FBI Says Ploutus Could Make an ATM Dispense Cash Without a Card and Its Alleged Developer Was Caught at Sea
The malware allegedly bypasses bank authorisation by using ATM software to dispense cash, while investigators link the wider scheme to Tren de Aragua

The FBI says Venezuelan national Anibal Alexander Canelon Aguirre is alleged to have developed Ploutus, malware that can make ATMs dispense cash without a bank card, customer account or bank authorisation.
Aguirre, who was added to the FBI's Ten Most Wanted Fugitives list in March 2026, was apprehended at sea by the US Coast Guard and appeared in a Nebraska federal court on 2 October, according to the FBI.
The allegations form part of a wider investigation into ATM 'jackpotting' a type of theft that targets the machine rather than individual bank customers.
Authorities allege that the scheme was tied to Tren de Aragua, a Venezuelan transnational criminal organisation, and involved millions of dollars taken from US financial institutions.
How Ploutus Turns ATMs Into Cash Machines
The FBI's Internet Crime Complaint Center warned in a 19 February Flash Alert that it had observed an increase in malware-enabled ATM jackpotting across the US. The alert said 1,900 incidents had been reported since 2020, including more than 700 incidents linked to over $20 million in losses during 2025 alone.
The agency said Ploutus exploits the eXtensions for Financial Services, or XFS, a software layer that instructs an ATM what to physically do. In a legitimate transaction, the ATM application sends instructions through XFS for bank authorisation.
Ploutus allows threat actors to issue their own commands to XFS, bypassing bank authorisation and instructing the ATM to dispense cash on demand, according to the FBI. The FBI said Ploutus can be used across ATMs from different manufacturers with little adjustment to the code.
That makes jackpotting particularly damaging. The criminals do not need to compromise thousands of customer accounts individually. Instead, they allegedly compromise the ATM itself, then cash out rapidly, sometimes within minutes.
The FBI said cash-outs can occur within minutes and may be difficult to detect until after the money has been withdrawn.
The FBI said ATM operators should watch for unauthorised USB devices, unexpected remote-access software, unexplained files and ATM doors opened outside scheduled maintenance. It also recommended comparing the machine's files with a verified 'gold image,' a trusted baseline containing approved software and configurations.
Aguirre Allegedly Could Determine How Much Cash ATMs Held
According to the FBI, Aguirre could remotely determine how much cash was held in an infected ATM. Investigators allege that the organisation's leadership used that information in directing jackpotting operations.
The FBI estimates that approximately $61 million has come out of US banks since 2021, with investigators alleging that about 50 per cent of the proceeds was available for Tren de Aragua's use. The figures are allegations from investigators and have not been tested at trial.
Aguirre is charged with conspiracy to commit bank fraud, conspiracy to commit bank burglary and fraud in connection with computers, conspiracy to commit money laundering, and conspiracy to provide material support to terrorists, according to the Justice Department.
The FBI said he was the first cyber fugitive added to its Ten Most Wanted list, although his alleged role extended beyond writing malicious code.
His capture was unusually dramatic. The FBI said the US Coast Guard apprehended him at sea, with assistance from an FBI Omaha agent and the Bureau's Critical Incident Response Group, and that he was transported to Nebraska by water and air. He pleaded not guilty to the charges and remains entitled to the presumption of innocence.
The case follows a series of prosecutions involving alleged ATM jackpotting associates. On 20 August, Juan Manuel Gouveia-Aguilera, 27, was sentenced in Omaha to 96 months in prison after pleading guilty to charges arising from a scheme that resulted in more than $3.5 million in losses, according to the Justice Department.
The prosecution also illustrates that jackpotting can involve both physical access to an ATM and the deployment of malware. The FBI's alert says criminals may gain access by opening an ATM face with generic keys, removing its hard drive, copying malware onto it and rebooting the machine. In other cases, they may replace the drive with an external device containing malicious software.
For banks, that creates an awkward security problem. Strong customer authentication may do little if the attack bypasses the customer transaction altogether. In these attacks, the ATM itself can be the target, with criminals exploiting physical access and maintenance-related vulnerabilities to introduce malware.
The FBI has urged financial institutions to strengthen physical security, audit removable storage, monitor process creation and preserve system logs. It also recommended software and device whitelisting, network controls and automatic shutdowns when multiple indicators of compromise appear.
Whether those measures were in place at the ATMs allegedly targeted in the investigation is not established by the public materials cited here. Aguirre has been returned to the United States to face the charges in Nebraska. He pleaded not guilty and remains presumed innocent unless and until proven guilty.
© Copyright IBTimes 2026. All rights reserved.

