Authorities Dismantle AudiA6 Crypto-Laundering Service Used by Ransomware Gangs
Law enforcement from 11 countries has dismantled AudiA6, a cryptocurrency laundering service that processed over $380 million for ransomware actors and other cybercriminals.

Law enforcement agencies across 11 countries have dismantled the AudiA6 cryptocurrency laundering service, which allegedly processed over $380 million for ransomware actors and other cybercriminals. The operation, coordinated by Europol and Eurojust, targeted a key financial infrastructure that enabled threat actors to obfuscate illicit cryptocurrency transactions. Two administrators, a Ukrainian and a Russian national, were arrested in Georgia, and authorities seized domains, vehicles, properties, and cryptocurrency assets.
AudiA6 operated as a "professional cryptocurrency mixing service" between 2022 and 2025, accepting cybercrime proceeds and moving them through complex transaction routes to obscure their origin. The service returned "cleaned" funds to holders in about an hour, charging a commission of 3-10%. Europol described the operation as an "industrial-scale cryptocurrency laundering operation built around thousands of fraudulent exchange accounts opened using stolen or purchased identities."
The investigation linked AudiA6 to more than 15 international investigations of ransomware attacks worldwide. Past reports from Intel471 and blockchain investigator ZachXBT had previously exposed the platform for facilitating illegal activity. The U.S. Department of Justice named Ruslan Igorevich Tkachuk, 37, and Alexander Vladimirovich Ledenev, 25, as senior members of the platform, both now in custody in Georgia facing up to 20 years in prison.
Authorities seized 25 domains, 80 vehicles and properties, and approximately €86,000 ($99,000) in cryptocurrency, while freezing an additional €692,000 ($798,000). They also blocked Telegram accounts used by the network and retrieved 6,000 Know-Your-Customer (KYC) records linked to money mule accounts. These accounts were created using stolen or purchased identities, many connected to Russian-speaking intermediaries who recruited individuals specifically for this purpose.
The takedown was made possible by the arrest in Poland in September 2025 of a Ukrainian national linked to AudiA6. Forensic examination of that suspect's devices helped investigators identify key individuals behind the operation and eventually locate and arrest them in Georgia. Both AudiA6 and the underground forum Dark2Web, which the administrators also ran, now display seizure notices to visitors.
This operation represents a significant blow to the financial infrastructure supporting ransomware and other cybercrime. By dismantling a major money-laundering channel, authorities have disrupted the ability of multiple ransomware families and threat actors to cash out their illicit gains. The case highlights the growing international cooperation in targeting the financial enablers of cybercrime, rather than just the attackers themselves.
The Help Net Security report adds that AudiA6 operators charged fees of 3% to 10% and delivered laundered funds within about an hour. The investigation uncovered over 6,000 KYC records tied to money mule accounts, and the service was linked to at least 15 international investigations. During the June 10 takedown, authorities seized more than 80 vehicles and multiple properties in Georgia, froze approximately €692,000 in cryptocurrency, and seized over €86,000 in crypto. The operation built on a September 2025 arrest of a Ukrainian suspect by Polish police.
The U.S. Department of Justice unsealed charges against the two arrested administrators — Ruslan Igorevich Tkachuk, 37, and Alexander Vladimirovich Ledenev, 25 — accusing them of conspiracy to launder monetary instruments and sting money laundering, each carrying a maximum 20-year sentence. Court documents revealed that of roughly 10,333 bitcoin deposited into AudiA6, about 393.39 BTC (valued at $19.2 million) came directly from known darknet markets, ransomware organizations, and other illicit sources. Europol also disclosed that the takedown was enabled by a September 2025 arrest in Poland, which led to forensic analysis of seized devices and the identification of additional suspects.
The operation, executed on June 10, 2026, involved the U.S. Secret Service, IRS Criminal Investigation, Polish law enforcement, and Europol, resulting in the arrest of two administrators of Ukrainian and Russian nationality in Georgia. Investigators seized over 30 servers, 25 domains, and cryptocurrency assets, and linked AudiA6 to more than 15 ransomware investigations, highlighting its role as a central enabler in the cybercrime ecosystem. The takedown also revealed that the same individuals likely operated the Dark2Web cybercrime forum, which served as a marketplace for illicit services.
New details from the Infosecurity Magazine report reveal that the AudiA6 platform laundered over €336 million ($389 million) for cybercriminals between 2022 and 2025, and was tied to at least 15 ransomware operations. The takedown on June 10 also led to the arrest of two alleged administrators of Ukrainian and Russian nationality in Georgia, with authorities seizing €692,000 in cryptocurrency and over 25 domains, while also blocking Telegram accounts used by the network. Additionally, the suspects are believed to have administered the Dark2Web dark web forum, a criminal marketplace used to connect cybercriminal actors worldwide.