Newsroom
12 June, 2026 / News / AI / Tags: audia, ransomware, cybercrime, europol, dark

International authorities have shut down AudiA6, a major cryptocurrency mixing service that processed hundreds of millions in illicit funds from ransomware and cybercrime, arresting key operators and seizing significant assets
On June 10, 2026, law enforcement agencies across multiple countries executed a coordinated takedown of AudiA6, a sophisticated cryptocurrency laundering platform. The operation, coordinated by Europol, targeted a service that had become a preferred option for ransomware groups and other cybercriminals looking to convert stolen digital assets into usable funds.
The platform, active since around 2021, is estimated to have laundered more than €336 million (approximately $389 million) in criminal proceeds. It functioned by accepting dirty cryptocurrency from clients, routing it through complex transaction chains involving numerous accounts, and returning cleaned funds, typically within an hour.
Authorities arrested Ruslan Igorevich Tkachuk, 37, of Ukrainian nationality, and Alexander Vladimirovich Ledenev, 25, of Russian nationality. Both are suspected of operating AudiA6 and are also linked to the administration of Dark2Web, a dark web forum used by cybercriminals to advertise illicit services and network with others.
The U.S. Department of Justice has charged the pair with conspiracy to launder monetary instruments and sting money laundering. If convicted, each faces up to 20 years in prison.
Audia6 marketed itself on cybercrime forums as a professional mixing service that guaranteed anonymity and fast processing. Customers transferred funds to wallets controlled by the group and received cleaned cryptocurrency back after the service applied layered transactions to obscure the money trail.
Operators charged commissions ranging from 3% to 10%. The service relied heavily on thousands of fraudulent exchange accounts created using stolen or purchased identities. Investigators identified more than 6,000 Know Your Customer (KYC) records linked to money mule accounts, many involving Russian-speaking intermediaries recruited for the purpose.
The group used a network of domains for email services to register these accounts, including designli.pictures, pheontx.eu, and others. This infrastructure allowed them to bypass anti-money laundering controls at legitimate exchanges.
The operation built upon earlier work by Polish police, who arrested a Ukrainian national in September 2025 connected to the AudiA6 network. Forensic analysis of devices seized in that case provided critical leads that helped identify the main operators and map the full extent of the operation.
Participating agencies included the U.S. Secret Service, IRS Criminal Investigation, Polish Police, Australian Federal Police, and partners from Canada, France, Georgia, Germany, Iceland, Japan, Switzerland, and the United Kingdom. Europol and Eurojust supported the cross-border effort.
Audia6 has been linked to more than 15 international investigations involving ransomware attacks and large-scale cryptocurrency thefts. One notable case involved funds from a ransomware attack on an Australian business.
This disruption highlights the critical role that specialized laundering services play in sustaining cybercriminal networks. By cutting off access to such platforms, authorities aim to reduce the financial incentive for ransomware attacks and other digital thefts.
Europol described AudiA6 as a central hub that enabled criminals to cash out stolen assets while concealing their origins. The service's reliance on mule accounts and layered transactions demonstrates how cybercriminals adapt to evade detection.
Law enforcement replaced both the clear web and dark web sites of AudiA6 and Dark2Web with seizure banners, sending a clear message to the cybercrime community.
While this represents a significant victory, authorities continue to monitor similar services that may emerge to fill the gap. The investigation remains ongoing, with potential for additional arrests and further asset recoveries.
Cybersecurity experts and financial institutions are expected to increase scrutiny of suspicious cryptocurrency flows and mule account patterns identified during this probe. The detailed publication of associated domains should help exchanges strengthen their verification processes.









