Authorities dismantle 'AudiA6' ransomware crypto-laundering service
Law enforcement shut down AudiA6, a crypto-laundering service tied to ransomware and other cybercrime, and linked it to more than 15 investigations.
Intelligence analysis by GPT-5.4 Mini

Europol says AudiA6 functioned as a central laundering hub for cybercriminals, moving illicit crypto through fake exchange accounts and returning it “cleaned” within about an hour. Authorities in 11 countries coordinated the takedown, made arrests, seized assets, and blocked network infrastructure.
AudiA6 was like a dirty-money washing machine for hackers. Police say it took stolen digital cash, mixed it around to hide where it came from, and sent it back looking clean. Now the machine has been shut down.
Analysis
What authorities said
Law enforcement has dismantled AudiA6, a cryptocurrency service that Europol says was used by ransomware actors and other cybercriminals to launder more than $380 million. Europol says the platform was linked to more than 15 international investigations involving ransomware attacks and large-scale crypto theft.
How the network worked
According to the report, AudiA6 was marketed as a “professional cryptocurrency mixing service,” but investigators say it did the opposite of a legitimate service: it accepted criminal proceeds, routed the money through complex transaction paths to hide its origin, and then returned funds “cleaned” in about an hour. The platform reportedly charged a 3% to 10% commission.
The investigation involved authorities from 11 countries across Europe, America, and Asia, with support from Europol and Eurojust. Europol says the breakthrough came after the September 2025 arrest in Poland of a Ukrainian national linked to AudiA6. Forensic work on that suspect’s devices reportedly helped investigators identify key people behind the operation and trace them to Georgia.
As a result, authorities say they arrested two people in Georgia, searched three properties, seized 25 domains, seized 80 vehicles and properties, took €86,000 in cryptocurrency, froze €692,000 in cryptocurrency, and blocked Telegram accounts used by the network. The two arrested people are described as a Ukrainian and a Russian national believed to be administrators of AudiA6 and the underground forum Dark2Web.
The U.S. Department of Justice identified the pair as Ruslan Igorevich Tkachuk and Alexander Vladimirovich Ledenev and said they face up to 20 years in prison for facilitating cybercrime laundering operations. The DoJ also said about 393.39 BTC came directly from darknet markets, ransomware groups, cybercrime services, and other illicit sources.
Key points
- Europol says AudiA6 laundered more than $380 million for ransomware actors and other cybercriminals.
- Authorities say the service used stolen or purchased identities to open thousands of fraudulent exchange accounts.
- Law enforcement from 11 countries coordinated arrests, domain seizures, and asset freezes.
- The U.S. DOJ named two alleged senior members and said they face up to 20 years in prison.
- Investigators also recovered thousands of KYC records tied to money mule accounts.
If the takedown holds, it could make it harder for ransomware crews and other criminals to move stolen money at scale. The seizures, domain takedowns, and arrests also give investigators more evidence to trace related networks.
Even with this network disrupted, other laundering services can appear to replace it. The article also suggests a large mule-and-identity ecosystem, which may continue supporting similar schemes if it is not broadly dismantled.



