U.S. Imposes Sanctions on Network Linked to ATM Jackpotting
The U.S. Department of the Treasury added eight people and two Mexican companies linked to attacks on ATMs to its sanctions list. Separately, it designated an alleged Tren de Aragua group official.

Sanctions for ATM jackpotting OFAC, the U.S. Treasury Department’s Office of Foreign Assets Control, imposed sanctions on September 30, 2026, against eight individuals and two Mexican companies in a network linked to attacks on ATMs. Separately, OFAC designated Juan Gabriel Rivas Nunez, whom the U.S. Treasury Department describes as a high-ranking official of the Tren de Aragua group.
The Mexican companies Enigma Community, S. de R.L. de C.V. and Soluciones Integrales Toluca, S.A. de C.V. were added to the SDN list. Among the eight individuals is Anibal Alexander Canelon Aguirre, who also uses the alias “Prometheus.” Treasury identifies him as the alleged author of malware deployed in ATM attacks.
Sanctions for ATM jackpotting block assets in the U.S.
Placement on the SDN list means that the property and property interests of designated persons located under U.S. jurisdiction are blocked. U.S. persons generally may not conduct transactions with them. Treasury also warns that foreign financial institutions may face the risk of secondary sanctions for significant transactions with designated entities.
The sanctions action is not a court ruling on guilt. The links between the individuals and companies and Tren de Aragua, the malware’s authorship, and the extent of the damage caused are claims by U.S. authorities.
Physical intrusion, malware and remote cash dispensing
The term ATM jackpotting refers to an attack in which attackers force an ATM to dispense cash. According to Treasury, the known method in this case involved physically compromising the device, installing malware and then remotely triggering the dispensing of money.
The U.S. Treasury Department stated that reported losses from alleged jackpotting attacks in the U.S. totaled $40.73 million as of August 2025. More than 1,500 incidents were recorded.
Treasury’s primary materials do not name the malware. Therefore, they cannot independently confirm that it was a specific previously known piece of malicious code. The announcement also does not describe a new technical vulnerability or provide a security patch.
Aguirre remains on the FBI list
The FBI continues to list Aguirre among its Ten Most Wanted Fugitives. It is seeking him in connection with charges that include conspiracy to commit bank fraud, bank burglary, damage to a protected computer system, money laundering and providing material support to terrorists.
The case is also relevant to ATM operators. It combines physical access to the device, malicious software and cash dispensing; according to Treasury, it also involves laundering proceeds, including through cryptocurrency transactions.
Further developments could include Aguirre’s possible arrest, new indictments or verdicts in a related case in Nebraska. It will also be important whether the FBI, the U.S. Department of Justice or ATM manufacturers publish verified technical details about the malware used and recommended measures.
Sources
- U.S. Department of the Treasury – Confirms the sanctions of September 30, 2026, the designated individuals and companies, the alleged jackpotting mechanism, the scale of reported losses and the legal consequences of the sanctions.
- Office of Foreign Assets Control – Confirms the addition of eight individuals and two Mexican companies to the SDN list, including Aguirre’s identification as “Prometheus.”
- FBI – Confirms that Anibal Alexander Canelon Aguirre was still on the FBI Ten Most Wanted Fugitives list as of October 1, 2026.
- SecurityWeek – Independently summarizes the sanctions action and its cybersecurity context.
Verified and updated: 10/01/2026 15:28



