The US Treasury Department has taken a significant step in combating ATM jackpotting attacks by blacklisting the alleged developer of the malware used in these crimes and his network. Anibal Alexander Canelon Aguirre, known as ‘Prometheus’, was added to the FBI’s Ten Most Wanted Fugitives list earlier this year for his role in creating the Ploutus malware that enables hackers to drain cash from ATMs.
Canelon Aguirre’s network is based in Mexico and Venezuela but targets ATMs in the United States, with the stolen cash being laundered through various means, including cryptocurrency. The Treasury Department describes the typical process of an ATM jackpotting attack as follows: after surveillance of potential victim ATMs, hackers break in and install malware, which is then activated remotely to bypass security systems and force the ATM to dispense its currency until it runs out of cash.
The scope of the attacks is staggering, with reported losses across the US totaling over $40 million from more than 1,500 incidents as of August 2025. The Treasury Department’s Office of Foreign Assets Control (OFAC) has designated Prometheus and seven of his alleged associates, all of whom have been indicted in Nebraska on charges including providing material support to TdA, bank fraud conspiracy, bank burglary conspiracy, and money laundering conspiracy.
The designations also include seven TRON cryptocurrency addresses linked to Prometheus and six of his associates, which have now been blocked by the US government. This move not only affects individuals but also foreign financial institutions that conduct significant transactions on behalf of these blacklisted entities, who risk facing secondary sanctions if they fail to comply. The Justice Department has already indicted 119 people in connection with the ATM jackpotting conspiracy, and several defendants have received prison sentences, including Venezuelan nationals Oddry Arnoldo Cabrera Torrealba and Carlos Javier Padron.
The Treasury’s actions are a significant blow to the TdA network and its associates, who will now face severe consequences for their crimes. The move also sends a strong message to other cybercriminals that the US government is committed to holding them accountable for their actions. As we continue to see the rise of ATM jackpotting attacks, it’s essential for financial institutions and consumers to remain vigilant and take proactive steps to prevent these types of incidents from occurring.
In light of this development, it’s crucial for individuals and businesses to be aware of the risks associated with ATM jackpotting and take necessary precautions. This includes monitoring accounts regularly, reporting suspicious activity to authorities, and ensuring that ATMs are properly secured with up-to-date security measures in place. By staying informed and taking proactive steps, we can all play a role in preventing these types of crimes from occurring.
Source: SecurityWeek — 2026-10-01