Home.Treasury Treasury Sanctions Tren de Aragua's Financial Network Amid ATM Theft Scheme
Article Content
- •OFAC sanctioned 10 individuals linked to Tren de Aragua for ATM thefts.
- •The fraud scheme uses malware to exploit U.S. ATMs, stealing millions.
- •Anibal Alexander Canelon Aguirre, a key figure, is one of the FBI's most-wanted fugitives.
On September 30, 2026, the U.S. Department of the Treasury's OFAC sanctioned 10 individuals linked to Tren de Aragua (TdA), a Foreign Terrorist Organization involved in a fraud scheme targeting U.S. banks. The scheme, orchestrated by Anibal Alexander Canelon Aguirre (aka 'Prometheus'), utilizes malware to exploit ATMs, forcing them to dispense cash. The stolen funds are laundered and sent to TdA members in various countries. This operation is part of a broader effort to dismantle TdA's financial networks, which have been linked to various criminal activities including drug trafficking and human trafficking. The sanctions reflect ongoing government actions against transnational criminal organizations since 2025. The Treasury aims to protect the U.S. financial system from exploitation by such groups.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Magic Casa De Cambio in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What is Tren de Aragua?
How does the ATM theft scheme work?
What actions should financial institutions take?
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…