European authorities have successfully dismantled AudiA6, a cryptocurrency laundering service that has been a significant conduit for ransomware gangs and cybercriminal networks. Europol announced that this operation has severed a crucial financial channel responsible for laundering over €336 million (approximately $389 million) since its inception in 2021.
AudiA6 functioned as a central hub for cybercriminals seeking to convert illicit digital assets into clean funds, effectively obscuring the origins of their profits. The service was particularly favored by ransomware operators and other cybercriminal entities due to its efficiency in anonymizing transactions.
In a coordinated effort on June 10, 2026, law enforcement executed several actions:
- Arrested two alleged administrators, identified as Ukrainian and Russian nationals, in Georgia.
- Conducted three property searches.
- Took down 25 domains and seized over 30 servers.
- Confiscated more than 80 vehicles and multiple properties in Georgia.
- Froze cryptocurrency assets valued at €692,000 ($798,000) and seized an additional €86,000 ($99,400) in cryptocurrency.
- Blocked Telegram accounts associated with the network.
- Replaced the websites of AudiA6 and its affiliated dark web forum, Dark2Web, with law enforcement seizure banners.
The U.S. Department of Justice has charged the two arrested individuals, Ruslan Igorevich Tkachuk, 37, and Alexander Vladimirovich Ledenev, 25, with conspiracy to launder monetary instruments and sting money laundering. If convicted, each faces up to 20 years in prison.
Investigations revealed that out of approximately 10,333 bitcoins deposited into AudiA6, about 393.39 BTC (valued at around $19.2 million at the time) originated directly from known darknet markets, ransomware organizations, and other illicit sources. Additional funds were indirectly funneled from similar origins into AudiA6 wallets.
This crackdown follows a prior enforcement action by Polish police in September 2025, which led to the arrest of a Ukrainian national linked to AudiA6’s money laundering activities. Forensic analysis of seized electronic devices from that operation provided critical insights, enabling authorities to identify and apprehend further individuals connected to the scheme.
AudiA6 operated on an industrial scale, utilizing thousands of fraudulent exchange accounts created with stolen or purchased identities. The service has been implicated in over 15 global investigations related to ransomware attacks and large-scale cryptocurrency thefts.
Before its disruption, AudiA6 marketed itself as a cryptocurrency mixing service that guaranteed anonymity and rapid transaction processing. Clients would transfer illicit proceeds to wallets controlled by AudiA6 and receive “cleaned” funds within an hour, processed through complex transaction chains designed to obscure the funds’ origins. Transactions were coordinated via private messaging platforms, with the operators charging commissions ranging from 3% to 10%.
During the investigation, authorities identified over 6,000 Know Your Customer (KYC) records linked to money mule accounts, highlighting the extensive network AudiA6 employed to facilitate its operations.
The dismantling of AudiA6 underscores the growing sophistication of law enforcement in combating cyber-enabled financial crimes. By targeting the infrastructure that supports illicit financial activities, authorities are sending a clear message about their commitment to disrupting the financial mechanisms that enable cybercrime. This operation also highlights the importance of international cooperation in addressing the borderless nature of cybercriminal enterprises.