Description

Five Venezuelan nationals have pleaded guilty in the United States after attempting to compromise ATMs in Kansas using jackpotting techniques. The incidents occurred in Wamego and Manhattan in December 2025, where the suspects allegedly targeted ATMs with the intention of making them dispense cash without authorized transactions. Both attempts were unsuccessful, but the investigation demonstrates how cybercriminal groups are increasingly combining physical access with malware to target financial infrastructure. The attacks relied on direct access to ATM hardware, followed by the installation of malicious software designed to interfere with the machine's cash-dispensing functions. Investigators said one member of the group was involved in physically accessing the machines while other participants were prepared to control the malware remotely. The first attempt reportedly triggered an alarm during the installation process, while the second operation also failed to produce a cash payout. Authorities subsequently used surveillance footage and other investigative evidence to identify the suspects. Unlike traditional card-skimming attacks, jackpotting directly targets an ATM's software or operational controls to force unauthorized cash withdrawals. The case highlights the need for financial institutions to strengthen both the physical and software security of ATMs. Organizations should restrict access to internal ATM components, deploy application controls to prevent unauthorized software execution, maintain updated firmware and operating systems, and monitor machines for unexpected software or hardware modifications. Additional safeguards such as continuous transaction monitoring, tamper detection, effective surveillance, and rapid incident-response procedures can help detect and contain jackpotting attempts before attackers can obtain cash.