Europol Shuts Down AudiA6 Crypto Laundering Ring Used by Ransomware Gangs
Europol has announced the takedown of AudiA6, an industrial-scale cryptocurrency laundering service that processed more than €336 million (~$389 million) in illicit funds since launching in 2021. Operating as a central financial pipeline for ransomware actors, darknet markets, and cybercrime services, the platform enabled threat actors to cash out stolen digital assets while obscuring the money trail from law enforcement. According to the U.S. Department of Justice, approximately 393.39 BTC (valued at around $19.2 million) flowed into AudiA6 wallets directly from known darknet markets, ransomware organizations, and other illicit sources, out of roughly 10,333 BTC deposited overall. The operation builds on a September 2025 arrest by Polish Police of a Ukrainian national linked to the group, whose seized devices helped authorities map out the wider network.
A coordinated action on June 10, 2026, resulted in the arrest of two alleged administrators — Ukrainian national Ruslan Igorevich Tkachuk (37) and Russian national Alexander Vladimirovich Ledenev (25) — in Georgia. Both have been charged by the DoJ with one count of conspiracy to launder monetary instruments and one count of sting money laundering, each carrying a maximum sentence of 20 years. The crackdown also included three property searches, the takedown of 25 domains, and the seizure of more than 30 servers. Investigators froze €692,000 ($798,000) in cryptocurrency, seized an additional €86,000 ($99,400) in digital assets, confiscated more than 80 vehicles and multiple properties in Georgia, and replaced both the clear web and dark web portals of AudiA6 and its associated forum Dark2Web with law enforcement seizure banners. Telegram accounts used by the network were also blocked.
AudiA6 relied on thousands of fraudulent exchange accounts opened using stolen or purchased identities, a tactic that has become standard for crypto-laundering operations. The same operators are suspected of running Dark2Web, a dark web cybercrime forum where threat actors advertised illicit services and connected with peers globally. The service has been linked to more than 15 active investigations worldwide tied to ransomware attacks, underscoring the scale of the financial infrastructure now offline. Security teams can use a WHOIS lookup to check whether newly registered domains match patterns associated with laundering services, while a email breach checker can help individuals and organizations detect whether identities have been harvested to fuel fraudulent account creation at this scale. A port scanner remains useful for defenders auditing exposed infrastructure that criminals may attempt to repurpose for similar cash-out operations.