Five Venezuelan nationals have pleaded guilty to attempting to drain automated teller machines using malware, according to BleepingComputer, in a case that underscores the continuing risk of so-called ATM jackpotting attacks against financial institutions. BleepingComputer reports that Luis Alberto Velasquez-Artigas, 27; Royder Adrian Figuera-Perez, 29; Javier Mejia Jr., 27; Gabriel Alexjandro Corales-Garcia, 33; and Italo Lizandro Corrales-Carrillo, 26, each pleaded guilty to one count of conspiracy to commit bank larceny. Velasquez-Artigas has already been sentenced to nine months in prison, while the other four defendants are awaiting sentencing. The case centers on attempted malware installations at ATMs in Wamego and Manhattan, Kansas. BleepingComputer, citing the Justice Department, reports that the group was arrested in December 2025 a few days after the attempted attacks, both of which were captured by surveillance cameras. The attempts were unsuccessful, according to the Justice Department account summarized by BleepingComputer. In Wamego, the attempted malware installation triggered an alarm, bringing law enforcement to the site before the suspects returned. In Manhattan, the group also failed to make the ATM dispense cash. ATM jackpotting is a physical-cyber hybrid attack. As BleepingComputer describes it, criminals install malware on an ATM’s internal computer, then use an attached USB keyboard or, in some cases, the machine’s own PIN pad to send commands to the cash dispenser and empty the cassette. The publication lists malware families used in prior campaigns, including ATMii, ATMitch, GreenDispenser, Alice, RIPPER, Skimer, SUCEFUL, and Ploutus. U.S. Attorney Ryan A. Kriegshauser said the group targeted ATMs they believed were more vulnerable to malware, according to BleepingComputer’s report. He also urged banks and other financial institutions to invest in technology updates that can help blunt jackpotting attempts. The guilty pleas come against a wider backdrop of enforcement and warnings around ATM jackpotting. BleepingComputer reports that the Federal Bureau of Investigation warned in February that criminals stole more than $20 million last year during a surge in jackpotting incidents. BleepingComputer also notes that the warning followed arrests involving members of the Tren de Aragua Venezuelan criminal organization, who were linked to a larger ATM jackpotting scheme using Ploutus malware to steal cash from ATMs across the United States. The Justice Department has charged 87 Tren de Aragua members, according to the report, with maximum prison terms ranging from 20 to 335 years each. Who benefits: Financial institutions that have invested in ATM software updates, alarms, monitoring, and physical access controls are better positioned against the attack path described in the case. Law enforcement also benefits when alarms and surveillance footage preserve evidence quickly. Who's exposed: ATMs believed to be more vulnerable to malware remain exposed to physical malware-installation attempts. The source specifically says the defendants targeted ATMs they believed were more vulnerable to malware.