FBI names alleged ATM jackpotting malware developer
The FBI added Anibal Alexander Canelon Aguirre to its Ten Most Wanted list for allegedly developing ATM jackpotting malware that funded the Tren de Aragua gang.
The FBI has placed Anibal Alexander Canelon Aguirre, the first cybercrime subject ever added to its Ten Most Wanted Fugitives list, on the list for allegedly leading and developing malware behind a large-scale ATM jackpotting scheme. Since at least 2017, and more actively since January 2024, Canelon Aguirre and associated crews are accused of installing malware on ATMs across the United States to force unauthorized cash dispensing not tied to any account, with proceeds laundered through a complex network to fund the transnational gang Tren de Aragua (TdA).
According to the FBI, over 1,800 jackpotting incidents have been reported in the U.S. since 2017, resulting in more than $55 million in losses, with Canelon Aguirre allegedly continuously updating the malware to bypass ATM protections and expand the range of targeted machine models. He was charged in December 2025 in the District of Nebraska with conspiracy to commit bank fraud, bank burglary, intentional damage to a protected computer system, money laundering, and providing material support to terrorists. The case is being pursued through Joint Task Force Vulcan alongside DOJ's Computer Crime and Intellectual Property Section, with a $1 million reward offered for information leading to his capture.
While the underlying malware and technical tradecraft (ATM jackpotting) represent an established cybercriminal technique, this article is primarily a law-enforcement wanted-fugitive announcement rather than a technical threat report. The financial services sector remains the primary target given the direct exploitation of ATM infrastructure.
Mentioned in this report
Source reporting: https://www.fbi.gov/news/stories/anibal-alexander-canelon-aguirre-added-to-fbis-ten-most-wanted-fugitives-list
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free