US sanctions Tren de Aragua-linked network
The United States sanctioned 10 people and entities tied to a financial network linked to Tren de Aragua, accused of ATM hacks.
The United States sanctioned 10 people and entities linked, according to U.S. authorities, to a financial network tied to Tren de Aragua that was accused of carrying out cyberattacks on ATMs to steal millions of dollars from financial institutions in the country.
The United States sanctioned 10 people and entities linked, according to U.S. authorities, to a financial network tied to Tren de Aragua. The network was accused of carrying out cyberattacks on ATMs to steal millions of dollars from financial institutions in the country.
What did the United States say about the sanctioned network?
U.S. authorities linked the group to operations designed to pull money from ATMs through hacking. The materials provided do not name the individuals or entities sanctioned, but they say the action covered 10 targets, including individuals and related entities.
The allegation places the scheme inside a financial network associated with Tren de Aragua. According to the source, the aim was to obtain millions of dollars from financial institutions in the United States.
What other attacks and campaigns appear in the same picture?
Mandiant said that over several weeks there were attacks against government and financial organizations, with dozens of victims, including some targeted by alleged state-sponsored actors. At the same time, other investigations reported phishing campaigns allegedly attributed to TA419 against U.S. experts in artificial intelligence policy.
SecurityWeek reported that Charles Carmakal said dozens of organizations were among the victims. Some had already been attacked by alleged state-sponsored actors, which points to a broader scope for the weeks-long campaigns against NetScaler.
The Register, citing Proofpoint, said that in July 2026 TA419 impersonated Lynne Edwards Parker, former principal deputy director of the White House Office of Science and Technology Policy, and Heidi Crebo-Rediker. The operational goal was to gain access to cloud accounts belonging to U.S. AI policy specialists.
CyberScoop added that the campaign also impersonated an Anthropic employee and that the targets worked at think tanks, universities, and law firms. Nextgov, meanwhile, said the attempts sought to compromise cloud accounts of artificial intelligence policy experts by impersonating a former White House technology official, a State Department economist, and a senior Anthropic employee.
How firm is the attribution of those campaigns?
The attribution to TA419 should be read cautiously because the cited reports present it as a hypothesis from the sources investigating the case. Proofpoint described TA419 as a China-aligned cyberespionage group, but in the materials provided several references appear as alleged or attributed by those firms.
In that same set of reports, the campaigns targeted cloud accounts of U.S. artificial intelligence policy specialists. The targets included people at think tanks, universities, and law firms, along with profiles tied to the White House, the State Department, and Anthropic.
Sources
- Proofpoint atribuye a hackers vinculados a China una campaña contra expertos en políticas de IA de EE.UU.diariobitcoin.com· Diario Bitcoin
- Un ciberataque podría exponer información militar y de seguridad nacional: qué tan vulnerable está Perúinfobae.com· Infobae
- Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attackssecurityweek.com· SecurityWeek
- EE.UU. sanciona a red del Tren de Aragua acusada de robar millones de dólares en cajeros mediante hackeoslaopinion.com· La Opinión
- Suspected Chinese spies spoofed an Anthropic exec, ex-White House official in AI phishingtheregister.com· The Register
- AI policy circles targeted in China-linked phishing operationcyberscoop.com· CyberScoop
- China-linked hackers posed as former US officials, Anthropic employee to target AI expertsnextgov.com· Nextgov



