Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

US Sanctions 10 Over ATM Jackpotting Malware Scheme Tied to Tren de Aragua

The U.S. Treasury sanctioned ten actors linked to the Ploutus ATM‑jackpotting malware used by Tren de Aragua, responsible for 1,500 attacks and $40 million in cash loss. The case underscores the need for robust third‑party risk oversight and continuous monitoring to satisfy audit and control‑assurance requirements.

LiveThreat™ Intelligence · 📅 October 01, 2026· 📰 therecord.media
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
3 recommended
📰
Source
therecord.media

US Sanctions 10 Over ATM Jackpotting Malware Scheme Tied to Tren de Aragua

What Happened — The U.S. Treasury’s Office of Foreign Assets Control (OFAC) sanctioned ten individuals and companies linked to the Ploutus ATM‑jackpotting malware used by the Venezuelan criminal group Tren de Aragua. The campaign has been traced to at least 1,500 attacks that drained cash from ATMs, resulting in roughly $40 million in losses.

Why It Matters for Trust & Control Assurance

  • The operation illustrates how malicious code can be introduced into third‑party hardware (ATMs) and leveraged to siphon assets, a scenario continuous control‑assurance programs are built to detect and document.
  • Effective vendor‑risk management and ongoing monitoring of external service providers are essential to prove due‑diligence and maintain a defensible audit trail when illicit activity originates outside the organization.

Who Is Affected – Financial services firms that operate or service ATMs, payment‑network providers, and any organization that outsources critical point‑of‑sale hardware to third parties.

Recommended Actions –

  • Map the incident to your third‑party risk‑management controls and verify that all ATM vendors are covered by a formal due‑diligence program.
  • Deploy continuous monitoring of vendor‑supplied firmware and network traffic for anomalous commands that could indicate jackpotting attempts.
  • Collect and retain evidence of vendor assessments, firmware integrity checks, and incident‑response logs to support audit readiness.

Source: The Record

Technical Notes – The Ploutus malware modifies ATM firmware to issue a “dispense all cash” command after a laptop is physically attached to the machine. The scheme relies on cryptocurrency laundering pipelines that span Mexico, Colombia and other Latin‑American jurisdictions. No specific CVE is associated, but the threat vector is malware installed via physical access.

Source: The Record

📰 Original Source
https://therecord.media/us-sanctions-10-atm-jackpotting-tren-de-aragua ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

Point-in-time vendor reviews miss incidents like this.

Verisq AI Trust Operations replaces the annual questionnaire with continuous third-party monitoring — so vendor exposure becomes audit evidence, not a once-a-year guess.

See how Verisq AI Trust Operations works →