At a DOJ news conference, officials explained the mechanics behind so-called ATM "jackpotting" and said the scheme combined on-the-ground operatives with overseas technical operators. "There are several steps in a successful ATM jackpotting crime... They place an external drive that has the malware in it already," Leslie (S1) said while outlining the investigative findings.
Prosecutors said screen-sharing and remote code were used by overseas organizers to determine ATM contents and cause machines to dispense available currency. "Our investigation has assessed since 2021 that approximately $61,000,000 has come out of American banks across our country," Leslie said. The same briefing later included a separate HSI estimate of roughly $5,400,000 in actual losses and $1,400,000 in attempted losses; that numeric difference is recorded in the transcript and is noted here as an unresolved inconsistency between speakers.
Officials said the alleged malware author played a remote engineering role: developing code and providing the access necessary for ground crews to trigger dispensals. The briefing did not include technical indicators (file names, hashes) that could be used to independently verify the malware's characteristics.