Case file · ATM HEIST 2013

How the $45 million ATM heist worked: prepaid cards with no limits

Published 2026-09-29 · 5 min read · Missing control: Vendor controls on prepaid card limits

About $40 million came out of ATMs in 24 countries in roughly 10 hours in February 2013, and the thieves never touched a bank vault or a customer's account.[1] The money came from a handful of prepaid cards whose limits had been erased inside a card processor's systems. This case file covers how the scheme worked, how the New York cashing crew was caught, what it cost, and the one control that was missing.

What happened

Prosecutors in Brooklyn called these "unlimited operations." A hacking team would break into a company that processes prepaid debit cards for a bank, steal card data, and lift the withdrawal limits and balances on those cards. The card numbers and PINs went out to crews in many countries, who copied them onto blank magnetic-stripe cards and waited for a start signal.[1][3]

The first big run in this series hit in February 2011 and took about $10 million through some 15,000 withdrawals in 18 countries.[3] On December 21 and 22, 2012, the crew hit prepaid travel cards issued by the National Bank of Ras Al-Khaimah in the United Arab Emirates, whose cards were processed by a company in India. That run took about $5 million from roughly 4,500 withdrawals in about 20 countries, including nearly $400,000 from more than 140 ATMs in New York City in under 2.5 hours.[1][5]

Then came the big one. On February 19, 2013, the cashers went to work on prepaid cards issued by Bank Muscat of Oman, handled by a different card processor with offices in India.[1][5] Over about 10 hours they made roughly 36,000 withdrawals in 24 countries and took about $40 million. In New York alone, the local cell made about 2,904 withdrawals and collected $2.4 million between 3 p.m. on February 19 and 1:26 a.m. the next morning.[1]

How it worked

A prepaid debit card normally carries a fixed balance and a daily withdrawal cap. Those numbers live not on the card but in the systems of the processor that authorizes each transaction. According to prosecutors, the hackers got into those processor networks, gave themselves administrator-level privileges, and changed the settings on a small number of cards so that both the balance and the cap disappeared.[1][4] Bank Muscat said only about a dozen prepaid travel cards were involved in its losses.[6]

That is the trick at the heart of the scheme. The same few card numbers could be cloned onto many plastic cards and used at thousands of machines at once, and every request was approved because the system saw no limit to hit. The attack only stopped when someone at the issuer or processor noticed and shut the cards down.[1] Nothing checked whether a single prepaid card making thousands of withdrawals across 2 dozen countries in one night made any sense.

How it was caught

Cash on that scale is hard to hide. Prosecutors said the New York cell laundered its take through bank deposits, including nearly $150,000 in $20 bills paid into a single branch in Miami, and spent it on luxury goods. The government seized cash, 2 Rolex watches and a Mercedes SUV, and moved to forfeit a Porsche.[1][2] On May 9, 2013, federal prosecutors in Brooklyn charged 8 members of the New York cell with access device fraud and money laundering conspiracy.[1] Their alleged leader had been killed in the Dominican Republic in April 2013, before the charges were announced.[1] By November 12, 2013, 3 members, Evan Jose Peña, Elvis Rafael Rodriguez and Emir Yasser Yeje, had pleaded guilty.[2]

The hacker at the top took longer. Ercan Findikoglu, a Turkish national prosecutors described as a leader of all 3 operations, was brought to the U.S., pleaded guilty on March 1, 2016, and on February 10, 2017, was sentenced to 8 years in prison and ordered to pay more than $55 million in restitution.[3][4]

What it cost

The 3 operations together took more than $55 million.[3] Bank Muscat put its own loss at about $39 million, roughly a tenth of its expected earnings for the year, and later said its insurers had agreed to cover it.[6][7] The processors' names ended up in headlines around the world, and the Indian processor that handled Bank Muscat's cards said its customers had been harmed by what it called a sophisticated crime.[5]

The missing control

The missing control: vendor controls on prepaid card limits. The banks let an outside processor hold the switch that set how much money each card could release, with no independent check on changes to it and no hard ceiling the vendor could not override.

If raising a card's limit had required approval from someone outside the processor's own admin accounts, or if the bank had set a firm cap that no processor setting could lift, the stolen access would have been worth far less. A simple velocity rule, flagging a single card used hundreds of times in an hour, would have stopped the run early instead of after 10 hours.[1] The banks outsourced the work. They could not outsource the risk.

What to do in your business

Watch the case
Forty Million Dollars From ATMs in About Ten HoursDrops 2026-12-08
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More vendors and third parties cases

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. U.S. Attorney's Office, E.D.N.Y.: Eight members of New York cell of cybercrime organization indicted in $45 million cybercrime campaign
  2. U.S. Attorney's Office, E.D.N.Y.: Members of New York cell of cybercrime organization plead guilty in $45 million cybercrime campaign
  3. U.S. Attorney's Office, E.D.N.Y.: Leader of three worldwide cyberattacks sentenced to 8 years for computer intrusion and access device fraud
  4. U.S. Attorney's Office, E.D.N.Y.: Leader of global cybercrime campaigns pleads guilty
  5. Daily FT (Reuters): Indian companies at center of global cyber heist
  6. Finextra: Bank Muscat hit by $39m pre-paid card fraud
  7. Finextra: Bank Muscat to recover $39m card fraud losses