Treasury Sanctions Tren de Aragua ATM Jackpotting Network Linked to $40.7 Million in Losses
US Treasury sanctioned a Tren de Aragua network accused of ATM jackpotting tied to about $40.7 million in losses.
The U.S. Treasury’s OFAC sanctioned eight individuals and two companies linked to a Tren de Aragua ATM jackpotting network, plus a separate figure tied to illicit gold mining. Authorities connected alleged malware-driven attacks to $40.73 million in reported losses across more than 1,500 incidents as of August 2025. Seven designated TRON exchange deposit addresses received about $6.1 million since March 2022, though TRM Labs said not all of that value is confirmed jackpotting proceeds. Treasury says the Justice Department has indicted 98 people in jackpotting schemes since October 21, 2025; charged defendants remain presumed innocent.
- OFAC designated eight people, two companies, and seven TRON addresses.
- Alleged jackpotting losses total $40.73 million across more than 1,500 incidents.
- Alleged malware engineer Anibal Canelon Aguirre is an FBI Ten Most Wanted fugitive.
- TRM Labs cautions the $6.1 million in crypto is not all confirmed proceeds.
- DOJ has indicted 98 people in jackpotting schemes since October 2025.
Full article852 words · extracted from cybersecuritynews.com · click to collapse
The U.S. Treasury has sanctioned a Tren de Aragua network accused of using malware to empty ATMs across the United States. Authorities linked the alleged attacks to $40.73 million in reported losses across more than 1,500 incidents as of August 2025.
The technique, known as jackpotting, makes cash machines dispense money without charging a customer account. Attackers typically survey machines, install malicious software, and activate it remotely.
Recent ATM jackpotting guilty pleas illustrate how criminals combine physical access with software manipulation to attempt cash theft. Analysts from TRM Labs noted that the operation also relied on cryptocurrency transactions to move stolen funds.
TRM Labs said in a report shared with Cyber Security News (CSN) that seven newly sanctioned TRON addresses had received approximately $6.1 million since March 2022.
The September 30, 2026, sanctions target eight individuals and two companies connected to the alleged scheme, plus a separate gang leader involved in illicit gold mining. The report does not identify a malware family or establish when the software first emerged.
Treasury Sanctions Tren de Aragua ATM Jackpotting Network
The Treasury’s Office of Foreign Assets Control added seven TRON addresses to its Specially Designated Nationals and Blocked Persons List. Each address is attributed to one of the designated individuals, connecting the sanctions to identifiable cryptocurrency activity rather than names alone.
The principal target is Anibal Alexander Canelon Aguirre, known as “Prometheus,” whom Treasury describes as the alleged engineer of the malware. He appears on the FBI’s Ten Most Wanted Fugitives list and allegedly helped develop software used to force unauthorized cash withdrawals.
Six alleged associates were also designated: Eric Gabriel Cardenas Arzola, Jose Dario Galeano Bazurto, Anthony Wuiliam Hernandez Guerrero, Carlos Javier Martinez Armenta, Oscar Leonardo Martinez Pirona, and Alejandro Mejia Castillo. Each is linked to one of the listed cryptocurrency addresses.
These seven individuals and an eighth designee, Aslhy Javier Galeano Basurto, face charges in Nebraska. Allegations include material support to Tren de Aragua, bank fraud conspiracy, bank burglary conspiracy, and money laundering conspiracy. The defendants remain presumed innocent unless proven guilty.
The action follows earlier ATM hacking conspiracy charges involving alleged gang financing. Treasury says the Justice Department has indicted 98 people in jackpotting schemes since October 21, 2025, while investigators identified extensive direct and indirect connections between defendants and Tren de Aragua.
The two sanctioned companies are Enigma Community, S. de R.L. de C.V., owned by Martinez Pirona, and Soluciones Integrales Toluca, S.A. de C.V., owned by Mejia Castillo. Separately, Treasury designated Juan Gabriel Rivas Nunez, known as “Juancho,” over alleged criminal activities.
Cryptocurrency Exposure
TRM found that all seven listed addresses are deposit addresses hosted at a centralized exchange. Most had been inactive for months, with the latest incoming transaction occurring in July 2026. The address attributed to Cardenas Arzola received approximately $2.1 million, the largest share.
The $6.1 million total should not be treated as confirmed jackpotting proceeds. TRM explicitly cautioned that not all incoming value necessarily relates to the ATM scheme, an important distinction when assessing the network’s financial activity and the scale of its alleged thefts.
The designated addresses also transferred funds to other addresses associated with Tren de Aragua. Those recipients subsequently sent approximately $35 million to a network authorities associate with Jorge Figueira, who faces allegations of laundering approximately $1 billion. He has not been convicted.
The wider pattern echoes cryptocurrency laundering network investigations where exchanges help move illicit value across borders.
TRM recommends screening the seven addresses, reviewing historical transactions, and checking indirect exposure through counterparties one or two transfers away from the sanctioned addresses.
Exchanges may also identify underlying account holders and related accounts because the addresses are exchange hosted.
Financial institutions should assess these connections carefully: foreign institutions knowingly facilitating significant transactions for designated persons could face secondary sanctions under the authority used for this action.
The sanctions also block designated persons’ property under U.S. jurisdiction or U.S. persons’ control, with reporting obligations to OFAC and restrictions on covered transactions.
Indicators of compromise (IoCs):-
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.