OFAC sanctioned a Tren de Aragua ATM jackpotting network on 30 September 2026 and listed seven TRON addresses. What changes for screening, blocking and SARs.
Table of contents
The Tren de Aragua sanctions of 30 September 2026 put eight alleged ATM jackpotting facilitators, two Mexican companies and a gang leader on the SDN List. Seven entries carry TRON addresses that Treasury links to laundering stolen cash. US persons must block and report their property, and foreign banks face secondary sanctions risk.
- OFAC designated 10 targets in a Tren de Aragua (TdA) ATM jackpotting scheme, plus a TdA leader tied to illegal gold mining, under E.O. 13581 and E.O. 13224, both as amended.
- Seven of the nine individuals carry a TRON (TRX) digital currency address on their SDN entry, and all nine carry a Venezuelan cédula or Mexican CURP number.
- Treasury says reported US losses from alleged jackpotting reached 40.73 million dollars across over 1,500 attacks as of August 2025.
- Every new entry flags secondary sanctions risk under section 1(b) of E.O. 13224, which reaches foreign financial institutions that knowingly facilitate significant transactions.
- The Justice Department has indicted 98 people in jackpotting schemes since 21 October 2025.
What did OFAC announce about Tren de Aragua?
The Tren de Aragua sanctions added 11 names to the Specially Designated Nationals (SDN) List on 30 September 2026. Ten belong to an ATM jackpotting network that Treasury says is a key source of revenue for TdA. The eleventh is Juan Gabriel Rivas Nunez, described as a high-ranking leader directing gold mining and narcotics operations in South America.
Treasury's press release says the network is led from Mexico and Venezuela by Anibal Alexander Canelon Aguirre, known as "Prometheus", who is on the FBI's Ten Most Wanted list and is alleged to have engineered the malware. On the money trail, Treasury is specific: the network "uses cryptocurrency transactions to launder proceeds of ATM jackpotting."
The eight jackpotting individuals are indicted in the US District Court for the District of Nebraska, and Rivas Nunez in the Southern District of Texas, so the criminal conduct remains alleged. The blocking obligations, by contrast, apply from the designation date recorded in the OFAC recent actions notice.
| Item | Detail | Source |
|---|---|---|
| Date | 30 September 2026 | OFAC recent actions |
| Authorities | E.O. 13581 and E.O. 13224, both as amended | Treasury release |
| Programme tags | SDGT and TCO on every new entry | OFAC recent actions |
| Persons listed | 9 individuals and 2 Mexican companies | OFAC recent actions |
| Crypto identifiers | 7 TRON (TRX) addresses, one per entry | OFAC recent actions |
| Reported losses | 40.73 million dollars, over 1,500 attacks, as of August 2025 | Treasury release |
| Prosecutions | 98 people indicted since 21 October 2025 | Treasury release |
The two companies are Enigma Community, S. de R.L. de C.V., established in Tlalnepantla de Baz in June 2024, and Soluciones Integrales Toluca, S.A. de C.V., established in Toluca in 2016. OFAC designated Enigma Community for being owned or controlled by, or acting for, Oscar Leonardo Martinez Pirona, and Soluciones Integrales Toluca on the same basis for Alejandro Mejia Castillo. Each entry carries a Folio Mercantil registry number (N-2024061521 and N-2016012368), which KYB teams can match against Mexican commercial registry extracts.
How does ATM jackpotting turn into a laundering problem?
Jackpotting is a physical and cyber attack on the machine, not on a customer account. Treasury describes crews who survey ATMs, break in, install malware, then trigger it remotely to push a dispense command until the cassettes are empty. No account is debited, so the loss lands on the institution that owns the cash. The compliance exposure starts after the cash leaves the machine. Treasury says the proceeds move among TdA members and associates to conceal their origin, and that cryptocurrency is one of the methods. That is where banks, money services businesses and crypto exchanges come in: cash has to be placed, converted and moved across borders, and most of those steps pass through a regulated financial institution.
The Justice Department is prosecuting TdA-linked jackpotting crews from the criminal side. On 26 June 2026 it announced the sentencing of two Venezuelan nationals to 78 months each, and US Attorney Lesley Woods for the District of Nebraska called jackpotting TdA's "assessed primary source of revenue".
| Action | Date | What it did |
|---|---|---|
| TdA listed as a TCO | 11 July 2024 | OFAC sanctioned TdA as a Transnational Criminal Organization |
| TdA identified as an FTO | 20 February 2025 | The State Department identified TdA as a Foreign Terrorist Organization |
| Earlier OFAC TdA actions | 24 June, 17 July and 3 December 2025 | Targeted TdA leadership and key support networks |
| Xinbi Guarantee designation | 9 September 2026 | Designated a scam marketplace and listed 52 TRON addresses |
| TdA jackpotting network | 30 September 2026 | Designated 11 persons and listed 7 TRON addresses |
What sets the Tren de Aragua sanctions apart is the predicate: a cyberattack on bank hardware rather than a scam on consumers. The TdA dates come from Treasury's release; our report on the Xinbi Guarantee sanctions covers the September precedent.
What do the Tren de Aragua sanctions mean for your obligations?
The Tren de Aragua sanctions create blocking, reporting and screening duties for every US person, and reach foreign banks through secondary sanctions. In practice they touch four regimes: OFAC blocking and reporting, list screening on names and identity numbers, suspicious activity reporting, and correspondent banking due diligence for institutions outside the United States.
Blocking and reporting. Any property of the 11 persons, and of entities owned 50 percent or more, directly or indirectly, individually or in the aggregate, by one or more blocked persons, must be blocked. Under 31 CFR 501.603, the holder files a blocking report within 10 business days, then an annual report by 30 September on property held at 30 June. A rejected transaction that is not blocked still needs a report within 10 business days under 31 CFR 501.604. OFAC's FAQ 646 applies the same 10-day rule to blocked virtual currency.
Screening on more than names. Every new individual entry carries a national identity number, either a Venezuelan cédula or a Mexican CURP. A KYC file that holds a verified document number can be matched on that number, which is far more reliable than fuzzy name logic. It matters here because Spanish double surnames collide: the list now holds both Aslhy Javier Galeano Basurto and Jose Dario Galeano Bazurto. Rivas Nunez also appears with the spelling Nuñez, two Aponte Rodriguez aliases and the nicknames Juancho and Negro Juancho, while Canelon Aguirre is also listed as The Engineer.
Wallet screening. Exchanges and other virtual asset businesses should load the seven TRON addresses into on-chain screening and look back at exposure. OFAC's FAQ 562 warns that its address listings "are not likely to be exhaustive". If you hold digital currency at other addresses you believe are owned by, or otherwise associated with, an SDN, the FAQ expects you to block it and file a report with OFAC.
Suspicious activity reports. A bank must file a SAR on a suspicious transaction of at least 5,000 dollars within 30 calendar days of initial detection, or up to 60 days if no suspect has been identified, under 31 CFR 1020.320; for a money services business the threshold is 2,000 dollars under 31 CFR 1022.320. FinCEN's 2016 cyber-events advisory treats a cyber-event aimed at moving funds as an attempted suspicious transaction and counts the funds put at risk. A jackpotted ATM therefore belongs in the SAR process, with cyber indicators such as IP addresses, timestamps and the wallet addresses involved in the narrative. Our guide to the suspicious activity report covers the mechanics.
Correspondent banking. Every new entry carries a secondary sanctions flag under section 1(b) of E.O. 13224, as amended by E.O. 13886. Treasury says OFAC can prohibit or strictly condition a US correspondent or payable-through account for a foreign financial institution that knowingly conducts or facilitates a significant transaction for a designated person. Banks in Mexico and South America with US correspondents should treat these names as a correspondent-access risk, not only a local one.
What is still uncertain about the Tren de Aragua sanctions?
The biggest open question about the Tren de Aragua sanctions is coverage. Seven TRON addresses are a starting point, not a map of the network, and OFAC says so itself. Laundering through crypto rarely stays on one address, so firms that match only on the listed strings will miss funds that have already moved one hop away. The loss figure is also dated. Treasury's 40.73 million dollar total runs only to August 2025, more than a year before the designation, and covers alleged attacks reported in the United States. It describes scale, not the network's current revenue, and it does not say how much of that total this specific group took.
Liability is split unevenly. The institution whose ATM is attacked absorbs the cash loss, but sanctions exposure lands wherever the proceeds surface: an exchange that converts cash, a money transmitter that sends it south, or a foreign bank holding a front company's account. OFAC applies civil penalties on a strict liability basis, so an institution can be liable without knowing it dealt with a designated person.
Three more questions remain open. The release names no frozen amount, so the immediate financial effect is unknown. The two Mexican companies carry generic activity descriptions, education services and building construction, which ordinary business-purpose checks are unlikely to flag. And secondary sanctions turn on whether a transaction was knowing and significant, a judgement OFAC makes case by case, so foreign banks cannot know in advance where that line sits.
Why does a gang sanction matter to KYC teams?
The Tren de Aragua sanctions turn a street crime into a screening and onboarding problem. The identity data on these entries, cédula and CURP numbers, dates of birth and wallet addresses, is the same data a good KYC process already collects, so the match happens at onboarding and on every list update.
The weaker link is ongoing monitoring. A customer onboarded cleanly in 2025 can become a designated person overnight, as these 11 did on 30 September. Firms that re-screen their book only at periodic review will be late; firms that re-screen on each SDN update will not. For a deeper walkthrough of match logic, see our sanctions screening guide and the glossary entry on the OFAC check.
How should compliance teams respond?
After the Tren de Aragua sanctions, the first job is a full re-screen against the 30 September SDN update, because any property you find must be blocked and reported to OFAC within 10 business days of the date it is blocked. Match on cédula and CURP numbers, on the Nuñez, Aponte Rodriguez and nickname aliases, and on names. Then add the seven TRON addresses to wallet screening and run a lookback for direct and one-hop exposure.
For corporate customers in Mexico, check ownership and Folio Mercantil numbers against the two listed companies and apply the 50 percent rule. Brief ATM fraud and cybersecurity teams to route jackpotting incidents into the SAR process with technical indicators attached, and make sure BSA analysts can see them. Foreign banks with US correspondents should document how they would detect a significant transaction for these persons, since knowingly conducting or facilitating a significant transaction is the test for secondary sanctions.
Zyphe's sanctions screening software screens customers against sanctions and watchlists inside a verification flow that reads the document chip to ICAO 9303 and keeps personal data sharded across thousands of nodes with no central honeypot. If you want to see how that fits your onboarding and re-screening, book a demo.
The bottom line
The Tren de Aragua sanctions show how a violent gang's cash business reaches the compliance desk. The theft happens at the machine, but the laundering runs through accounts, exchanges and wallets that regulated financial institutions control. Teams that screen on verified identity numbers and wallet addresses, re-screen on every list update and route cyber incidents into SARs are the ones that will catch it.
Cited sources
- Treasury press release: Treasury sanctions financial network of Tren de Aragua after theft of millions from US banks, 30 September 2026
- OFAC recent actions, 30 September 2026: Counter Terrorism and Transnational Criminal Organizations designations
- US Department of Justice: two sentenced in international ATM jackpotting conspiracy with ties to Tren de Aragua, 26 June 2026
- 31 CFR 501.603: reports of blocked, unblocked or transferred blocked property
- 31 CFR 501.604: reports of rejected transactions
- 31 CFR 1020.320: reports by banks of suspicious transactions
- 31 CFR 1022.320: reports by money services businesses of suspicious transactions
- OFAC FAQ 562: how OFAC identifies digital currency information on the SDN List
- OFAC FAQ 646: how to block digital currency
- FinCEN advisory FIN-2016-A005 on cyber-events and cyber-enabled crime
Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.