Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
enforcement-actionransomware-group-operationfinancial-sector-threat

Cybercrime Prosecutions: ATM Jackpotting Deportations and Ransomware Guilty Plea

Updated 3mo agoFirst seen Jan 24, 20262 sources

U.S. authorities reported multiple enforcement actions against financially motivated cybercrime. In South Carolina, two Venezuelan nationals convicted in an ATM jackpotting scheme will be deported after serving their sentences; prosecutors said they physically accessed older ATM models, connected a laptop, and installed malware that bypassed security controls to force cash-out until the machines were emptied. The activity impacted banks across several southeastern states, with court-ordered restitution of $285,100 and $126,340 respectively, and investigators said evidence from the case contributed to a broader Nebraska indictment of dozens of individuals tied to a larger ATM-theft conspiracy.

Separately, a Russian national, Ianis Aleksandrovich Antropenko, pleaded guilty in federal court to conspiracy to commit money laundering and conspiracy to commit computer fraud and abuse for leading a ransomware operation that targeted at least 50 victims over a four-year period ending in August 2022; he faces up to 25 years in prison, financial penalties, restitution, and forfeiture, and the plea acknowledges potential immigration consequences. A third item describes convicted Bitcoin thief Ilya Lichtenstein seeking post-release work in cybersecurity, but it is not tied to the ATM jackpotting or Antropenko ransomware case and does not add incident-specific threat intelligence.

Share:
Cybercrime Prosecutions: ATM Jackpotting Deportations and Ransomware Guilty Plea
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

8 events from the most recent confirmed update back to the earliest known activity.

8 EVENTS
Jan 23, 20265mo ago

DOJ says five other Venezuelans face immediate deportation in related ATM cases

The Justice Department also reported that five additional Venezuelan nationals are subject to immediate deportation over similar ATM jackpotting thefts across multiple U.S. states. The cases involved malware-enabled cash-outs from older ATM models affecting banks in several southeastern states.

Two Venezuelans sentenced in ATM jackpotting case and face deportation

South Carolina federal prosecutors announced that Luz Granados and Johan Gonzalez-Jimenez, convicted in an ATM jackpotting scheme using a Ploutus malware variant, will be deported after serving their sentences. Gonzalez-Jimenez received 18 months in prison and restitution, while Granados was sentenced to time served with restitution and remains in custody pending deportation.

South Carolina ATM jackpotting investigation expands to wider federal case

Evidence developed in a South Carolina ATM jackpotting investigation was shared with Nebraska authorities. That information helped support a broader federal case indicting 54 people in a related nationwide ATM jackpotting conspiracy.

Jan 22, 20265mo ago

Antropenko pleads guilty in Texas federal court

Antropenko pleaded guilty in the U.S. District Court for the Northern District of Texas to conspiracy to commit money laundering and conspiracy to commit computer fraud and abuse. Prosecutors said he led the ransomware conspiracy while living in Florida and California, and the Justice Department seized millions in cryptocurrency, cash, and luxury vehicles tied to the case.

Jan 1, 20242y ago

Antropenko violates pretrial release conditions repeatedly

After his 2024 arrest, Antropenko violated his pretrial release conditions at least three times within a four-month period. The violations included two Southern California arrests involving dangerous behavior while under the influence of drugs and alcohol.

Antropenko arrested in the United States

U.S. authorities arrested Ianis Aleksandrovich Antropenko in 2024 in connection with the ransomware conspiracy. He was granted bail despite the flight-risk concerns that often arise in ransomware cases.

Aug 1, 20224y ago

Antropenko ransomware crime spree ends

The Antropenko-led ransomware conspiracy concluded in August 2022 after four years of activity. Investigators later tied the operation to money laundering and computer fraud offenses.

Aug 1, 20188y ago

Antropenko-led ransomware conspiracy begins targeting victims

A ransomware conspiracy led by Ianis Aleksandrovich Antropenko operated over a four-year period and ultimately targeted at least 50 victims using variants including Zeppelin and GlobeImposter. The campaign caused at least $1.5 million in victim losses before ending in 2022.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

1 LINKEDOpen in app
Malware
1 linked
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.