The DOJ's District of Connecticut release on the ATM jackpotting case is available in full, so the earlier source note saying full text was not retrieved has been removed.
Federal prosecutors said four Venezuelan nationals were charged with federal offenses related to the theft of more than $500,000 in an ATM jackpotting scheme. DOJ identified the defendants as Euclides Moreno Itanare, Willian Ricardo Flores, Alberto Jose Freites Arvilla, and Luis Jose Freites Arvilla. The release says the charges are allegations and that each defendant is presumed innocent unless and until proven guilty.
According to DOJ, the alleged conduct occurred in August 2025. Prosecutors said the defendants and others conspired to steal cash from at least nine ATMs in Connecticut using jackpotting methods, which often involve specialized hardware and malware that force a machine to dispense stored cash. DOJ said $529,220 was allegedly stolen from eight ATMs between August 8 and August 18, 2025, and that an Ansonia ATM was protected by a software patch that prevented a theft.
Credit-union relevance
The release does not say credit-union ATMs were involved. The relevance is operational: credit unions with branch, drive-up, and off-site ATM fleets should treat jackpotting as a combined physical-security, software-patching, vendor-response, and insurance-control issue.
The most useful review is practical. Confirm which party owns patching, who monitors physical tampering alerts, what video-retention rules apply, how quickly cash-loss events are escalated, and whether armored-car, ATM-servicer, and core/vendor contracts make incident responsibilities clear.
What to review
Credit unions should ask ATM vendors whether current anti-jackpotting patches are deployed, whether end-of-life machines remain in service, and how tamper events are reported after hours. Branch operations, IT, security, and finance should also understand how bond coverage applies to malware-assisted or physical ATM attacks.
The corrected takeaway is not that every credit union faces the same Connecticut pattern. It is that a real DOJ case shows why ATM fleet controls, patch records, and incident playbooks need to be current before an attack occurs.