Key Highlights
- OFAC designated 10 individuals and entities allegedly linked to a Tren de Aragua (TdA) financial network.
- Treasury said the network used malware to force U.S. ATMs to dispense cash in jackpotting attacks.
- Cryptocurrency transactions were allegedly used to launder proceeds from the ATM thefts.
The U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) has designated 10 targets involved in a Tren de Aragua (TdA)-linked ATM jackpotting scheme that allegedly stole millions of dollars from U.S. financial institutions.
According to the Office of Foreign Assets Control (OFAC) report published on September 30, identifying the network as a source of revenue for TdA, which the U.S. government has designated as a Foreign Terrorist Organization.
Treasury said the group used malware to force ATMs to dispense cash and later used several methods, including cryptocurrency transactions, to move or launder the proceeds.
Malware used to force ATMs to dispense cash
Treasury described the attacks as ATM jackpotting, a type of cyberattack in which criminals install malware that allows them to bypass normal controls and force an ATM or interactive teller machine to dispense cash without a corresponding customer withdrawal.
According to the Treasury, the attacks typically involved several stages, including identifying target machines, gaining physical access, installing malware, and remotely activating the software to trigger cash withdrawals.
The department identified Anibal Alexander Canelon Aguirre, also known as “Prometheus,” as an alleged organizer of the network and the engineer behind the malware used in the attacks.
Treasury said the network coordinated crews operating in the United States to target financial institutions.
Crypto allegedly used to launder ATM proceeds
The sanctions notice said the stolen cash was moved among TdA members and associates to conceal its origins.
Cryptocurrency was one of the methods allegedly used to launder the proceeds.
The Treasury said Canelon Aguirre and several other individuals used crypto transactions to facilitate the movement of funds generated through the ATM attacks.
The agency’s announcement distinguishes the role of cryptocurrency from the initial theft: the ATM jackpotting was carried out using malware, while digital assets were allegedly used afterward to move or conceal some of the proceeds.
Jackpotting losses reach $40.7 million
Treasury said reported losses from alleged ATM jackpotting attacks in the United States totaled approximately $40.73 million across more than 1,500 attacks as of August 2025.
The department also said the Department of Justice had indicted 98 individuals since October 21, 2025, in connection with ATM jackpotting schemes.
The cases involve allegations including bank burglary, bank fraud, money laundering, unauthorized access to protected computers, and providing material support to a designated foreign terrorist organization.
The defendants remain subject to the legal process, and the allegations against them have not been established in court unless proven.
OFAC targets TdA leaders and associated companies
The latest action includes Juan Gabriel Rivas Nunez, also known as “Juancho,” whom Treasury identified as a high-ranking TdA leader operating across several South American countries.
OFAC also designated Mexico-based companies Enigma Community, S. de R.L. de C.V. and Soluciones Integrales Toluca S.A. de C.V., which Treasury linked to individuals targeted in the action.
The sanctions generally block property and interests in property belonging to designated persons that are in the United States or under the control of U.S. persons. The restrictions also generally apply to entities owned 50% or more by blocked persons.
Separate FinCEN analysis flags crypto scam activity
The Treasury action comes as U.S. financial authorities continue examining the use of digital assets in other forms of financial crime.
On September 3, the Financial Crimes Enforcement Network (FinCEN) said it had analyzed 33,904 Bank Secrecy Act reports involving suspected digital-asset investment scams filed between September 2023 and December 2025.
Those reports represented approximately $12.7 billion in suspected financial activity linked to digital-asset investment scams, according to FinCEN.
FinCEN said the scams were largely connected to overseas operations that used fake identities, social engineering, fraudulent investment platforms, and networks of money launderers. The agency also identified stablecoin transfers to overseas digital-asset exchanges as one method used to move suspected scam proceeds.
The FinCEN analysis is separate from the TdA case and does not establish a connection between the two sets of activity.
Crypto remains part of broader financial crime investigations
The latest OFAC action illustrates how cryptocurrency can appear within a wider criminal financial network rather than necessarily being the mechanism used to commit the underlying offense.
In the TdA case, Treasury alleges that criminals first obtained cash through ATM jackpotting and subsequently used cryptocurrency transactions among other methods to launder some of the proceeds.
The separate FinCEN analysis involves investment scams in which victims were allegedly persuaded to transfer funds directly into fraudulent digital-asset schemes.
For investigators, both types of cases can involve financial trails spanning bank accounts, cash, crypto wallets, exchanges and entities across multiple jurisdictions.
The Treasury’s latest designations therefore add another enforcement action involving digital assets within a broader investigation into financial networks associated with cybercrime and organized criminal activity.
Also Read: Ex-NCA Officer Ordered to Pay £1.8M Over Stolen Bitcoin
