Introduction: ATM Jackpotting Attacks — Why It Matters
ATM Jackpotting Attacks have highlighted a growing threat to financial institutions after five Venezuelan nationals pleaded guilty over attempted attacks against ATMs in Kansas. The incidents took place in Wamego and Manhattan in December 2025, where the suspects allegedly attempted to install malware that could force ATMs to dispense cash.
The attacks failed, and no money was dispensed. According to the U.S. Department of Justice, the investigation involved the FBI, surveillance footage and law-enforcement response after an alarm was triggered at the Wamego ATM.
The case is significant because the FBI has recorded about 1,900 ATM jackpotting incidents in the United States since 2020. More than 700 occurred during 2025 alone, resulting in losses exceeding $20 million, according to the FBI’s ATM jackpotting advisory.
What Caused the Kansas ATM Incidents?
ATM jackpotting is a form of financial cybercrime in which attackers attempt to compromise an ATM’s software or connected systems and make the machine dispense cash without a legitimate customer transaction.
In the Kansas case, prosecutors said the group traveled from Indiana and targeted ATMs that they believed had security or design weaknesses, according to the U.S. Department of Justice case announcement. The alleged plan involved physically installing malware and later remotely activating commands that would cause the machines to release cash.
Both attempts were unsuccessful:
- In Wamego, the attempted malware installation triggered an ATM alarm.
- Law enforcement responded, preventing the suspects from completing the operation.
- In Manhattan, the ATM also failed to dispense money.
- Surveillance cameras captured the attempted thefts.
- Investigators used the footage to identify and arrest the suspects several days later.
ATM Jackpotting Attacks: Factual Breakdown
Timeline of Events
The attempted attacks occurred in December 2025 in Wamego and Manhattan, Kansas. The defendants allegedly traveled to the locations intending to compromise ATMs and obtain cash remotely.
The Wamego attempt was interrupted when an alarm alerted authorities. The Manhattan operation also failed to produce cash. The investigation subsequently used surveillance evidence to identify the suspects.
What Systems Were Targeted?
The available case information identifies ATMs and their software as the primary targets. No specific bank customer data or account information was reported as compromised.
The broader FBI warning indicates that jackpotting criminals can exploit physical and software weaknesses in ATMs to deploy malware and control cash-dispensing functions.
Potential Risks & Impact
Financial Risk
ATM jackpotting directly threatens financial institutions because attackers attempt to make machines dispense the institution’s stored cash. Even when an operation fails, organizations can face investigation, system recovery costs and additional security expenses.
The scale of the broader threat is substantial, with more than $20 million in losses reported from over 700 U.S. incidents in 2025.
Business and Reputational Risk
Repeated ATM attacks can undermine customer confidence and create operational disruption. Banks may also need to temporarily inspect, patch or replace affected ATM systems.
Organizations can review similar financial-sector incidents through CyberNexora’s cyber incidents coverage.
Regulatory and Compliance Risk
Financial institutions are expected to maintain appropriate security controls around critical banking infrastructure. A successful ATM compromise could therefore create additional compliance, investigation and reporting concerns depending on the circumstances.
Official Response
The U.S. Department of Justice confirmed that all five defendants pleaded guilty to conspiracy to commit bank larceny. Luis Alberto Velasquez-Artigas received a nine-month prison sentence, while the other defendants were awaiting sentencing as of the August 31, 2026 announcement.
The U.S. Attorney’s Office urged banks and financial institutions to take preventative measures and invest in security updates capable of helping protect ATMs from jackpotting.
The FBI has separately published technical information and defensive guidance concerning the rise in malware-enabled ATM jackpotting incidents.
Industry Context: Why ATM Jackpotting Is Increasing
The Kansas case comes amid a wider increase in ATM jackpotting activity across the United States. Criminal groups are increasingly looking for ATMs with physical or software weaknesses that can be exploited to gain control of cash-dispensing functions.
The FBI’s February 2026 alert specifically warned that threat actors are deploying ATM jackpotting malware and exploiting ATM vulnerabilities.
For financial organizations, the trend reinforces the need for continuous monitoring, timely security updates and stronger physical protection. Readers can also explore CyberNexora’s Learn & Protect resources for broader cybersecurity protection practices.
How to Protect Your Organization
Financial institutions can reduce the risk of ATM malware and jackpotting attacks by:
- Patch ATM software regularly and apply security updates as soon as they are validated.
- Restrict physical access to internal ATM components and monitor unauthorized maintenance activity.
- Strengthen application controls so unauthorized software cannot execute on ATM systems.
- Monitor unusual ATM behavior, including unexpected commands, alarms or abnormal cash-dispensing activity.
- Review surveillance footage and access logs when suspicious activity occurs.
- Segment ATM networks from other critical banking infrastructure to limit potential compromise.
- Maintain incident-response procedures specifically covering ATM compromise and suspected jackpotting.
- Coordinate with law enforcement and security teams when attempted attacks are detected.
Additional security awareness guidance is available in CyberNexora’s cybersecurity protection resources.
Indicators of Compromise (IoCs)
No case-specific malware hashes, filenames or other technical IoCs were disclosed in the provided Kansas case details. However, defensive teams should watch for:
- Unexpected ATM software or configuration changes.
- Unauthorized physical access to ATM internal components.
- Unusual ATM alarms or maintenance activity.
- Suspicious commands associated with cash-dispensing functions.
- Unexpected software execution or system behavior.
Organizations should rely on the FBI’s published technical advisory for detailed jackpotting-related indicators and mitigation guidance.
Key Takeaways
- Five Venezuelan nationals pleaded guilty after attempted ATM jackpotting operations in Kansas.
- Both attacks failed, and no cash was dispensed.
- Surveillance footage and an ATM alarm helped investigators identify the suspects.
- The FBI has recorded about 1,900 U.S. ATM jackpotting incidents since 2020.
- Financial institutions should strengthen ATM software, physical security, monitoring and incident response.
Conclusion: ATM Jackpotting Attacks and What Happens Next
ATM Jackpotting Attacks demonstrate that ATM security remains an important part of financial-sector cybersecurity. Although the Kansas attempts failed, the wider statistics show that criminals continue targeting machines with perceived physical and software weaknesses.
Banks and financial institutions should treat attempted jackpotting as a warning to review ATM configurations, patching, physical access controls and monitoring. As law enforcement continues pursuing these schemes, organizations should also follow new FBI guidance and emerging cases involving ATM malware.
Frequently Asked Questions(FAQs)
ATM Jackpotting Attacks refers to reported ATM jackpotting activity and related enforcement actions during 2026. Jackpotting generally involves compromising an ATM so it can be forced to dispense cash without a legitimate transaction.
Five Venezuelan nationals pleaded guilty to conspiracy to commit bank larceny. Luis Alberto Velasquez-Artigas was sentenced to nine months in prison, while the other defendants were awaiting sentencing.
The attempted attacks occurred in Wamego and Manhattan, Kansas, in December 2025. Both operations failed to dispense cash.
ATM jackpotting can involve exploiting physical or software weaknesses and installing malware that allows attackers to control cash-dispensing functions. The FBI has warned about the increasing use of malware-enabled jackpotting against ATMs.
The FBI reported approximately 1,900 ATM jackpotting incidents in the United States since 2020. More than 700 incidents occurred in 2025, with losses exceeding $20 million.
Banks can reduce the risk by maintaining updated ATM software, restricting physical access, monitoring suspicious activity, strengthening application controls and maintaining dedicated incident-response procedures.
