Case file · RIVIERA MAYA 2020

The Riviera Maya ATM gang: when the skimmer came with the machine

Published 2026-09-29 · 4 min read · Missing control: Vet who owns and services ATMs

Most ATM skimming gangs sneak a device onto somebody else's cash machine. According to investigative reporters, the crew behind Mexico's biggest skimming operation skipped that step and ran its own fleet of ATMs, with the skimmers already inside.[1][2] This case file covers what reporters found, how the scheme was said to work, what happened to the people behind it, and the control that was missing.

What happened

In September 2015 a security journalist published a 3-part investigation into cash machines in Mexico's Yucatan Peninsula. He found nearly 2 dozen ATMs in tourist areas that had been fitted with skimming devices that could be read over Bluetooth, the short-range wireless standard used by headphones and phones.[1] Many of the machines carried the same brand name: Intacash.[1][2]

In 2020 the Organized Crime and Corruption Reporting Project, a network of investigative journalists, published its own long investigation and gave the group a name: the Riviera Maya gang.[1] Reporters said the Romanian-led group owned and operated Intacash and had skimmers inside at least 100 of its ATMs, in resort towns including Cancun, Cozumel, Playa del Carmen and Tulum, and in other cities such as Puerto Vallarta and Tijuana.[1][2]

The reporting estimated the group's total take at about $1.2 billion over roughly 8 years, drawn from the bank accounts of tourists and locals who used the machines.[1][2] Reporters also tied the group to bribes paid to Mexican officials and politicians, and to threats against people who got in its way.[1][2]

How it worked

A normal skimmer is a fake card reader glued over the real one. It can be spotted by a careful customer or a bank technician. Reporters said the Riviera Maya gang did not need that trick, because it controlled the machines themselves. The skimming parts were installed inside the ATM cases, out of sight, and could be read wirelessly by someone standing nearby.[1]

The gang also went after the people who service other companies' machines. According to the reporting, installers linked to Intacash offered ATM technicians many times their monthly pay in exchange for periodic access to the machines they looked after.[1] A person who holds the keys to an ATM can place a device inside it that no customer will ever see.

The card data was then used to make cloned cards, and withdrawals were made far away from Mexico, in countries including India, Indonesia and Taiwan. Reporters said the crew often waited around 3 months before using the stolen data, which made it much harder for banks to work out which ATM had been the source.[1] By one estimate each compromised machine captured about 1,000 cards a month.[1]

How it was caught

Journalists, not bank fraud alerts, first put the scheme on the public record. The 2015 investigation found the hacked machines by scanning for the skimmers' wireless signals with a smartphone.[1] Intercepted communications reported later showed the group's leadership reacting to that coverage by ordering operations shut down.[1]

The pressure built from there. In 2019 the Mexican bank that sponsored Intacash suspended its contract to process transactions, and Mexican police arrested the man reporters describe as the gang's leader on a weapons charge.[1] In February 2021 a Mexican Green Party leader resigned after reports that he had taken money from the group.[2]

On May 27, 2021, the alleged boss, a Romanian national living in Mexico, was arrested in Mexico City on a Romanian extradition warrant; the arrest was reported the next day.[2] Romanian prosecutors had brought charges against him that included organized crime, attempted murder and blackmail.[1][2]

What it cost

The $1.2 billion figure is a reporters' estimate, not a court finding, and no official total has been published. It came from the number of cards each machine captured and the average amount taken from each account.[1] Several members of the group have since been sentenced in Romania, and a member and his wife were sent to prison by a US court.[3][4] For tourists, the cost landed quietly: withdrawals from far-off countries months after a beach holiday, with no obvious link back to the ATM in the hotel lobby.

The missing control

The missing control: vetting who owns and services the machines. The gang did not beat the ATM network's defenses from outside. It got in as an ATM operator with a bank sponsor, and it reached other machines by buying off the technicians trusted to open them.[1]

Real due diligence on the company behind a new ATM brand, and on who actually owned it, would have made it much harder for this group to put its own machines on the network. Controls on technician access, such as 2-person service visits, logged openings and spot inspections of the inside of each machine, would have made paid-off technicians far easier to catch.

What to do in your business

Watch the case
The Gang That Ran Its Own ATM NetworkDrops 2026-12-20
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More vendors and third parties cases

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. KrebsOnSecurity: Romanian skimmer gang in Mexico outed by KrebsOnSecurity stole $1.2 billion
  2. KrebsOnSecurity: Boss of ATM skimming syndicate arrested in Mexico
  3. OCCRP: Riviera Maya gang members sentenced in Romania
  4. OCCRP: US court sends Riviera Maya gang member and wife behind bars