Global Sting Dismantles $390M AudiA6 Crypto Laundering Operation


Global Sting Dismantles 0M AudiA6 Crypto Laundering Operation


Iris Coleman
Jun 13, 2026 07:12

Authorities shut down AudiA6, a laundering service used by ransomware gangs to process $390M in illicit crypto funds, seizing domains and assets.

An international law enforcement operation involving 11 countries has dismantled AudiA6, a crypto laundering platform that processed over €336 million ($390 million) in illicit funds between 2022 and 2025. The platform, which catered to ransomware groups, was seized alongside its associated dark web forum, ‘Dark2Web.’

Authorities arrested two administrators—Ruslan Igorevich Tkachuk and Alexander Vladimirovich Ledenev—in Georgia on Wednesday, according to the European Union Agency for Criminal Justice Cooperation (Eurojust). The sting operation also resulted in the seizure of 25 domains, more than 30 servers, $900,000 in frozen cryptocurrency, and 80 vehicles tied to the operation.

AudiA6 operated as a “mixer-as-a-service,” offering to obfuscate the origin of stolen crypto for a fee of 3% to 10%, enabling criminals to ‘clean’ funds within an hour. The platform was heavily used by ransomware syndicates, processing approximately 10,333 BTC since its launch in 2021, according to blockchain analytics firm Chainalysis. At the time of the transactions, this was valued at around $389 million.

Fake Identities and Money Mule Accounts

The laundering operation relied on thousands of fraudulent accounts created using stolen or purchased identities. Investigators uncovered over 6,000 fake Know Your Customer (KYC) records tied to “money mule” accounts. These accounts were reportedly managed by Russian-speaking intermediaries specifically recruited to launder funds through crypto exchanges.

AudiA6’s infrastructure wasn’t limited to crypto mixing. The group also operated ‘Dark2Web,’ a marketplace forum advertising illicit services and facilitating connections between global cybercriminals. Both platforms’ domains now display law enforcement seizure banners.

Global Effort to Combat Ransomware

The takedown of AudiA6 represents one of the most significant law enforcement actions against crypto-fueled ransomware operations to date. Agencies from the United States, United Kingdom, Australia, France, Japan, and other nations coordinated the investigation through Eurojust and Europol.

Ransomware attacks have surged in recent years, with the U.S. accounting for nearly 65% of global incidents in Q1 2026, according to cybersecurity firms Emsisoft and Check Point Research. AudiA6 was reportedly involved in laundering ransom payments, including funds extorted from an Australian business in 2024.

“The ransomware ecosystem is consolidating around fewer, more dominant operators,” stated Check Point Research in May. The top 10 ransomware groups were responsible for 71% of all recorded incidents in early 2026, highlighting the ongoing challenge of dismantling these criminal networks.

Implications for Crypto Regulation

The AudiA6 case underscores the growing sophistication of cybercriminal infrastructure and the role of crypto in facilitating illicit activity. By targeting platforms like AudiA6, law enforcement sends a clear signal to bad actors that regulatory and investigative capabilities are catching up.

For legitimate crypto businesses, this serves as a reminder of the importance of robust compliance measures, particularly around KYC and anti-money laundering (AML) protocols. Platforms that fail to enforce these standards risk becoming tools for criminal enterprises—and targets for regulatory action.

With ransomware remaining a persistent threat and crypto mixers under increasing scrutiny, further law enforcement actions in this space appear inevitable. Market participants should monitor developments closely, as regulatory shifts and enforcement priorities could reshape the operational landscape for crypto services.

Image source: Shutterstock





Source link