DOJ Arrests Ploutus Developer in ATM Jackpotting Ring
The U.S. Justice Department said it arrested alleged Ploutus developer Anibal Alexander Canelon Aguirre, tying him to an ATM jackpotting ring that stole more than $5.4 million from banks and credit unions in at least 117 attacks between February 2024 and December 2025. Prosecutors also say the group moved the proceeds through laundering channels linked to Tren de Aragua.
Ploutus was built to make ATMs spit out cash on command, and the court filing says it also carried anti-analysis features and code meant to delete itself afterward. That matters because the machine can look ordinary again after the payout, which can slow forensic review and hide how many devices were touched.
For ATM operators and fraud teams, the case points to a criminal pipeline rather than a single-machine theft spree: the malware turns the device into a cash faucet, and the money trail can keep moving after the hardware is cleaned up. If cash-distribution machines sit in your environment, the exposure is not only the terminal but the laundering network that may already have absorbed the loss.
Alleged dev of Ploutus ATM malware appears in US court after arrest
Department of Justice has announced the arrest of the alleged developer of Ploutus malware, used to steal millions of dollars in ATM jackpotting attacks across the United States.