Eight Years for ATM Jackpotting: What the Sentence Tells Us About Cash Machine Crime

A Venezuelan national just received what prosecutors are calling a record federal prison term for a scheme that drained ATMs of millions. Here is what happened, and why it is harder to pull off than it looks on TV.

ThreatVectr Newsdesk· 3 min read
Full-frame overhead view of a modern silver laptop on a dark wooden desk, screen showing a blurred generic system password dialog with a red warning glow, apps
Share

Key points

  • Juan Manuel Gouveia-Aguilera was sentenced to 8 years in federal prison for his role in an ATM jackpotting scheme.
  • Prosecutors describe the sentence as a record federal term for this type of crime.
  • The scheme caused millions of dollars in losses, though an exact figure has not been made public.
  • ATM jackpotting is a physical-plus-digital attack that forces cash machines to spit out money on command.
  • Ordinary bank customers are not directly liable for jackpotting losses, but the fraud raises costs across the financial system.

Juan Manuel Gouveia-Aguilera is going to prison for eight years. A federal judge handed down that sentence after Gouveia-Aguilera was convicted for his part in an ATM jackpotting operation, meaning a scheme where criminals physically tamper with a cash machine and install malicious software, which is code designed to cause harm, to make it dispense cash on demand like a broken slot machine paying out.

Prosecutors say the sentence is a record for this kind of crime at the federal level. SecurityWeek first reported the sentencing.

How does ATM jackpotting actually work?

Jackpotting is not a remote hack. It needs someone on the ground.

The basic method: a criminal with a stolen or counterfeit technician's uniform approaches an ATM, often one sitting in a retail store or pharmacy rather than a bank branch. They open the machine's outer casing, plug in a laptop or small device, and install software that tricks the ATM's internal computer into thinking it is receiving a legitimate command to empty its cash cassette. The machine then cycles out bills continuously until it is empty or the crew stops it.

The failure mode here is that banks and ATM operators have, historically, left the internal software on these machines unpatched and unmonitored for long stretches. An ATM running outdated software is easy to trick. Add a physical access control that amounts to a basic lock, and you have a very stealable pile of cash.

Should ordinary people be worried?

Directly, no. When a criminal drains an ATM through jackpotting, the money lost belongs to the bank or the ATM operator, not to individual account holders. Your savings are not at risk from this particular method.

In practice, that does not mean the losses disappear. Banks and processors pass fraud costs back through fees and reduced services. Cash machine availability in lower-traffic areas gets worse when operators decide the security overhead is not worth it.

The key detail in this case is scale. Losses running into the millions from a single conspiracy signal an organised crew, not a solo opportunist.

What the eight-year sentence actually means

A record federal term sends a message, but it does not close the problem.

Jackpotting has been a known threat in the United States since at least 2018, when the Secret Service first warned financial institutions about a surge in attacks. The underlying vulnerability is not sophisticated code. It is neglected hardware running software that was never designed to defend against someone who can physically open the box.

One thing the post-mortem will say every time: the ATM was reachable, the software was old, and nobody noticed the machine was empty until a customer complained.

Keep your card details to yourself. Jackpotting does not steal them, but it is a useful reminder that any machine you interact with in public is only as secure as its least-maintained component.

© 2026 Threat Vectr