Treasury Sanctions Tren de Aragua's ATM Jackpotting Network
The U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) announced sanctions on September 30, 2026, against eight members of the Venezuelan gang Tren de Aragua (TdA) and two Mexico-based companies for operating a large-scale ATM jackpotting scheme that stole more than $40.73 million from U.S. financial institutions across over 1,500 attacks as of August 2025. The network's alleged ringleader, Anibal Alexander Canelon Aguirre — known by the alias "Prometheus" — is one of the FBI's Ten Most Wanted Fugitives, reportedly the first person added to that list for cybercrime. Treasury says Canelon Aguirre personally engineered the Ploutus malware strain used to force U.S. ATMs to dispense cash on command, with stolen funds laundered through cryptocurrency and routed to TdA members in multiple countries. The action, part of a campaign Treasury has referred to internally as "Cash Me If You Can," also designated seven TRON cryptocurrency addresses linked to the network to OFAC's Specially Designated Nationals and Blocked Persons (SDN) List.
Incident Details
| Attribute | Value |
|---|---|
| Announced by | U.S. Department of the Treasury, Office of Foreign Assets Control (OFAC) |
| Date announced | September 30, 2026 |
| Threat actor | Tren de Aragua (TdA), Venezuelan transnational criminal organization |
| Alleged ringleader | Anibal Alexander Canelon Aguirre ("Prometheus") — FBI Ten Most Wanted Fugitive |
| Individuals designated | 8: Canelon Aguirre, Eric Gabriel Cardenas Arzola, Jose Dario Galeano Bazurto, Aslhy Javier Galeano Basurto, Anthony Wuiliam Hernandez Guerrero, Carlos Javier Martinez Armenta, Oscar Leonardo Martinez Pirona, Alejandro Mejia Castillo |
| Companies designated | Enigma Community, S. de R.L. de C.V. (Mexico); Soluciones Integrales Toluca, S.A. de C.V. (Mexico) |
| Related designation (same action) | Juan Gabriel Rivas Nunez ("Juancho"), senior TdA leader tied to illicit gold mining |
| Malware used | Ploutus (self-erasing after each attack); broader jackpotting malware families referenced by Treasury include ATMii, ATMitch, GreenDispenser, Alice, RIPPER, Skimer, and SUCEFUL |
| Financial impact | $40.73 million stolen, 1,500+ alleged ATM jackpotting attacks (as of August 2025) |
| Crypto laundering | 7 TRON addresses added to the SDN List; roughly $6.1 million in inflows since March 2022 per TRM Labs |
| Legal authority | Executive Order 13581 and Executive Order 13224, as amended |
| Parallel DOJ action | 98 individuals indicted since October 21, 2025 on jackpotting-related charges, including cases in Nebraska federal court |
How the Scheme Worked
Malware-driven jackpotting
Jackpotting attacks force an ATM's cash dispenser to empty itself without debiting any customer account. According to OFAC and court filings tied to the network, operatives gained physical or logical access to targeted ATMs and deployed Ploutus — malware that commands the machine's dispenser to release cash on demand — via an attached USB keyboard or the ATM's own PIN pad. Treasury said the malware was designed to erase itself and any transaction logs after each heist, complicating forensic attribution and slowing law enforcement response. While Ploutus is the strain specifically tied to Prometheus's network, Treasury's broader description of the ATM jackpotting landscape also referenced other known families such as ATMitch, GreenDispenser, Alice, RIPPER, Skimer, and SUCEFUL as tools used in similar attacks against the sector.
Organizational structure
OFAC describes Canelon Aguirre as the network's architect, operating from a base spanning Mexico and Venezuela while directing attacks against ATMs physically located inside the United States. The seven associates designated alongside him have each been indicted — largely in a federal case out of Nebraska — on charges that include providing material support to a designated Foreign Terrorist Organization, bank fraud conspiracy, bank burglary conspiracy, and money laundering conspiracy, with potential sentences reported to range from roughly 20 to 335 years depending on the specific charges and defendant.
Laundering through crypto and shell businesses
Once cash was extracted, proceeds moved through a laundering layer that included cryptocurrency transfers on the TRON network and two Mexico-registered companies that OFAC says were controlled by designated individuals: Enigma Community, tied to Oscar Leonardo Martinez Pirona, and Soluciones Integrales Toluca, tied to Alejandro Mejia Castillo. Blockchain analytics firm TRM Labs found that the seven sanctioned TRON addresses — all deposit addresses hosted at a centralized exchange — received approximately $6.1 million in total inflows since March 2022, with funds subsequently moved to other TdA-associated wallets. Treasury says the laundered proceeds ultimately funded the broader TdA enterprise, which spans drug trafficking, human smuggling, extortion, and murder-for-hire in addition to cyber-enabled financial fraud.
Designation history
Tren de Aragua, which originated as a prison gang in Venezuela's Aragua state before expanding across Latin America and into the United States, was designated a Transnational Criminal Organization by Treasury on July 11, 2024, and a Foreign Terrorist Organization by the State Department on February 20, 2025. This action follows prior 2025 OFAC designations against TdA leadership and support networks on June 24, July 17, and December 3, and is one of more than 30 actions Treasury has taken against more than 300 individuals and entities tied to transnational criminal organizations since 2025.
Impact Assessment
| Impact Area | Description |
|---|---|
| Financial sector losses | $40.73 million stolen from U.S. banks and credit unions across 1,500+ confirmed jackpotting incidents |
| Sanctions exposure | All U.S. property and interests of the 10 designated individuals/entities are blocked; U.S. persons are generally barred from transacting with them |
| Secondary sanctions risk | Foreign financial institutions that knowingly process significant transactions for designated parties risk losing access to U.S. correspondent banking under Executive Order 13224 |
| Cryptocurrency exposure | Virtual asset service providers and exchanges should screen for exposure to the 7 sanctioned TRON addresses to avoid processing blocked transactions |
| Criminal justice exposure | 98 individuals already indicted by DOJ since October 2025, separate from and complementary to the Treasury sanctions |
| National security | Treasury frames disrupting TdA's financial infrastructure as a priority given the group's ties to trafficking, smuggling, and violent crime beyond ATM fraud |
Recommendations
For financial institutions and ATM operators
- Audit physical security controls on ATM top-hats and service panels; jackpotting typically requires brief physical access to connect a rogue USB device or exploit an exposed PIN pad interface.
- Enforce application allow-listing and code-signing on ATM operating systems so unauthorized executables such as Ploutus cannot run even with local access.
- Monitor for anomalous dispense events, especially large cash-outs outside normal transaction patterns or sequences that bypass standard authorization logging.
- Review vendor and third-party maintenance access procedures, since jackpotting campaigns have historically relied on social engineering or insider access to reach machine internals.
For compliance and AML/sanctions teams
- Screen customer and counterparty databases against the updated OFAC SDN List for the 8 newly designated individuals and 2 companies, and confirm no existing relationships require immediate blocking or reporting.
- Virtual asset service providers should specifically screen wallet activity against the 7 sanctioned TRON addresses and file blocked-property reports for any matching transactions.
- Reassess correspondent banking relationships with foreign institutions that may have exposure to TdA-linked individuals or shell companies, given the secondary sanctions risk under Executive Order 13224.
For security teams and law enforcement liaisons
- Treat ATM jackpotting as a cross-border, organized-crime problem rather than isolated fraud; coordinate with the FBI and Secret Service on indicator-sharing given the scale of the Nebraska-linked indictments.
- Track further OFAC actions against TdA, as Treasury has signaled this is part of a continuing campaign rather than a single, isolated enforcement action.
Key Takeaways
- OFAC sanctioned 8 individuals and 2 companies tied to Tren de Aragua on September 30, 2026, for an ATM jackpotting scheme that stole $40.73 million across 1,500+ attacks.
- Alleged ringleader Anibal Alexander Canelon Aguirre ("Prometheus") is on the FBI's Ten Most Wanted Fugitives list and is accused of personally engineering the Ploutus malware used in the attacks.
- Proceeds were laundered through cryptocurrency, with 7 TRON addresses — now on the SDN List — receiving roughly $6.1 million since March 2022, alongside two Mexico-based shell companies.
- The designations rely on Executive Orders 13581 and 13224, exposing both the named individuals and any foreign banks that transact with them to U.S. financial restrictions.
- The sanctions run parallel to a DOJ criminal track that has indicted 98 individuals since October 21, 2025 on jackpotting-related charges.
- This is one of more than 30 Treasury actions against TdA and related transnational criminal organizations since 2025, reflecting sustained pressure on the group's financial infrastructure following its 2024-2025 Transnational Criminal Organization and Foreign Terrorist Organization designations.
Sources
- US sanctions Tren de Aragua gang members in ATM hacks crackdown — BleepingComputer
- Treasury Sanctions Financial Network of Foreign Terrorist Organization, Tren de Aragua, After Theft of Millions from U.S. Banks — U.S. Department of the Treasury
- Treasury Sanctions Tren de Aragua ATM Jackpotting Network, Including Seven TRON Addresses — TRM Labs
- US sanctions 10 over ATM malware scheme tied to Tren de Aragua — The Record
- Treasury Blacklists Most-Wanted ATM Malware Developer and His Network — SecurityWeek