotting Scheme Using Ploutus Malware — thehackernews.com — 20.12.2025 15:48
- US charges 31 more suspects linked to ATM malware attacks — www.bleepingcomputer.com — 27.01.2026 18:27
- FBI: Over $20 million stolen in surge of ATM malware attacks in 2025 — www.bleepingcomputer.com — 20.02.2026 12:08
-
Tren de Aragua, a Venezuelan crime syndicate, allegedly used ATM jackpotting to steal millions and launder money.
First reported: 19.12.2025 13:203 sources, 4 articlesShow sources
- US Charges 54 in Massive ATM Jackpotting Conspiracy — www.infosecurity-magazine.com — 19.12.2025 13:20
- U.S. DOJ Charges 54 in ATM Jackpotting Scheme Using Ploutus Malware — thehackernews.com — 20.12.2025 15:48
- US charges 31 more suspects linked to ATM malware attacks — www.bleepingcomputer.com — 27.01.2026 18:27
- FBI: Over $20 million stolen in surge of ATM malware attacks in 2025 — www.bleepingcomputer.com — 20.02.2026 12:08
-
Total losses from the jackpotting incidents reached $40.73 million as of August 2025.
First reported: 19.12.2025 13:203 sources, 6 articlesShow sources
- US Charges 54 in Massive ATM Jackpotting Conspiracy — www.infosecurity-magazine.com — 19.12.2025 13:20
- U.S. DOJ Charges 54 in ATM Jackpotting Scheme Using Ploutus Malware — thehackernews.com — 20.12.2025 15:48
- US to deport Venezuelans who emptied bank ATMs using malware — www.bleepingcomputer.com — 23.01.2026 18:38
- US charges 31 more suspects linked to ATM malware attacks — www.bleepingcomputer.com — 27.01.2026 18:27
- FBI Reports 1,900 ATM Jackpotting Incidents Since 2020, $20M Lost in 2025 — thehackernews.com — 20.02.2026 10:05
- FBI: Over $20 million stolen in surge of ATM malware attacks in 2025 — www.bleepingcomputer.com — 20.02.2026 12:08
-
The conspiracy deployed Ploutus malware, a sophisticated ATM malware family first discovered in Mexico in 2013.
First reported: 19.12.2025 13:203 sources, 4 articlesShow sources
- US Charges 54 in Massive ATM Jackpotting Conspiracy — www.infosecurity-magazine.com — 19.12.2025 13:20
- U.S. DOJ Charges 54 in ATM Jackpotting Scheme Using Ploutus Malware — thehackernews.com — 20.12.2025 15:48
- US to deport Venezuelans who emptied bank ATMs using malware — www.bleepingcomputer.com — 23.01.2026 18:38
- FBI: Over $20 million stolen in surge of ATM malware attacks in 2025 — www.bleepingcomputer.com — 20.02.2026 12:08
-
Ploutus malware was used to force ATMs to dispense cash and obfuscate evidence of the activity.
First reported: 19.12.2025 13:203 sources, 6 articlesShow sources
- US Charges 54 in Massive ATM Jackpotting Conspiracy — www.infosecurity-magazine.com — 19.12.2025 13:20
- U.S. DOJ Charges 54 in ATM Jackpotting Scheme Using Ploutus Malware — thehackernews.com — 20.12.2025 15:48
- US to deport Venezuelans who emptied bank ATMs using malware — www.bleepingcomputer.com — 23.01.2026 18:38
- US charges 31 more suspects linked to ATM malware attacks — www.bleepingcomputer.com — 27.01.2026 18:27
- FBI Reports 1,900 ATM Jackpotting Incidents Since 2020, $20M Lost in 2025 — thehackernews.com — 20.02.2026 10:05
- FBI: Over $20 million stolen in surge of ATM malware attacks in 2025 — www.bleepingcomputer.com — 20.02.2026 12:08
-
The U.S. government sanctioned Hector Rusthenford Guerrero Flores (aka Niño Guerrero) and five other key members of Tren de Aragua in July 2025 for their involvement in various criminal activities.
First reported: 20.12.2025 15:482 sources, 3 articlesShow sources
- U.S. DOJ Charges 54 in ATM Jackpotting Scheme Using Ploutus Malware — thehackernews.com — 20.12.2025 15:48
- FBI Reports 1,900 ATM Jackpotting Incidents Since 2020, $20M Lost in 2025 — thehackernews.com — 20.02.2026 10:05
- FBI: Over $20 million stolen in surge of ATM malware attacks in 2025 — www.bleepingcomputer.com — 20.02.2026 12:08
-
The conspiracy involved methodical surveillance and burglary techniques to install malware into ATMs.
First reported: 20.12.2025 15:482 sources, 4 articlesShow sources
- U.S. DOJ Charges 54 in ATM Jackpotting Scheme Using Ploutus Malware — thehackernews.com — 20.12.2025 15:48
- US to deport Venezuelans who emptied bank ATMs using malware — www.bleepingcomputer.com — 23.01.2026 18:38
- US charges 31 more suspects linked to ATM malware attacks — www.bleepingcomputer.com — 27.01.2026 18:27
- FBI: Over $20 million stolen in surge of ATM malware attacks in 2025 — www.bleepingcomputer.com — 20.02.2026 12:08
-
The Ploutus malware was designed to delete evidence of its deployment to mislead bank employees.
First reported: 20.12.2025 15:482 sources, 4 articlesShow sources
- U.S. DOJ Charges 54 in ATM Jackpotting Scheme Using Ploutus Malware — thehackernews.com — 20.12.2025 15:48
- US to deport Venezuelans who emptied bank ATMs using malware — www.bleepingcomputer.com — 23.01.2026 18:38
- US charges 31 more suspects linked to ATM malware attacks — www.bleepingcomputer.com — 27.01.2026 18:27
- FBI: Over $20 million stolen in surge of ATM malware attacks in 2025 — www.bleepingcomputer.com — 20.02.2026 12:08
-
A total of 1,529 jackpotting incidents have been recorded in the U.S. since 2021, with about $40.73 million lost to the international criminal network as of August 2025.
First reported: 20.12.2025 15:482 sources, 2 articlesShow sources
- U.S. DOJ Charges 54 in ATM Jackpotting Scheme Using Ploutus Malware — thehackernews.com — 20.12.2025 15:48
- FBI: Over $20 million stolen in surge of ATM malware attacks in 2025 — www.bleepingcomputer.com — 20.02.2026 12:08
-
Luz Granados and Johan Gonzalez-Jimenez, two Venezuelan nationals, were convicted of stealing hundreds of thousands of dollars from U.S. banks using ATM jackpotting.
First reported: 23.01.2026 18:381 source, 2 articlesShow sources
- US to deport Venezuelans who emptied bank ATMs using malware — www.bleepingcomputer.com — 23.01.2026 18:38
- FBI: Over $20 million stolen in surge of ATM malware attacks in 2025 — www.bleepingcomputer.com — 20.02.2026 12:08
-
The defendants connected laptops to ATMs and installed malware to bypass security protocols, forcing the machines to dispense all available cash.
First reported: 23.01.2026 18:382 sources, 4 articlesShow sources
- US to deport Venezuelans who emptied bank ATMs using malware — www.bleepingcomputer.com — 23.01.2026 18:38
- US charges 31 more suspects linked to ATM malware attacks — www.bleepingcomputer.com — 27.01.2026 18:27
- FBI Reports 1,900 ATM Jackpotting Incidents Since 2020, $20M Lost in 2025 — thehackernews.com — 20.02.2026 10:05
- FBI: Over $20 million stolen in surge of ATM malware attacks in 2025 — www.bleepingcomputer.com — 20.02.2026 12:08
-
The stolen funds came directly from the banks rather than individual customer accounts, affecting institutions in South Carolina, Georgia, North Carolina, and Virginia.
First reported: 23.01.2026 18:381 source, 3 articlesShow sources
- US to deport Venezuelans who emptied bank ATMs using malware — www.bleepingcomputer.com — 23.01.2026 18:38
- US charges 31 more suspects linked to ATM malware attacks — www.bleepingcomputer.com — 27.01.2026 18:27
- FBI: Over $20 million stolen in surge of ATM malware attacks in 2025 — www.bleepingcomputer.com — 20.02.2026 12:08
-
Johan Gonzalez-Jimenez was sentenced to 18 months in federal prison and ordered to pay $285,100 in restitution before deportation.
First reported: 23.01.2026 18:381 source, 2 articlesShow sources
- US to deport Venezuelans who emptied bank ATMs using malware — www.bleepingcomputer.com — 23.01.2026 18:38
- FBI: Over $20 million stolen in surge of ATM malware attacks in 2025 — www.bleepingcomputer.com — 20.02.2026 12:08
-
Luz Granados was sentenced to time served and ordered to pay $126,340 in restitution before deportation.
First reported: 23.01.2026 18:381 source, 2 articlesShow sources
- US to deport Venezuelans who emptied bank ATMs using malware — www.bleepingcomputer.com — 23.01.2026 18:38
- FBI: Over $20 million stolen in surge of ATM malware attacks in 2025 — www.bleepingcomputer.com — 20.02.2026 12:08
-
Jimena Romina Araya Navarro, an entertainer and alleged leader of the Tren de Aragua Venezuelan gang, was sanctioned by the Department of the Treasury's Office of Foreign Assets Control in December.
First reported: 23.01.2026 18:381 source, 2 articlesShow sources
- US to deport Venezuelans who emptied bank ATMs using malware — www.bleepingcomputer.com — 23.01.2026 18:38
- FBI: Over $20 million stolen in surge of ATM malware attacks in 2025 — www.bleepingcomputer.com — 20.02.2026 12:08
-
A Nebraska federal grand jury charged 31 additional defendants for their involvement in an ATM jackpotting operation allegedly orchestrated by members of the Venezuelan gang Tren de Aragua.
First reported: 27.01.2026 18:271 source, 2 articlesShow sources
- US charges 31 more suspects linked to ATM malware attacks — www.bleepingcomputer.com — 27.01.2026 18:27
- FBI: Over $20 million stolen in surge of ATM malware attacks in 2025 — www.bleepingcomputer.com — 20.02.2026 12:08
-
The latest charges follow two previous indictments: a December 9 one charging 22 individuals with conspiracy to provide material support to terrorists and money laundering, and an October 21 indictment that charged 32 defendants with multiple counts of bank fraud, bank burglary, and damage to computers.
First reported: 27.01.2026 18:271 source, 2 articlesShow sources
- US charges 31 more suspects linked to ATM malware attacks — www.bleepingcomputer.com — 27.01.2026 18:27
- FBI: Over $20 million stolen in surge of ATM malware attacks in 2025 — www.bleepingcomputer.com — 20.02.2026 12:08
-
The Nebraska grand jury returned the latest indictment, alleging 32 counts, stemming from a scheme that used Ploutus malware to steal millions in cash from bank ATMs across the United States.
First reported: 27.01.2026 18:271 source, 2 articlesShow sources
- US charges 31 more suspects linked to ATM malware attacks — www.bleepingcomputer.com — 27.01.2026 18:27
- FBI: Over $20 million stolen in surge of ATM malware attacks in 2025 — www.bleepingcomputer.com — 20.02.2026 12:08
-
Many of the indicted suspects are Venezuelan and Colombian nationals affiliated with the Tren de Aragua (TdA) gang, designated by the U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) in December as a Foreign Terrorist Organization.
First reported: 27.01.2026 18:271 source, 2 articlesShow sources
- US charges 31 more suspects linked to ATM malware attacks — www.bleepingcomputer.com — 27.01.2026 18:27
- FBI: Over $20 million stolen in surge of ATM malware attacks in 2025 — www.bleepingcomputer.com — 20.02.2026 12:08
-
"TdA grew from a prison gang to a transnational criminal organization to a foreign terrorist organization," said Chris Eason, co-director of the Justice Department's Joint Task Force Vulcan. "Using sophisticated malware to empty ATMs and damage U.S. financial institutions that also fund TdA's terrorist activity will not be tolerated."
First reported: 27.01.2026 18:271 source, 2 articlesShow sources
- US charges 31 more suspects linked to ATM malware attacks — www.bleepingcomputer.com — 27.01.2026 18:27
- FBI: Over $20 million stolen in surge of ATM malware attacks in 2025 — www.bleepingcomputer.com — 20.02.2026 12:08
-
According to court documents, the suspects allegedly deployed Ploutus malware on banks and credit union ATMs nationwide after first opening the machines' housings and waiting nearby to detect alarm responses.
First reported: 27.01.2026 18:271 source, 2 articlesShow sources
- US charges 31 more suspects linked to ATM malware attacks — www.bleepingcomputer.com — 27.01.2026 18:27
- FBI: Over $20 million stolen in surge of ATM malware attacks in 2025 — www.bleepingcomputer.com — 20.02.2026 12:08
-
They installed the malware by removing hard drives, replacing them with pre-loaded drives, or connecting thumb drives. Once deployed, the malware allowed them to delete evidence to conceal the attacks and force the ATMs to dispense cash until empty.
First reported: 27.01.2026 18:272 sources, 3 articlesShow sources
- US charges 31 more suspects linked to ATM malware attacks — www.bleepingcomputer.com — 27.01.2026 18:27
- FBI Reports 1,900 ATM Jackpotting Incidents Since 2020, $20M Lost in 2025 — thehackernews.com — 20.02.2026 10:05
- FBI: Over $20 million stolen in surge of ATM malware attacks in 2025 — www.bleepingcomputer.com — 20.02.2026 12:08
-
The stolen money was split according to predetermined arrangements, with funds transferred among the crime ring's members to launder the illegally obtained cash.
First reported: 27.01.2026 18:272 sources, 3 articlesShow sources
- US charges 31 more suspects linked to ATM malware attacks — www.bleepingcomputer.com — 27.01.2026 18:27
- FBI Reports 1,900 ATM Jackpotting Incidents Since 2020, $20M Lost in 2025 — thehackernews.com — 20.02.2026 10:05
- FBI: Over $20 million stolen in surge of ATM malware attacks in 2025 — www.bleepingcomputer.com — 20.02.2026 12:08
-
In total, the Justice Department has charged 87 Tren de Aragua members over the past six months, with the defendants facing maximum prison terms ranging from 20 to 335 years if convicted.
First reported: 27.01.2026 18:271 source, 2 articlesShow sources
- US charges 31 more suspects linked to ATM malware attacks — www.bleepingcomputer.com — 27.01.2026 18:27
- FBI: Over $20 million stolen in surge of ATM malware attacks in 2025 — www.bleepingcomputer.com — 20.02.2026 12:08
-
The FBI reported 1,900 ATM jackpotting incidents since 2020, with 700 occurring in 2025.
First reported: 20.02.2026 10:052 sources, 2 articlesShow sources
- FBI Reports 1,900 ATM Jackpotting Incidents Since 2020, $20M Lost in 2025 — thehackernews.com — 20.02.2026 10:05
- FBI: Over $20 million stolen in surge of ATM malware attacks in 2025 — www.bleepingcomputer.com — 20.02.2026 12:08
-
The FBI reported losses of more than $20 million in 2025 due to ATM jackpotting incidents.
First reported: 20.02.2026 10:052 sources, 2 articlesShow sources
- FBI Reports 1,900 ATM Jackpotting Incidents Since 2020, $20M Lost in 2025 — thehackernews.com — 20.02.2026 10:05
- FBI: Over $20 million stolen in surge of ATM malware attacks in 2025 — www.bleepingcomputer.com — 20.02.2026 12:08
-
Threat actors exploit physical and software vulnerabilities in ATMs to deploy malware.
First reported: 20.02.2026 10:052 sources, 2 articlesShow sources
- FBI Reports 1,900 ATM Jackpotting Incidents Since 2020, $20M Lost in 2025 — thehackernews.com — 20.02.2026 10:05
- FBI: Over $20 million stolen in surge of ATM malware attacks in 2025 — www.bleepingcomputer.com — 20.02.2026 12:08
-
Cybercriminals gain unauthorized access to ATMs by opening the ATM face with widely available generic keys.
First reported: 20.02.2026 10:052 sources, 2 articlesShow sources
- FBI Reports 1,900 ATM Jackpotting Incidents Since 2020, $20M Lost in 2025 — thehackernews.com — 20.02.2026 10:05
- FBI: Over $20 million stolen in surge of ATM malware attacks in 2025 — www.bleepingcomputer.com — 20.02.2026 12:08
-
Ploutus malware exploits the eXtensions for Financial Services (XFS) layer to bypass bank authorization.
First reported: 20.02.2026 10:052 sources, 2 articlesShow sources
- FBI Reports 1,900 ATM Jackpotting Incidents Since 2020, $20M Lost in 2025 — thehackernews.com — 20.02.2026 10:05
- FBI: Over $20 million stolen in surge of ATM malware attacks in 2025 — www.bleepingcomputer.com — 20.02.2026 12:08
-
The FBI recommends tightening physical security, auditing ATM devices, changing default credentials, configuring automatic shutdown modes, enforcing device allowlisting, and maintaining logs to mitigate jackpotting risks.
First reported: 20.02.2026 10:052 sources, 2 articlesShow sources
- FBI Reports 1,900 ATM Jackpotting Incidents Since 2020, $20M Lost in 2025 — thehackernews.com — 20.02.2026 10:05
- FBI: Over $20 million stolen in surge of ATM malware attacks in 2025 — www.bleepingcomputer.com — 20.02.2026 12:08
-
The FBI reported 1,900 ATM jackpotting incidents since 2020, with 700 occurring in 2025.
First reported: 20.02.2026 12:081 source, 1 articleShow sources
- FBI: Over $20 million stolen in surge of ATM malware attacks in 2025 — www.bleepingcomputer.com — 20.02.2026 12:08
-
Losses in 2025 exceeded $20 million.
First reported: 20.02.2026 12:081 source, 1 articleShow sources
- FBI: Over $20 million stolen in surge of ATM malware attacks in 2025 — www.bleepingcomputer.com — 20.02.2026 12:08
-
Cybercriminals exploit physical and software vulnerabilities to deploy malware, often using generic keys to access ATMs.
First reported: 20.02.2026 12:081 source, 1 articleShow sources
- FBI: Over $20 million stolen in surge of ATM malware attacks in 2025 — www.bleepingcomputer.com — 20.02.2026 12:08
-
Ploutus malware exploits the eXtensions for Financial Services (XFS) layer to bypass bank authorization.
First reported: 20.02.2026 12:081 source, 1 articleShow sources
- FBI: Over $20 million stolen in surge of ATM malware attacks in 2025 — www.bleepingcomputer.com — 20.02.2026 12:08
-
The FBI recommends tightening physical security, auditing devices, changing default credentials, configuring automatic shutdown modes, enforcing device allowlisting, and maintaining logs to mitigate risks.
First reported: 20.02.2026 12:081 source, 1 articleShow sources
- FBI: Over $20 million stolen in surge of ATM malware attacks in 2025 — www.bleepingcomputer.com — 20.02.2026 12:08
Similar Happenings
Crazy Ransomware Gang Abuses Employee Monitoring and Remote Support Tools
The Crazy ransomware gang has been observed abusing legitimate employee monitoring software (Net Monitor for Employees Professional) and the SimpleHelp remote support tool to maintain persistence in corporate networks, evade detection, and prepare for ransomware deployment. The attackers used these tools to gain full interactive access to compromised systems, transfer files, execute commands, and monitor system activity in real time. They also attempted to disable Windows Defender and set up monitoring rules to detect cryptocurrency-related activities and remote access tools. The use of multiple remote access tools provided redundancy for the attackers, ensuring they retained access even if one tool was discovered or removed. The breaches were enabled through compromised SSL VPN credentials, highlighting the need for organizations to enforce MFA on all remote access services.
US Seizes E-Note Crypto Exchange for Ransomware Laundering
The U.S. Department of Justice, led by the FBI and collaborating with international partners, has seized the E-Note cryptocurrency exchange for allegedly laundering over $70 million in ransomware and account takeover proceeds. The operation involved confiscating domains, servers, and customer databases, with an indictment unsealed against the Russian national Mykhalio Petrovich Chudnovets, believed to be the operator of E-Note. Chudnovets targeted US healthcare and critical infrastructure sectors through his money laundering services, which he began offering in 2010. This action may lead to further identification of cybercriminals involved in the laundering scheme.
European Authorities Dismantle Ukraine-Based Call Center Fraud Ring
European law enforcement dismantled a fraud network operating call centers in Ukraine that scammed victims across Europe out of over 10 million euros. The operation involved arrests, seizures, and the disruption of multiple call centers employing approximately 100 people. The criminals used various schemes, including impersonating bank employees and police officers, to defraud over 400 known victims. The network operated as a commission-based criminal enterprise, promising bonuses for successful scams. Authorities from the Czech Republic, Latvia, Lithuania, and Ukraine, supported by Eurojust, arrested 12 suspects out of 45 identified. The operation included 72 searches across three Ukrainian cities, leading to the seizure of vehicles, weapons, a polygraph machine, computers, cash, and counterfeit identification documents. The fraud ring used remote access software to steal banking logins and directed victims to transfer funds to 'safe' accounts under their control. Members of the network had different roles, including making scam phone calls, forging official documents, and collecting cash from victims.
Storm-0249 Adopts Advanced Tactics for Ransomware Attacks
Storm-0249, previously known as an initial access broker, has escalated its operations by employing advanced tactics such as domain spoofing, DLL sideloading, and fileless PowerShell execution to facilitate ransomware attacks. These methods allow the threat actor to bypass defenses, infiltrate networks, maintain persistence, and operate undetected. The group has shifted from mass phishing campaigns to more precise attacks, leveraging the trust associated with signed processes for added stealth. The ultimate goal is to obtain persistent access to enterprise networks and monetize them by selling access to ransomware gangs.
FBI Warns of $262M Stolen in Account Takeover Fraud Schemes
Since January 2025, cybercriminals impersonating bank support teams have stolen over $262 million through account takeover (ATO) fraud schemes. The FBI's Internet Crime Complaint Center (IC3) has received over 5,100 complaints, affecting individuals and businesses across various sectors. Criminals gain unauthorized access to online financial accounts using social engineering techniques or fraudulent websites. Once in control, they wire funds to crypto wallets and often change account passwords, making recovery difficult. The FBI advises monitoring financial accounts, using strong passwords, enabling MFA, and avoiding search results for banking websites. Victims are urged to contact their financial institutions immediately and file complaints with the IC3. Recent reports highlight the growing use of AI-powered phishing campaigns, SEO poisoning, and exploitation of e-commerce vulnerabilities, particularly ahead of the holiday season. Additionally, purchase scams and mobile phishing (mishing) sites have seen a significant increase, leveraging trusted brand names to deceive users. The U.S. Justice Department (DoJ) has seized the fraud domain web3adspanels[.]org, which was used to host and manipulate illegally harvested bank login credentials. The scheme targeted 19 victims across the U.S., including two companies in the Northern District of Georgia, with attempted losses of approximately $28 million and actual losses of approximately $14.6 million. The confiscated domain stored the stolen login credentials of thousands of victims and hosted a backend server to facilitate takeover fraud as recently as November 2025. The FBI and Estonian law enforcement collaborated in this seizure, and the domain now displays a law enforcement banner indicating it is under the control of authorities. No arrests have been made yet, but the investigation may reveal clues leading to the operators.