Tuesday , August 25 2026
31

US indicts 31 in major ATM malware heist draining bank funds

A federal grand jury in Nebraska has indicted 31 individuals for their involvement in a Ploutus malware scheme that resulted in the theft of millions from ATMs throughout the United States. This sophisticated “ATM jackpotting” operation is connected to the Tren de Aragua (TdA) gang, classified as a foreign terrorist organization.

Recent months have seen 87 TdA members charged. Authorities claim the plot financed violent crimes like trafficking and murder.

Chameleon SEO Poisoning
Hackers poison Bing and Google search results to deliver phishing banking pages

Bank customers looking for a login page can now fall into a trap before getting a strange email or text....
Read More
Chameleon SEO Poisoning  Hackers poison Bing and Google search results to deliver phishing banking pages

Mysterious AI model “Ox Alpha” with free 100 trillion tokens a day for coders

A mysterious AI model dubbed "Ox Alpha" has surfaced online and created noise within the developer community after releasing on...
Read More
Mysterious AI model “Ox Alpha” with free 100 trillion tokens a day for coders

After BDJobs, Directorate of Secondary and Higher Education 390k data surfaced online

A group of hackers named “Madarax” claims they have stolen and are offering to sell the personal information of about...
Read More
After BDJobs, Directorate of Secondary and Higher Education 390k data surfaced online

Researchers show new technique to bypass AI safety guardrails in Grok and Gemini

A new hacking technique has been demonstrated to steal data from Elon Musk's Grok AI. It uses a simple trick...
Read More
Researchers show new technique to bypass AI safety guardrails in Grok and Gemini

About thousands of leaked AWS keys Held Full Admin Rights

More than 9,300 AWS access keys that were made public from August 2022 to August 2026 are still active, says...
Read More
About thousands of leaked AWS keys Held Full Admin Rights

US Bank investigates LockBit’s Data Breach Claims

US Bank is looking into LockBit's claims about a breach and stolen data. The ransomware group says they will share...
Read More
US Bank investigates LockBit’s Data Breach Claims

Five new malware families actively targeting Asian Gov.t infra

Central Asian government agencies have been attacked in a cyber spy operation that used a small but different range of...
Read More
Five new malware families actively targeting Asian Gov.t infra

T-Mobile Cuts Cables to Remove Chiness Salt Typhoon Hackers from Network

T-Mobile’s cybersecurity team reportedly physically cut a network cable connecting compromised infrastructure to the outside world. According to Bloomberg, the move...
Read More
T-Mobile Cuts Cables to Remove Chiness Salt Typhoon Hackers from Network

Splunk, Zyxel Patch Multiple Flaws Enabling RCE and Root Command Execution

Splunk has issued security fixes for 17 weaknesses in different apps and add-ons, such as Splunk MCP Server, Splunk AI...
Read More
Splunk, Zyxel Patch Multiple Flaws Enabling RCE and Root Command Execution

“Zombie Card” attack revels expired Visa card may be used for contactless payments

Security experts have shown that expired credit cards can still be used. A study from the University of Massachusetts Amherst,...
Read More
“Zombie Card” attack revels expired Visa card may be used for contactless payments

The indictment comprises 32 charges, encompassing conspiracy to commit bank fraud, bank burglary, computer fraud, and computer damage. If found guilty, the defendants could face a staggering maximum sentence of 335 years in prison. Notably, many of the accused are nationals from Venezuela or Colombia, including members of TdA who unlawfully entered the United States.

How ATM Jackpotting Works:

ATM jackpotting involves tricking machines into dispensing cash without cards or PINs. Criminals use malware, such as Ploutus, to take control of the ATM’s cash dispenser. Ploutus, which emerged in 2013, targets ATMs using Windows XP or older software, sending fake commands to release cash. Criminals initially inspected bank ATMs to see if alarms would trigger by opening the hood; if not, they deemed it safe to proceed.

Then, they installed Ploutus in three ways:

Removed the ATM’s hard drive and loaded malware directly.
Swapped it with a pre-infected drive.
Plugged in a USB drive to deploy the code remotely.

Ploutus erases logs to cover its tracks, deceiving bank staff. After stealing cash, groups divide the money. Case photos reveal tools like USBs and open ATM panels during the heist.

This follows earlier indictments. A December 2025 case charged 22 people for TdA-related jackpotting and money laundering. An October indictment hit 32 for similar fraud. Total losses are in the millions, affecting banks and credit unions across the country.

TdA began as a Venezuelan prison gang in the 2000s and has expanded to drug trafficking, arms smuggling, sex trafficking, and extortion throughout the Americas, including the US. Jackpotting generates fast cash to support these activities, which officials label as a “revenue stream” for terrorism.

Attorney General Pamela Bondi labeled TdA a “complex terrorist organization.” Deputy AG Todd Blanche vowed to dismantle it via Joint Task Force Vulcan (JTFV).
US Attorney Lesley Woods in Nebraska aims to cut their funds. Justice FBI’s Eugene Kowel stressed tracking the money.

The investigation includes the FBI Omaha, HSI, and many other agencies. The HSTF, created by Executive Order 14159, focuses on cartels and gangs. The JTFV, which started in 2019 to combat MS-13, is now targeting TdA.

Technical Defenses Against Jackpotting:

ATMs remain vulnerable due to outdated software. Many still use Windows XP, unpatched for years. Malware like Ploutus exploits weak physical security unlocked panels let attackers insert devices.

Banks fight back with:
EMV Chip Cards and Tokenization: Reduces card skimming risks.
Jammed Detection: Sensors block CDM if tampered.
Remote Monitoring: Real-time alerts for odd cashouts.
Hardened OS: Shift to Linux or secure Windows versions.
Air-Gapped Networks: Isolates ATMs from the internet.

CISA recommends updating firmware and using multi-factor access for security. Logical locks, like PIN-protected hoods, can deter intruders, but physical access still poses a risk. The rise of cartels using cyber tools highlights the need for stronger defenses as TdA evolves. The DOJ’s 87 charges indicate a crackdown, but increased ATM attacks are likely unless banks quickly enhance security.

Check Also

card

“Zombie Card” attack revels expired Visa card may be used for contactless payments

Security experts have shown that expired credit cards can still be used. A study from …