Reported losses from alleged ATM jackpotting attacks in the United States stood at $40.73 million across more than 1,500 attacks as of August 2025, according to the Treasury Department. That tally anchored the September 30 announcement in which Treasury’s Office of Foreign Assets Control sanctioned ten targets tied to a Tren de Aragua fraud scheme built around malware that makes cash machines spit out money.
The figure belongs to the whole American jackpotting problem, and the release says so in plain terms. Treasury did not say the sanctioned crews personally stole every dollar of it, which is the distinction that matters when reading the numbers.
The $40.73 million figure and what Treasury attaches it to
In its September 30 press release, Treasury wrote that “as of August 2025, reported losses from alleged ATM jackpotting attacks in the United States total $40.73 million across over 1,500 attacks.” The sentence describes a national category of crime, with the qualifiers “reported” and “alleged” doing real work. It sits in the release as background for why the operation matters, directly beside the description of the Tren de Aragua scheme.
Some coverage compressed that into a claim about the gang itself. BleepingComputer reported that gang members had stolen $40.73 million from U.S. financial institutions across the attacks, citing OFAC’s estimates. A December 2025 account of a Justice Department indictment, relayed by The Hacker News, likewise put the same sum as lost to an international criminal network across 1,529 incidents since 2021. Treasury’s own wording is the narrower and safer one: losses reported nationwide, with Tren de Aragua named as the organization behind a key scheme within them.
Jackpotting malware and the ATM that pays out on command
Jackpotting means forcing an ATM to dispense cash without debiting any account. Treasury says the scheme at the center of the action relies on malware to do it, and describes Anibal Alexander Canelon Aguirre, known as “Prometheus,” as the alleged engineer of the malware used in the attacks. BleepingComputer’s account names it as Ploutus.
The same coverage describes how the attacks are triggered, with the malware responding to an attached USB keyboard or the machine’s built-in PIN pad. The Justice Department’s earlier charging documents, as summarized by The Hacker News, describe criminals swapping in a hard drive preloaded with Ploutus or connecting a removable thumb drive, and note that the code was built to issue commands to the Cash Dispensing Module and to delete traces of itself.
Ten targets, one separate leader, and seven wallet addresses
Treasury’s opening paragraph says OFAC designated 10 targets involved in the Tren de Aragua fraud scheme, which it calls a key source of revenue for the organization. It adds that the operation is orchestrated by Canelon Aguirre, who sits on the FBI’s list of Ten Most Wanted Fugitives; the FBI’s Ten Most Wanted page carries his name.
The count needs care, because three different numbers circulate. The OFAC recent-actions notice for the day lists 11 entries: nine individuals and two Mexico-based companies, Enigma Community, S. de R.L. de C.V. and Soluciones Integrales Toluca, S.A. de C.V. Treasury’s release treats Juan Gabriel Rivas Nunez, alias “Juancho,” separately. It calls him a high-ranking Tren de Aragua leader directing operations in multiple South American countries, designated in addition to the network. That leaves 10 targets in the scheme itself, made up of eight individuals and the two companies. The eight individuals are the number BleepingComputer reports.
The eight individuals in the network group are Canelon Aguirre, Carlos Javier Martinez Armenta, Alejandro Mejia Castillo, Jose Dario Galeano Bazurto, Eric Gabriel Cardenas Arzola, Oscar Leonardo Martinez Pirona, Anthony Wuiliam Hernandez Guerrero and Aslhy Javier Galeano Basurto. OFAC lists most as Venezuelan, with Martinez Armenta and Mejia Castillo as Mexican and Hernandez Guerrero as Colombian and residing in Mexico.
Bessent’s framing and the TRON wallets Treasury listed
Treasury Secretary Scott Bessent framed the action around the financial system. “President Trump’s administration will not allow terrorist organizations like Tren de Aragua to exploit the U.S. financial system or enrich themselves through theft and other criminal activity targeting American individuals and businesses,” he said in the release. Tren de Aragua is designated a Foreign Terrorist Organization, and the release lists drug trafficking, human trafficking, extortion and murder-for-hire among its activities.
The designations carry secondary sanctions risk under Executive Order 13224, according to OFAC’s notice, which means foreign institutions that deal with those named can face consequences too. BleepingComputer adds that the Treasury also listed seven TRON cryptocurrency addresses on the sanctions list, which it says received roughly $6.1 million in total inflows since March 2022. That is the trail Treasury is trying to close: the cash comes out of the machines, and some of the proceeds move through digital wallets.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview
- The NSA says three phone features should be off whenever you aren’t using them
- Hawaii’s magnitude 6.0 Kona earthquake is now a federal major disaster
- Comcast is shutting down its email service, and Xfinity customers must act to keep it
- Invisible volcanic gas at a California ski resort has killed three ski patrollers