Back Streamlinefeed.Co.Ke FBI Exposes KES 68.7M Interstate ATM Jackpotting Syndicate
Four Venezuelan nationals face federal charges after using malware to steal $529,220 (KES 68.7M) from ATMs, exposing global banking flaws.
Four Venezuelan nationals face federal charges after allegedly deploying sophisticated malware to systematically drain automated teller machines across Connecticut rest stops, exposing severe vulnerabilities in automated financial infrastructure.
The arrests highlight a surging global vulnerability in retail banking networks. The sophisticated heist mirrors urgent warnings previously issued by the Central Bank of Kenya (CBK) regarding cyber-resilience, as transnational syndicates increasingly exploit outdated ATM operating systems to bypass standard physical security measures.
According to federal prosecutors, the organized crew executed a string of thefts targeting ATMs along the Interstate 95 corridor, striking locations from Darien to New Haven. The United States Attorney for the District of Connecticut, David X. Sullivan, detailed the calculated nature of the attacks, which resulted in the theft of $529,220 (KES 68.7 million) over a precise 10-day operational window in August 2025.
Court documents allege the syndicate utilized a technique known as "jackpotting." This method involves bypassing the machine's external security to access internal USB ports, uploading specialized malware like the notorious Ploutus strain, and commanding the cash dispenser to rapidly eject its entire reserve.
The four men charged—Willian Flores, 49; Alberto Arvilla, 41; Luis Arvilla, 38; and Euclides Itanare, 28—allegedly maintained strict operational discipline. Surveillance footage reviewed by the FBI indicates Luis Arvilla acted as a primary lookout while Alberto Arvilla breached the ATM cabinets. Over several hours, the remaining members reportedly took turns extracting the dispensed cash, frequently changing their clothing to evade detection.
Jackpotting bypasses traditional consumer fraud methods, such as card skimming, by directly attacking the machine's core architecture. The malware targets the eXtensions for Financial Services (XFS) middleware, effectively severing the ATM's communication with the host bank. Once installed, the malicious software allows criminals to issue direct commands to the cash dispenser using an external keyboard or mobile device.
In one instance during the crew's spree, an attempted theft at an Ansonia, Connecticut location failed completely. Investigators confirmed the machine had recently received a critical software patch that neutralized the malware's execution script, demonstrating the immediate value of proactive system updates.
The Connecticut syndicate's success underscores a persistent threat that extends far beyond North America. In East Africa, financial regulators remain on high alert for similar cyber-kinetic attacks. In 2019, Kenyan authorities investigated a highly coordinated KES 14 million heist targeting Barclays Bank (now Absa) ATMs in Nairobi, which cybersecurity experts widely attributed to local variations of jackpotting.
The Central Bank of Kenya has mandated stringent cybersecurity frameworks, compelling commercial lenders to continuously upgrade legacy operating systems. Dr. Bright Mawudor, a leading Nairobi-based cybersecurity consultant, previously noted that executing such attacks often requires insider knowledge of ATM hardware configurations, alongside the technical capacity to override factory security protocols.
As global financial institutions transition to advanced encryption and zero-trust architectures, older machines placed in remote or low-security transit corridors remain highly susceptible. The FDIC estimated that jackpotting schemes cost United States banking institutions roughly $20 million (KES 2.5 billion) in 2025 alone.
The New Haven Homeland Security Task Force, which had been tracking the suspects for nearly a year, utilized advanced cell phone geolocation data to link the four individuals to the precise coordinates and timestamps of the thefts. The suspects currently face charges of interstate transportation of stolen property and conspiracy.
With all four individuals ordered held without bail, federal authorities are expanding their investigation to determine if the men are connected to a broader network of unresolved ATM breaches across the eastern seaboard.
As commercial banks globally assess the security of their remote dispensing networks, the Connecticut arrests serve as a definitive mandate for hardware modernization, proving that physical padlocks are no longer sufficient against digital lockpicks.
Keep the conversation in one place—threads here stay linked to the story and in the forums.
Sign in to start a discussion
Start a conversation this story and keep it linked here.
E-sports and Gaming Community in Kenya
The Role of Technology in Modern Agriculture (AgriTech)
Popular Recreational Activities Across Counties
Investing in Youth Sports Development Programs
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
