Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
U.S. Treasury Takes Action Against ATM Jackpotting Ring

U.S. Treasury Takes Action Against ATM Jackpotting Ring

Posted on October 2, 2026 By CWS

The U.S. Department of the Treasury has imposed sanctions on a network believed to be responsible for ATM jackpotting incidents across the United States. This network, allegedly linked to the Tren de Aragua gang, has been accused of utilizing malware to empty cash machines, resulting in reported losses totaling $40.7 million from over 1,500 occurrences by August 2025.

Understanding ATM Jackpotting Techniques

ATM jackpotting is a sophisticated method used by criminals to make ATMs dispense cash without debiting a customer’s account. Typically, perpetrators conduct reconnaissance, install malicious software, and remotely trigger cash withdrawals. Recent guilty pleas in ATM jackpotting cases highlight the combination of physical ATM access and software manipulation used in these operations.

In addition to traditional methods, the operation reportedly involved the utilization of cryptocurrency transactions to move illicitly acquired funds. TRM Labs’ analysis, shared with Cyber Security News, revealed that seven sanctioned TRON cryptocurrency addresses had received approximately $6.1 million since March 2022.

Sanctioned Individuals and Entities

On September 30, 2026, sanctions were levied against eight individuals and two companies associated with the alleged scheme. Among those targeted is Anibal Alexander Canelon Aguirre, known as “Prometheus,” identified as the purported mastermind behind the malware used in the heists. He is also listed on the FBI’s Ten Most Wanted Fugitives list for his alleged role in developing the software.

Additional individuals implicated include Eric Gabriel Cardenas Arzola, Jose Dario Galeano Bazurto, Anthony Wuiliam Hernandez Guerrero, Carlos Javier Martinez Armenta, Oscar Leonardo Martinez Pirona, and Alejandro Mejia Castillo. All are connected to specific cryptocurrency addresses. The designated entities, Enigma Community, S. de R.L. de C.V. and Soluciones Integrales Toluca, S.A. de C.V., are linked to the scheme’s operations.

Cryptocurrency’s Role in Financial Crime

TRM Labs’ investigation found that the TRON addresses were hosted at a centralized exchange, with most remaining dormant for several months. The address linked to Cardenas Arzola received around $2.1 million, marking the largest portion of funds. It’s important to note that not all received funds are confirmed proceeds of ATM jackpotting.

Funds from the designated addresses were also transferred to other accounts associated with the Tren de Aragua, which further transferred approximately $35 million to networks allegedly controlled by Jorge Figueira, accused of laundering $1 billion. This highlights a broader pattern of using cryptocurrency exchanges to facilitate illegal financial transactions globally.

The Treasury’s action underscores the importance of financial institutions conducting rigorous assessments of transactions linked to designated individuals or entities. Institutions found to be knowingly facilitating substantial transactions for these parties could face secondary sanctions.

Designated individuals’ assets under U.S. jurisdiction are now blocked, and they face strict reporting obligations to the Office of Foreign Assets Control. This move aims to curb the financial operations of those involved and safeguard the financial system from illicit activities.

Cyber Security News Tags:ATM fraud, Cryptocurrency, Cybercrime, Cybersecurity, financial security, money laundering, OFAC, Treasury sanctions, Tren de Aragua, TRON addresses

Post navigation

Previous Post: Critical FortiMail Vulnerability Demands Immediate Attention
Next Post: AI Agents Target US and Canadian Government Websites

Related Posts

Hackers Weaponized Linux Webcams as Attack Tools to Inject Keystrokes and Launch Attacks Hackers Weaponized Linux Webcams as Attack Tools to Inject Keystrokes and Launch Attacks Cyber Security News
Critical Windows Graphics Vulnerability Lets Hackers Seize Control with a Single Image Critical Windows Graphics Vulnerability Lets Hackers Seize Control with a Single Image Cyber Security News
OpenMatter Joins HOL for Secure AI Standards Development OpenMatter Joins HOL for Secure AI Standards Development Cyber Security News
Top Log Monitoring Tools to Watch in 2026 Top Log Monitoring Tools to Watch in 2026 Cyber Security News
AI Assists in Exploit Development for WAGO PLCs AI Assists in Exploit Development for WAGO PLCs Cyber Security News
GitLab SSRF Vulnerability Exploited: CISA Issues Warning GitLab SSRF Vulnerability Exploited: CISA Issues Warning Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Kiteworks Enhances Security with Major Update Fixing 126 Vulnerabilities
  • AI Agents Target US and Canadian Government Websites
  • U.S. Treasury Takes Action Against ATM Jackpotting Ring
  • Critical FortiMail Vulnerability Demands Immediate Attention
  • Android 17 Enhances Security by Restricting Accessibility Services

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Kiteworks Enhances Security with Major Update Fixing 126 Vulnerabilities
  • AI Agents Target US and Canadian Government Websites
  • U.S. Treasury Takes Action Against ATM Jackpotting Ring
  • Critical FortiMail Vulnerability Demands Immediate Attention
  • Android 17 Enhances Security by Restricting Accessibility Services

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark