The Riviera Maya ATM gang: when the skimmer came with the machine
Most ATM skimming gangs sneak a device onto somebody else's cash machine. According to investigative reporters, the crew behind Mexico's biggest skimming operation skipped that step and ran its own fleet of ATMs, with the skimmers already inside.[1][2] This case file covers what reporters found, how the scheme was said to work, what happened to the people behind it, and the control that was missing.
What happened
In September 2015 a security journalist published a 3-part investigation into cash machines in Mexico's Yucatan Peninsula. He found nearly 2 dozen ATMs in tourist areas that had been fitted with skimming devices that could be read over Bluetooth, the short-range wireless standard used by headphones and phones.[1] Many of the machines carried the same brand name: Intacash.[1][2]
In 2020 the Organized Crime and Corruption Reporting Project, a network of investigative journalists, published its own long investigation and gave the group a name: the Riviera Maya gang.[1] Reporters said the Romanian-led group owned and operated Intacash and had skimmers inside at least 100 of its ATMs, in resort towns including Cancun, Cozumel, Playa del Carmen and Tulum, and in other cities such as Puerto Vallarta and Tijuana.[1][2]
The reporting estimated the group's total take at about $1.2 billion over roughly 8 years, drawn from the bank accounts of tourists and locals who used the machines.[1][2] Reporters also tied the group to bribes paid to Mexican officials and politicians, and to threats against people who got in its way.[1][2]
How it worked
A normal skimmer is a fake card reader glued over the real one. It can be spotted by a careful customer or a bank technician. Reporters said the Riviera Maya gang did not need that trick, because it controlled the machines themselves. The skimming parts were installed inside the ATM cases, out of sight, and could be read wirelessly by someone standing nearby.[1]
The gang also went after the people who service other companies' machines. According to the reporting, installers linked to Intacash offered ATM technicians many times their monthly pay in exchange for periodic access to the machines they looked after.[1] A person who holds the keys to an ATM can place a device inside it that no customer will ever see.
The card data was then used to make cloned cards, and withdrawals were made far away from Mexico, in countries including India, Indonesia and Taiwan. Reporters said the crew often waited around 3 months before using the stolen data, which made it much harder for banks to work out which ATM had been the source.[1] By one estimate each compromised machine captured about 1,000 cards a month.[1]
How it was caught
Journalists, not bank fraud alerts, first put the scheme on the public record. The 2015 investigation found the hacked machines by scanning for the skimmers' wireless signals with a smartphone.[1] Intercepted communications reported later showed the group's leadership reacting to that coverage by ordering operations shut down.[1]
The pressure built from there. In 2019 the Mexican bank that sponsored Intacash suspended its contract to process transactions, and Mexican police arrested the man reporters describe as the gang's leader on a weapons charge.[1] In February 2021 a Mexican Green Party leader resigned after reports that he had taken money from the group.[2]
On May 27, 2021, the alleged boss, a Romanian national living in Mexico, was arrested in Mexico City on a Romanian extradition warrant; the arrest was reported the next day.[2] Romanian prosecutors had brought charges against him that included organized crime, attempted murder and blackmail.[1][2]
What it cost
The $1.2 billion figure is a reporters' estimate, not a court finding, and no official total has been published. It came from the number of cards each machine captured and the average amount taken from each account.[1] Several members of the group have since been sentenced in Romania, and a member and his wife were sent to prison by a US court.[3][4] For tourists, the cost landed quietly: withdrawals from far-off countries months after a beach holiday, with no obvious link back to the ATM in the hotel lobby.
The missing control
The missing control: vetting who owns and services the machines. The gang did not beat the ATM network's defenses from outside. It got in as an ATM operator with a bank sponsor, and it reached other machines by buying off the technicians trusted to open them.[1]
Real due diligence on the company behind a new ATM brand, and on who actually owned it, would have made it much harder for this group to put its own machines on the network. Controls on technician access, such as 2-person service visits, logged openings and spot inspections of the inside of each machine, would have made paid-off technicians far easier to catch.
What to do in your business
- Check who you are letting in. Before you allow a company to place an ATM, card terminal or kiosk on your premises, look up who owns it and ask your bank or card processor whether it is an approved partner.
- Log every service visit. Keep a simple record of who opened a card terminal or cash machine, when, and why, and match it against the service company's own schedule.
- Inspect your card terminals. Once a week, look over payment devices for loose parts, extra wires, broken seals or anything that looks different from the day it arrived.
- Treat unusual offers as a warning sign. Tell staff that anyone offering cash for access to a register, terminal or back office should be reported, not negotiated with.
- Tell customers to use trusted machines. If you run a hotel, shop or rental, point guests to bank-branded ATMs and remind them to watch their statements after a trip.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- Guide: How to manage vendor, IT provider and contractor access to your systems
- How the Target breach happened: a vendor's billing login and the alarms nobody answered
- How the SolarWinds hack happened: malware shipped as a trusted update
- What caused the Marriott breach: the intruder that came with Starwood
- How the Bybit hack happened: a vendor's laptop and a screen that lied
- The C&M Software hack: a sold login and $140 million from Brazil's bank reserves
- How the Caesars hack happened: a con at the outsourced IT help desk
- Every vendors and third parties control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.