Skip to content
Brief Security & Trust ·

US sanctions 10 targets in Tren de Aragua ATM malware scheme

Treasury named eight people and two Mexican firms in a scheme that uses malware to empty US ATMs.

In brief
  • Treasury named eight people and two Mexico-based firms in the ATM scheme. A gang leader tied to gold mining was named separately.
  • Treasury says the malware makes ATMs pay out without debiting an account. US firms must block and report the named parties' assets.

The U.S. Treasury's sanctions office, OFAC, named 10 targets in a Tren de Aragua ATM scheme: eight people and two Mexico-based companies. One is Anibal Alexander Canelon Aguirre, called "Prometheus," who is on the FBI's Ten Most Wanted list. Treasury calls him the alleged engineer of the malware. The same action separately named Juan Gabriel Rivas Nunez, a gang leader tied to gold mining and other crime. He is not part of the ATM network.

Treasury said reported losses from alleged US attacks reached $40.73 million by August 2025, across more than 1,500 incidents. It gave no newer total. BleepingComputer reported eight members sanctioned but listed only seven names. It said Aguirre allegedly built the Ploutus malware, which Treasury does not name.

Treasury says criminals break in, install malware and trigger it remotely, so the ATM skips its security and pays out without debiting an account. A physical break-in becomes a remote attack on the machine's trust in its own software. Banks should ask who can open cabinets and whether no-debit payouts trigger alerts. US firms must block and report assets of those named, and of entities they own 50% or more. Foreign banks knowingly handling significant deals for those named under E.O. 13224 risk losing US correspondent accounts.

A WebPulse Brief: a short report of an important event, written by the WebPulse Newsroom with AI assistance and checked against the reporting below. When there is more to explain, we follow up with a full story. How we use AI.

Reporting: U.S. Department of the Treasury.