DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Rydox Cybercrime Marketplace Shut Down and Three Administrators Arrested

Posted on December 13, 2024 by Dissent

The Justice Department today announced the seizure of Rydox, an illicit website and marketplace dedicated to selling stolen personal information, access devices, and other tools for carrying out cybercrime and fraud, and the arrest of Rydox administrators and Kosovo nationals Ardit Kutleshi, 26, and Jetmir Kutleshi, 28. Both defendants were arrested earlier today in Kosovo by Kosovo law enforcement pursuant to a U.S. request for extradition. They are currently awaiting extradition to the United States to face an indictment unsealed today in the Western District of Pennsylvania.

A third administrator of the Rydox marketplace, Kosovo national Shpend Sokoli, was also arrested earlier today in Albania by Albania’s Special Anti-Corruption Body (SPAK). Sokoli is expected to be charged and prosecuted in Albania.

According to the indictment, the Rydox marketplace has conducted over 7,600 sales of personally identifiable information (PII), stolen access devices, and cybercrime tools, which generated at least $230,000 in revenue since its inception in or around February 2016. These sales included PII, credit card information, and login credentials stolen from thousands of victims residing in the United States. In addition, the Rydox site has offered for sale at least 321,372 cybercrime products to over 18,000 users including stolen PII such as names, addresses, and social security numbers; access devices such as stolen credentials for online accounts and credit card information; and cybercrime tools such as scam pages, spamming logs, and spamming tutorials.

“The indictment alleges that, for more than eight years, the defendants administered an illicit online marketplace that sold PII, credit card information, and login credentials that had been stolen from thousands of U.S. victims,” said Principal Deputy Assistant Attorney General Nicole M. Argentieri, head of the Justice Department’s Criminal Division. “Today, we announce that, working with our domestic and foreign law enforcement partners, we have dismantled the marketplace, arrested its administrators, and seized their criminal proceeds. This announcement is a powerful demonstration of the value of our partnerships on cybercrime, without which these arrests and seizures would not have been possible.”

“The Rydox marketplace was a one-stop shop where upwards of 18,000 of its cybercriminal customers could choose from more than 300,000 cybercrime tools,” said U.S. Attorney Eric G. Olshan for the Western District of Pennsylvania. “While cybercrime often involves conduct occurring overseas and the actions of foreign nationals, its harms can be devastatingly local, with residents in our own communities suffering financial ruin as a result of the theft and misuse of their sensitive personal information. Today’s takedown reinforces our steadfast message that the Western District of Pennsylvania and our domestic and international law enforcement partners will use every available tool to hold accountable those who pursue illicit profit at the expense of ordinary citizens around the world.”

“The success of this international operation underscores the power of collaboration between the FBI and our partners worldwide,” said Special Agent in Charge Kevin Rojek of the FBI Pittsburgh Field Office. “It also serves as a clear warning: those who go after innocent people for financial gain will be pursued and brought to justice no matter where they are in the world. This operation marks a major blow against the criminal underground that seeks to profit from stolen information and fuels global cybercrime.”

As part of the actions announced today, the United States also obtained judicial authorization to seize the domain www.Rydox.cc, which hosted and facilitated access to the Rydox website. The seizure of this domain by the government will prevent the owners and third parties from using the site to continue to buy and sell cybercrime tools and stolen personal information. Anyone visiting this site will now see a seizure banner that notifies them that the domain has been seized by federal authorities.

This Website Has Been Seized as part of a coordinated law enforcement action taken against Rydox, a black-market website. This domain has been seized by the Federal Bureau of Investigation in accordance with a seizure warrant pursuant to 18 U.S. Code §§ 981, 982, and 953 issued by the United States District Court for the Western District of Pennsylvania as part of a joint international law enforcement operation and action by: • The United States Attorney’s Office for the Western District of Pennsylvania • F
Rydox Domain Splash Page

In coordination with today’s actions, the FBI and Royal Malaysian Police seized servers in Kuala Lumpur, Malaysia, that hosted the Rydox illicit marketplace and took the Rydox website offline. The United States also obtained judicial authorization to seize approximately $225,000 worth of cryptocurrency from accounts controlled by the defendants.

Ardit Kutleshi and Jetmir Kutleshi are each charged with two counts of identity theft, one count of conspiracy to commit identity theft, one count of aggravated identity theft, one count of access device fraud, and one count of money laundering, all arising from their roles as administrators of the Rydox website. If convicted, they each face a maximum penalty of 20 years in prison for the money laundering offense, a maximum penalty of 10 years in prison for the access device fraud offense, a maximum penalty of five years in prison for each of the identity theft offenses, and a mandatory minimum sentence of two years in prison for the aggravated identity theft charge, which is required to run consecutively to any other sentence imposed. A federal district court judge will determine any sentence after considering the U.S. Sentencing Guidelines and other statutory factors.

The FBI Pittsburgh Field Office investigated this case in coordination with the Kosovo State Prosecutor’s Special Prosecution Office, Kosovo Police’s Cybercrime Investigation Directorate, SPAK, Attorney General’s Chambers of Malaysia, and Royal Malaysia Police’s Commercial Crime Investigation Department.

Senior Counsel Thomas Dougherty of the Criminal Division’s Computer Crime and Intellectual Property Section and Assistant U.S. Attorney Nicole Stockey for the Western District of Pennsylvania are prosecuting the case. The Justice Department’s Office of International Affairs provided significant assistance.

An indictment is merely an allegation. All defendants are presumed innocent until proven guilty beyond a reasonable doubt in a court of law.

Updated December 12, 2024

Source:  U.S. Department of Justice

Category: Breach Incidents

Post navigation

← Dutch people advised to carry cash in case of cyberattack by Russia
Minnesota schools must report cybersecurity incidents under new law →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Department of Justice says Berkeley Research Group data breach may have exposed information on diocesan sex abuse survivors
  • Masimo Manufacturing Facilities Hit by Cyberattack
  • Education giant Pearson hit by cyberattack exposing customer data
  • Star Health hacker claims sending bullets, threats to top executives: Reports
  • Nova Scotia Power hit by cyberattack, critical infrastructure targeted, no outages reported
  • Georgia hospital defeats data-tracking lawsuit
  • 60K BTC Wallets Tied to LockBit Ransomware Gang Leaked
  • UK: Legal Aid Agency hit by cyber security incident
  • Public notice for individuals affected by an information security breach in the Social Services, Health Care and Rescue Services Division of Helsinki
  • PowerSchool paid a hacker’s extortion demand, but now school district clients are being extorted anyway (3)

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Clothing Retailer, Todd Snyder, Inc., Settles CPPA Allegations Regarding California Consumer Privacy Act Violations
  • US Customs and Border Protection Plans to Photograph Everyone Exiting the US by Car
  • Google agrees to pay Texas $1.4 billion data privacy settlement
  • The App Store Freedom Act Compromises User Privacy To Punish Big Tech
  • Florida bill requiring encryption backdoors for social media accounts has failed
  • Apple Siri Eavesdropping Payout Deadline Confirmed—How To Make A Claim
  • Privacy matters to Canadians – Privacy Commissioner of Canada marks Privacy Awareness Week with release of latest survey results

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.