Monday , October 5 2026
31

US indicts 31 in major ATM malware heist draining bank funds

A federal grand jury in Nebraska has indicted 31 individuals for their involvement in a Ploutus malware scheme that resulted in the theft of millions from ATMs throughout the United States. This sophisticated “ATM jackpotting” operation is connected to the Tren de Aragua (TdA) gang, classified as a foreign terrorist organization.

Recent months have seen 87 TdA members charged. Authorities claim the plot financed violent crimes like trafficking and murder.

Citrix NetScaler SAML 0-Day Flaw Under Attack

Citrix has put out emergency security updates for a NetScaler SAML flaw that hackers are using. Known as CVE-2026-88779, this...
Read More
Citrix NetScaler SAML 0-Day Flaw Under Attack

Major Danish university breached, 200,000 users at risk

Hackers got into the identity and access management system at the Technical University of Denmark (DTU) and downloaded a lot...
Read More
Major Danish university breached, 200,000 users at risk

Microsoft’s X account hijacked to promote Clippy crypto scam

Microsoft's official X account was taken over to promote an unapproved Clippy-themed cryptocurrency. The tech giant’s X account, with 13...
Read More
Microsoft’s X account hijacked to promote Clippy crypto scam

Critical cPanel, GitLab AI Gateway and Dell CSM Flaws Enable RCE And Admin Hijacking

CPanel has put out security updates to fix three problems in cPanel & WHM. These problems could let attackers take...
Read More
Critical cPanel, GitLab AI Gateway and Dell CSM Flaws Enable RCE And Admin Hijacking

Nearly 100,000 email addresses exposed in first AI-related data breach in Singapore

Nearly 100,000 Bee Cheng Hiang customers had their email addresses leaked when an employee used an AI tool to generate...
Read More
Nearly 100,000 email addresses exposed in first AI-related data breach in Singapore

Hackers Exploit Zimbra Mail Servers: TeamViewer patched 5 critical flaws

Hackers to exploit a flaw in Zimbra mail servers that are connected to the Internet. They send special emails that...
Read More
Hackers Exploit Zimbra Mail Servers: TeamViewer patched 5 critical flaws

Google Warns of Hackers Actively Exploiting Citrix 0-Day Flaws

Google has said that hackers are using two serious Citrix NetScaler security holes to get root access, set up hidden...
Read More
Google Warns of Hackers Actively Exploiting Citrix 0-Day Flaws

CISA Warns Critical MikroTik RouterOS Flaw While Cisco SD-WAN Zero-Day Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is alerting people about a major flaw in MikroTik RouterOS. This could...
Read More
CISA Warns Critical MikroTik RouterOS Flaw While Cisco SD-WAN Zero-Day Exploited in Attacks

Apple Zero-Day Exploited: Pentagon Data Breach Reportedly Exposes Sensitive Data of 3 Million People

Apple has launched iOS 26.7.1 and iPadOS 26.7.1 to fix a serious zero-day flaw that it believes might have been...
Read More
Apple Zero-Day Exploited: Pentagon Data Breach Reportedly Exposes Sensitive Data of 3 Million People

JadePuffer Agentic AI targets and destroys Azure’s cloud resources

The JadePuffer ransomware group is attacking Azure users with agent-based attacks that gather information, steal passwords, and damage key components. The...
Read More
JadePuffer Agentic AI targets and destroys Azure’s cloud resources

The indictment comprises 32 charges, encompassing conspiracy to commit bank fraud, bank burglary, computer fraud, and computer damage. If found guilty, the defendants could face a staggering maximum sentence of 335 years in prison. Notably, many of the accused are nationals from Venezuela or Colombia, including members of TdA who unlawfully entered the United States.

How ATM Jackpotting Works:

ATM jackpotting involves tricking machines into dispensing cash without cards or PINs. Criminals use malware, such as Ploutus, to take control of the ATM’s cash dispenser. Ploutus, which emerged in 2013, targets ATMs using Windows XP or older software, sending fake commands to release cash. Criminals initially inspected bank ATMs to see if alarms would trigger by opening the hood; if not, they deemed it safe to proceed.

Then, they installed Ploutus in three ways:

Removed the ATM’s hard drive and loaded malware directly.
Swapped it with a pre-infected drive.
Plugged in a USB drive to deploy the code remotely.

Ploutus erases logs to cover its tracks, deceiving bank staff. After stealing cash, groups divide the money. Case photos reveal tools like USBs and open ATM panels during the heist.

This follows earlier indictments. A December 2025 case charged 22 people for TdA-related jackpotting and money laundering. An October indictment hit 32 for similar fraud. Total losses are in the millions, affecting banks and credit unions across the country.

TdA began as a Venezuelan prison gang in the 2000s and has expanded to drug trafficking, arms smuggling, sex trafficking, and extortion throughout the Americas, including the US. Jackpotting generates fast cash to support these activities, which officials label as a “revenue stream” for terrorism.

Attorney General Pamela Bondi labeled TdA a “complex terrorist organization.” Deputy AG Todd Blanche vowed to dismantle it via Joint Task Force Vulcan (JTFV).
US Attorney Lesley Woods in Nebraska aims to cut their funds. Justice FBI’s Eugene Kowel stressed tracking the money.

The investigation includes the FBI Omaha, HSI, and many other agencies. The HSTF, created by Executive Order 14159, focuses on cartels and gangs. The JTFV, which started in 2019 to combat MS-13, is now targeting TdA.

Technical Defenses Against Jackpotting:

ATMs remain vulnerable due to outdated software. Many still use Windows XP, unpatched for years. Malware like Ploutus exploits weak physical security unlocked panels let attackers insert devices.

Banks fight back with:
EMV Chip Cards and Tokenization: Reduces card skimming risks.
Jammed Detection: Sensors block CDM if tampered.
Remote Monitoring: Real-time alerts for odd cashouts.
Hardened OS: Shift to Linux or secure Windows versions.
Air-Gapped Networks: Isolates ATMs from the internet.

CISA recommends updating firmware and using multi-factor access for security. Logical locks, like PIN-protected hoods, can deter intruders, but physical access still poses a risk. The rise of cartels using cyber tools highlights the need for stronger defenses as TdA evolves. The DOJ’s 87 charges indicate a crackdown, but increased ATM attacks are likely unless banks quickly enhance security.

Check Also

JadePuffer

JadePuffer Agentic AI targets and destroys Azure’s cloud resources

The JadePuffer ransomware group is attacking Azure users with agent-based attacks that gather information, steal …