Europol and Global Partners Shut Down AudiA6 Crypto Laundering Network Used by Ransomware Groups
European law enforcement has dismantled AudiA6, a cryptocurrency laundering service long relied upon by ransomware collectives and other cybercriminal syndicates. In a statement released on Thursday, Europol said the operation severed a “key financial pipeline used to wash hundreds of millions in illicit profits,” a service that investigators estimate processed more than €336 million (approximately $389 million) since it began operating in 2021.
Europol described AudiA6 as a central cash-out mechanism for threat actors who wanted to obscure the provenance of stolen digital funds. Investigators allege the same operators ran a dark web forum called Dark2Web, which served as a marketplace and meeting place for criminals offering illegal services and coordinating activity worldwide.
The coordinated takedown, executed on June 10, 2026, included several simultaneous measures: the arrest of two suspected administrators of Ukrainian and Russian nationality in Georgia; three property searches; the removal of 25 domains and seizure of more than 30 servers; confiscation of over 80 vehicles and multiple properties in Georgia; freezing of cryptocurrency holdings totalling €692,000 (about $798,000) and the seizure of €86,000 (around $99,400) in crypto; the blocking of Telegram accounts used by the network; and the replacement of AudiA6 and Dark2Web webpages (both on the open and dark web) with law enforcement seizure banners.
Concurrently, the U.S. Department of Justice charged two defendants identified as Ruslan Igorevich Tkachuk, 37, and Alexander Vladimirovich Ledenev, 25. Each is accused of one count of conspiracy to launder monetary instruments and one count of sting money laundering; if convicted, both face up to 20 years in prison.
The DoJ outlined transaction figures tied to the service, saying that out of roughly 10,333 bitcoin deposited into AudiA6-controlled wallets, around 393.39 BTC (valued at about $19,234,331 at the time) were traced directly to darknet markets, ransomware groups, cybercrime services and other illegal sources, while additional deposits came indirectly from illicit actors.
Europol said the disruption built on an earlier Polish Police enforcement action in September 2025 that led to the arrest of a Ukrainian national suspected of involvement with the AudiA6 operation. Evidence from devices seized in that probe allowed forensic examiners to identify further individuals linked to the network.
Investigators characterize AudiA6 as an industrial-scale laundering enterprise that depended on thousands of fraudulent exchange accounts created using stolen or purchased identities. The service has been connected to more than 15 international investigations tied to ransomware incidents and large cryptocurrency thefts.
Before being taken down, AudiA6 operated as a so-called mixing or “mixer-as-a-service” platform promising anonymity and speed. Customers purportedly transferred illicit proceeds into wallets controlled by the group and received “cleaned” funds back-often within an hour-after the operators executed an intricate sequence of transfers intended to disguise the funds’ origins. Communications and transaction instructions were exchanged via private messaging channels, and the operators reportedly levied fees ranging from 3 percent up to 10 percent.
During the inquiry, authorities uncovered more than 6,000 Know Your Customer (KYC) records associated with mule accounts, Europol said. Many of those mule accounts were tied to Russian-speaking intermediaries specifically recruited to move criminal proceeds through cryptocurrency exchanges. The network is also alleged to have created mule accounts using both mainstream email services and addresses registered on domains it controlled.
The domains linked to the operation include: designli.pictures, pheontx.eu, smplfy.in, sumato-soft.org, technobrains.dev, lett.email, trayo.app, deliverly.top, inboxly.top, postfast.eu, postino.click, inboxally.agency, mailora.eu, postify.email, quix.express, flowcomm.click, qube.black, deliverlett.com, lettermail.eu.
Earlier industry reporting corroborates aspects of AudiA6’s model. A November 2021 Intel 471 bulletin noted that the service required a minimum balance of 27 bitcoins and charged a flat fee between 3 percent and 5.5 percent. More recently, a December 2025 analysis by TRM Labs found that funds stolen during the 2022 LastPass breach were routed through intermediaries including Cryptex and AudiA6.
The multinational probe was led by the U.S. Secret Service and IRS Criminal Investigation, working with the Polish Police and law enforcement partners from Australia, Canada, France, Georgia, Germany, Iceland, Japan, Switzerland and the U.K.
Authorities say the case highlights the growth of large-scale cryptocurrency laundering services that enable the cybercrime economy. These schemes commonly exploit fake exchange accounts, mule wallets and privacy-enhancing tools to obscure transaction trails and evade anti-money laundering safeguards. Europol warned that ransomware groups increasingly use tactics such as chain-hopping, decentralized exchanges and “mixer-as-a-service” platforms to move illicit coins across multiple blockchains in minutes, allowing criminal proceeds to vanish into the digital underground.