FBI’s First Cyber Fugitive Captured — DOJ Says ATM Scheme Reached 47 States

aguirre-featured.jpg

The FBI’s first cyber fugitive is back on American soil, and the case against him reads like a collision between organized crime, computer hacking and terrorism financing.

Anibal Alexander Canelon Aguirre — known by the aliases “Prometheus” and “The Engineer” — appeared in federal court in Nebraska on Friday after being apprehended in Venezuela and transferred to the United States.

Federal prosecutors allege that he helped build an ATM “jackpotting” operation that reached 47 states, Washington, D.C., and several foreign countries. The machines were allegedly infected with malware and forced to spit out cash without debiting a customer’s account.

HUGE NEWS in Omaha today. Congrats to @FBIOmaha and @USAO_NE on this incredible ATM Jackpotting investigation and capture of an FBI Ten Most Wanted fugitive.

NSP is proud to be a part of the team assisting in the investigation.

Learn more here: justice.gov/opa/pr/apprehended…

— Nebraska State Patrol (@NEStatePatrol) October 2, 2026

The Justice Department says Canelon Aguirre, 50, is an alleged leader of Tren de Aragua, the Venezuelan gang President Trump designated a foreign terrorist organization. He was added to the FBI’s Ten Most Wanted Fugitives list in March as the list’s 540th entrant and its first alleged cyber criminal.

He pleaded not guilty at his initial appearance in Omaha and was ordered detained. The charges are allegations, and he is presumed innocent unless proven guilty in court.

The indictment accuses Canelon Aguirre of participating in conspiracies involving bank fraud, bank burglary, computer fraud, money laundering and material support for terrorists. The bank-fraud conspiracy charge carries a maximum penalty of 30 years in prison; the money-laundering conspiracy charge carries up to 20 years.

Prosecutors say the crews physically broke into ATMs, installed malware and then remotely triggered unauthorized cash withdrawals. They allege Canelon Aguirre developed a strain called Ploutus that included features designed to hinder analysis and delete itself after an attack.

That technical detail matters. This was far beyond a thief showing up with a stolen bank card.

The government describes an international operation that combined physical access, custom malware, cash crews and laundering networks.

FBI's first cyber fugitive on Ten Most Wanted list returns to US after capture in Venezuela

Alleged Tren de Aragua leader Anibal Alexander Canelon Aguirre pleaded not guilty to ATM jackpotting conspiracy in Nebraska

#cyber #fugitive #crime #FBI

— Dan Lohrmann (@govcso) October 3, 2026

The scale of the larger investigation is enormous. The Justice Department says 120 defendants have been charged in the Nebraska case, with three already sentenced to 78, 78 and 96 months in prison.

Since the terrorist designation, nearly 350 alleged Tren de Aragua members and associates have been charged nationwide.

FBI Director Kash Patel called Canelon Aguirre the tenth Top Ten fugitive captured under President Trump. Patel also said 107 wanted foreign fugitives have been returned from 43 countries during the past 18 months — an increase of more than 90 percent from the previous 18-month period.

Those figures show why cross-border cooperation matters. Criminal networks exploit borders, currencies and digital systems. Law enforcement has to move just as deliberately across those same lines.

The Treasury Department’s Office of Foreign Assets Control sanctioned Canelon Aguirre and nine other alleged Tren de Aragua figures and entities two days before his court appearance. Treasury used both transnational-crime and counterterrorism authorities in the action.

Treasury described ATM jackpotting as a key revenue stream for the organization and said stolen cash was moved among members and associates, including through cryptocurrency. As of August 2025, U.S. financial institutions had reported more than 1,500 such attacks and approximately $40.7 million in losses.

The sanctions package also named figures and companies in Mexico and Venezuela that Treasury says supported the network. Any property or interests in property under U.S. jurisdiction are blocked, and U.S. persons are generally prohibited from dealing with the designated targets.

Sanctions are not criminal convictions, and Treasury’s allegations remain distinct from the charges being litigated in Nebraska. Together, however, the two actions show the government attacking the alleged network from both directions: a prosecution aimed at prison time and financial restrictions aimed at the money.

ATM malware is not “cyber noise” when the cash lands in a designated terrorist organization’s accounts.

On 30 Sep 2026, Treasury’s OFAC designated 10 Tren de Aragua (TdA)–linked targets after a jackpotting fraud scheme that has become a key revenue stream for the group. Dual authorities: E.O. 13581 (TCO) and E.O. 13224 (counterterrorism / SDGT). State designated TdA an FTO on 20 Feb 2025; OFAC had already listed it as a TCO on 11 Jul 2024.

What jackpotting means in practice: crews break into U.S. ATMs, install malware, then remotely force the machines to dispense cash until empty — without debiting a customer account. Proceeds move among TdA members and associates, including through cryptocurrency, to conceal origin.

Scale (Treasury figures, as of Aug 2025): reported U.S. losses of $40.73 million across more than 1,500 attacks. Since 21 Oct 2025, DOJ has indicted 98 individuals in related jackpotting cases, with charges that include material support to a designated FTO, bank burglary, money laundering, and computer fraud — many in the District of Nebraska investigation.

Lead figure: Aníbal Alexander Canelón Aguirre (“Prometheus”), on the FBI’s Ten Most Wanted list. Treasury describes him as the alleged malware engineer who deploys crews into the United States and has been photographed with crime proceeds. Network nodes sit in Mexico and Venezuela; OFAC also listed associates and two Mexico-based companies (Enigma Community; Soluciones Integrales Toluca).

Same package, different lane: Juan Gabriel Rivas Núñez (“Juancho”), a high-ranking TdA leader directing operations across multiple South American countries — including illicit gold mining, narcotics export, and violent crime. Indicted in the Southern District of Texas (Dec 2025) for material support to TdA; designated under the same dual TCO + SDGT authorities.

My view: designation packages that hit malware facilitators, crypto rails, and plaza-to-mine leadership in one action are how financial targeting keeps up with diversified FTO revenue — not just narcotics. The binding question is always follow-through: SDN listing plus prosecutions plus partner disruption of the cash-out and laundering nodes.

For practitioners watching TdA finance: where does your organization’s next move land first — ATM malware indicators, crypto off-ramps tied to this network, or Juancho-linked gold/narcotics facilitation in the Southern Cone and Andes — and which of those are you actually staffed to work?

Based on U.S. Treasury OFAC press release sb0640 (30 Sep 2026) and related DOJ charging summaries in open reporting.

#WesternHemisphere #TrenDeAragua #TdA #OFAC #Sanctions #FTO #FinancialCrime #CyberCrime

— Seth Price (@sethprice02) October 2, 2026

The government’s case still has to survive the courtroom. But the capture itself is a major law-enforcement result: an accused malware engineer tied to an alleged terrorist-financing network is no longer beyond the reach of an American judge.

That is what accountability looks like when the borderless promise of cybercrime finally meets a federal courtroom in Nebraska.

Photo: Official FBI image of Anibal Alexander Canelon Aguirre. Color and landscape framing enhanced.

This is a Guest Post from our friends over at 100 Percent Fed Up. View the original article here.

Continue reading...

[ H/T WLT Report ]

Comments

There are no comments to display
Back
Top