Eight Years for ATM Jackpotting: What the Sentence Tells Us About Cash Machine Crime

A Venezuelan national just received what prosecutors are calling a record federal prison term for a scheme that drained ATMs of millions. Here is what happened, and why it is harder to pull off than it looks on TV.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
An ATM machine photographed from the front with interior cash mechanisms visible through the open service panel, in a law enforcement evidence context
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Juan Manuel Gouveia-Aguilera was sentenced to 8 years in federal prison for his role in an ATM jackpotting scheme.
  • Prosecutors describe the sentence as a record federal term for this type of crime.
  • The scheme caused millions of dollars in losses, though an exact figure has not been made public.
  • ATM jackpotting is a physical-plus-digital attack that forces cash machines to dispense money on command.
  • Ordinary bank customers aren't directly liable for jackpotting losses, but the fraud raises costs across the financial system.

Juan Manuel Gouveia-Aguilera is going to prison for eight years. A federal judge handed down that sentence after Gouveia-Aguilera was convicted for his part in an ATM jackpotting operation: a scheme where criminals physically tamper with a cash machine and install malicious software to make it dispense cash on demand. SecurityWeek reported the sentencing. Prosecutors say it's a record for this kind of crime at the federal level.

How does ATM jackpotting actually work?

Jackpotting isn't a remote hack. It needs someone on the ground.

A criminal with a stolen or counterfeit technician's uniform approaches an ATM, often one sitting in a retail store or pharmacy rather than a bank branch. They open the machine's outer casing, plug in a laptop or small device, and install software that tricks the ATM's internal computer into accepting a command to empty its cash cassette. Bills cycle out continuously until the machine is empty or the crew walks away.

Historically, banks and ATM operators have left internal software on these machines unpatched for long stretches. Couple that with physical access controls that amount to a basic lock, and you've got a stealable pile of cash sitting in a pharmacy aisle.

Should ordinary people be worried?

Directly, no. When a criminal drains an ATM through jackpotting, the money lost belongs to the bank or the ATM operator, not individual account holders. Your savings aren't at risk from this particular method.

That doesn't mean the losses disappear. Banks and processors pass fraud costs back through fees and reduced services. Cash machine availability in lower-traffic areas gets worse when operators decide the security overhead isn't worth it. We've been tracking this pattern since our first ATM jackpotting story on 3 July 2026, and the calculus for small operators hasn't improved.

The key detail in this case is scale. Losses running into the millions from a single conspiracy signal an organised crew, not a solo opportunist.

What the eight-year sentence actually means

A record federal term sends a message, but it doesn't close the problem.

Jackpotting has been a known threat in the United States since at least 2018, when the Secret Service first warned financial institutions about a surge in attacks. The underlying vulnerability isn't sophisticated code. It's neglected hardware running software that was never designed to defend against someone who can physically open the box.

The postmortem writes itself every time: the ATM was reachable, the software was old, nobody noticed the machine was empty until a customer complained.

Jackpotting doesn't steal your card details, but it's a useful reminder that any machine you interact with in public is only as secure as its least-maintained component. Eight years is a serious number. The unpatched XFS middleware sitting inside a thousand ATMs right now is a more serious problem.

© 2026 Threat Vectr