Wednesday , September 16 2026
31

US indicts 31 in major ATM malware heist draining bank funds

A federal grand jury in Nebraska has indicted 31 individuals for their involvement in a Ploutus malware scheme that resulted in the theft of millions from ATMs throughout the United States. This sophisticated “ATM jackpotting” operation is connected to the Tren de Aragua (TdA) gang, classified as a foreign terrorist organization.

Recent months have seen 87 TdA members charged. Authorities claim the plot financed violent crimes like trafficking and murder.

CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

CISA has added a serious Cisco Secure Email Gateway flaw to its list of known exploits. They warn that attackers...
Read More
CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

VPN flaw exposed 246,000 personnel records in japan

Japan’s Digital Agency found a data leak that may have exposed about 246,000 records with personal information of government workers....
Read More
VPN flaw exposed 246,000 personnel records in japan

Hackers deploy Casbaneiro Trojan that activates on bank websites

Casbaneiro is going after online banking users by sending fake messages that seem like urgent bills or legal papers. The...
Read More
Hackers deploy Casbaneiro Trojan that activates on bank websites

German police read Signal, Telegram, WhatsApp messages without breaking encryption

German law enforcement agencies are using features built into apps such as WhatsApp to monitor people’s messages without breaking their...
Read More
German police read Signal, Telegram, WhatsApp messages without breaking encryption

Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

GitLab has released an important security update to fix two serious problems. These issues could allow unauthorized file access and...
Read More
Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

Palo Alto PAN-OS Flaw Enables Root Arbitrary Code Execution

Palo Alto Networks has revealed a serious flaw in PAN-OS. It may let a remote attacker without a password run...
Read More
Palo Alto PAN-OS Flaw Enables Root Arbitrary Code Execution

Critical Check Point VPN flaws allow remote code execution attacks

Check Point Software has revealed and fixed two major VPN flaws, CVE-2026-85102 and CVE-2026-85103. Both have a top CVSS score...
Read More
Critical Check Point VPN flaws allow remote code execution attacks

Cisco confirms CVE-2026-20079 flaw in Secure FMC is exploited in attacks

Cisco has said that a serious security flaw CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being used...
Read More
Cisco confirms CVE-2026-20079 flaw in Secure FMC is exploited in attacks

Hackers exploit PaperCut flaws using hundreds of AI agents, compromising 440 servers globally

A Russian-speaking hacker has used artificial intelligence like never before. They sent out hundreds of AI agents to find and...
Read More
Hackers exploit PaperCut flaws using hundreds of AI agents, compromising 440 servers globally

CISA Says Chinese Firms Extracted Billions of Tokens From Frontier AI Models

Six Chinese AI companies ran large-scale attacks on American AI models since late 2024, according to U.S. cybersecurity and intelligence...
Read More
CISA Says Chinese Firms Extracted Billions of Tokens From Frontier AI Models

The indictment comprises 32 charges, encompassing conspiracy to commit bank fraud, bank burglary, computer fraud, and computer damage. If found guilty, the defendants could face a staggering maximum sentence of 335 years in prison. Notably, many of the accused are nationals from Venezuela or Colombia, including members of TdA who unlawfully entered the United States.

How ATM Jackpotting Works:

ATM jackpotting involves tricking machines into dispensing cash without cards or PINs. Criminals use malware, such as Ploutus, to take control of the ATM’s cash dispenser. Ploutus, which emerged in 2013, targets ATMs using Windows XP or older software, sending fake commands to release cash. Criminals initially inspected bank ATMs to see if alarms would trigger by opening the hood; if not, they deemed it safe to proceed.

Then, they installed Ploutus in three ways:

Removed the ATM’s hard drive and loaded malware directly.
Swapped it with a pre-infected drive.
Plugged in a USB drive to deploy the code remotely.

Ploutus erases logs to cover its tracks, deceiving bank staff. After stealing cash, groups divide the money. Case photos reveal tools like USBs and open ATM panels during the heist.

This follows earlier indictments. A December 2025 case charged 22 people for TdA-related jackpotting and money laundering. An October indictment hit 32 for similar fraud. Total losses are in the millions, affecting banks and credit unions across the country.

TdA began as a Venezuelan prison gang in the 2000s and has expanded to drug trafficking, arms smuggling, sex trafficking, and extortion throughout the Americas, including the US. Jackpotting generates fast cash to support these activities, which officials label as a “revenue stream” for terrorism.

Attorney General Pamela Bondi labeled TdA a “complex terrorist organization.” Deputy AG Todd Blanche vowed to dismantle it via Joint Task Force Vulcan (JTFV).
US Attorney Lesley Woods in Nebraska aims to cut their funds. Justice FBI’s Eugene Kowel stressed tracking the money.

The investigation includes the FBI Omaha, HSI, and many other agencies. The HSTF, created by Executive Order 14159, focuses on cartels and gangs. The JTFV, which started in 2019 to combat MS-13, is now targeting TdA.

Technical Defenses Against Jackpotting:

ATMs remain vulnerable due to outdated software. Many still use Windows XP, unpatched for years. Malware like Ploutus exploits weak physical security unlocked panels let attackers insert devices.

Banks fight back with:
EMV Chip Cards and Tokenization: Reduces card skimming risks.
Jammed Detection: Sensors block CDM if tampered.
Remote Monitoring: Real-time alerts for odd cashouts.
Hardened OS: Shift to Linux or secure Windows versions.
Air-Gapped Networks: Isolates ATMs from the internet.

CISA recommends updating firmware and using multi-factor access for security. Logical locks, like PIN-protected hoods, can deter intruders, but physical access still poses a risk. The rise of cartels using cyber tools highlights the need for stronger defenses as TdA evolves. The DOJ’s 87 charges indicate a crackdown, but increased ATM attacks are likely unless banks quickly enhance security.

Check Also

Crack 85 Accounts and Steal 2,500+ Records
8-Agent AI Framework Used to Compromise Gov’t Entities in Asia

A cyberattack using open-source AI tools almost ran on its own. It affected government systems …