Tren de Aragua ATM Jackpotting Sanctions Target $40.73 Million Scheme
The U.S. Treasury sanctioned 10 individuals and companies linked to a Tren de Aragua ATM malware scheme that caused over $40.7 million in losses.

The U.S. Treasury Department has sanctioned eight individuals and two Mexican companies for their role in a transnational ATM jackpotting scheme that stole $40.73 million from U.S. Financial institutions. Officials tracked more than 1,500 attacks as of August 2025, with the proceeds allegedly serving as a key revenue source for the Venezuelan criminal organization Tren de Aragua.
The Treasury’s Office of Foreign Assets Control (OFAC) designated the targets under Executive Orders 13581 and 13224. This action blocks their property interests in the U.S. and exposes foreign financial institutions to secondary sanctions for facilitating significant transactions on their behalf. The sanctions follow a joint investigation by the FBI, Homeland Security Investigations, the Financial Crimes Enforcement Network, and the Justice Department.
Cryptocurrency laundering infrastructure exposed
Analysis of the scheme reveals a sophisticated money laundering operation. The network used shared laundering infrastructure, including stablecoins, that services multiple criminal organizations across Latin America. Blockchain analysis firm TRM found that seven designated TRON addresses received approximately $6.1 million in total inflows since March 2022.
These addresses are deposit addresses hosted at a centralized exchange, placing compliance responsibilities on virtual asset service providers. Funds from these addresses were sent to other Tren de Aragua-associated addresses, which then transferred about $35 million to a network linked to Jorge Figueira, a Venezuelan national charged with laundering approximately $1 billion. Chainalysis experts said: "The network relied on shared laundering infrastructure, including stablecoins, that services multiple criminal organizations across Latin America."
Counterparties of the wallets had exposure to laundering operations used by Colombian and Mexican drug cartels. Stolen money was moved through Tren de Aragua members and associates across several countries.
Key figures and indictments detailed
The alleged orchestrator of the network is Anibal Alexander Canelon Aguirre, also known as Prometheus. U.S. Officials claim he is the engineer behind the Ploutus malware used in the attacks and is now among the FBI's ten most-wanted fugitives. The Treasury Department states it has photographs of Aguirre with proceeds of the crimes.
Since October 21, 2025, the Department of Justice has indicted 98 individuals for involvement in these international ATM jackpotting schemes. Five men pleaded guilty to related charges last month. Six alleged associates of Canelon Aguirre were designated, each linked to one of the seven TRON addresses.
The two Mexico-based companies sanctioned are Enigma Community, S. De R.L. De C.V., owned by Oscar Leonardo Martinez Pirona, and Soluciones Integrales Toluca, S.A. De C.V., owned by Alejandro Mejia Castillo. The scheme involved using malware to force ATMs to dispense cash without debiting customer accounts, a process requiring surveillance, malware installation, and remote activation.
Joint law enforcement action against transnational crime
This action is part of a broader campaign resulting in more than 30 actions against over 300 individuals and entities linked to transnational criminal organizations since 2025. Another target was Juan Gabriel Rivas Nunez, known as 'Juancho,' a senior Tren de Aragua leader involved in illicit gold mining and narcotics, who was indicted in December 2025.
OFAC described Tren de Aragua as a Foreign Terrorist Organization involved in drug trafficking, human trafficking, extortion, and money laundering. The Justice Department has repeatedly claimed there are extensive direct and indirect links between the Ploutus malware and the criminal group. Experts have warned for nearly a decade about variants of Ploutus, which Google researchers previously called one of the most advanced ATM malware families they had seen.
Treasury Secretary Scott Bessent stated the administration would continue targeting the group's financial networks. Foreign financial institutions may face secondary sanctions exposure if they facilitate significant transactions for the designated persons.





