DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu
Rydox

Rydox Cybercrime Marketplace Shut Down and Three Administrators Arrested

Posted on December 13, 2024 by Dissent

The Justice Department today announced the seizure of Rydox, an illicit website and marketplace dedicated to selling stolen personal information, access devices, and other tools for carrying out cybercrime and fraud, and the arrest of Rydox administrators and Kosovo nationals Ardit Kutleshi, 26, and Jetmir Kutleshi, 28. Both defendants were arrested earlier today in Kosovo by Kosovo law enforcement pursuant to a U.S. request for extradition. They are currently awaiting extradition to the United States to face an indictment unsealed today in the Western District of Pennsylvania.

A third administrator of the Rydox marketplace, Kosovo national Shpend Sokoli, was also arrested earlier today in Albania by Albania’s Special Anti-Corruption Body (SPAK). Sokoli is expected to be charged and prosecuted in Albania.

According to the indictment, the Rydox marketplace has conducted over 7,600 sales of personally identifiable information (PII), stolen access devices, and cybercrime tools, which generated at least $230,000 in revenue since its inception in or around February 2016. These sales included PII, credit card information, and login credentials stolen from thousands of victims residing in the United States. In addition, the Rydox site has offered for sale at least 321,372 cybercrime products to over 18,000 users including stolen PII such as names, addresses, and social security numbers; access devices such as stolen credentials for online accounts and credit card information; and cybercrime tools such as scam pages, spamming logs, and spamming tutorials.

“The indictment alleges that, for more than eight years, the defendants administered an illicit online marketplace that sold PII, credit card information, and login credentials that had been stolen from thousands of U.S. victims,” said Principal Deputy Assistant Attorney General Nicole M. Argentieri, head of the Justice Department’s Criminal Division. “Today, we announce that, working with our domestic and foreign law enforcement partners, we have dismantled the marketplace, arrested its administrators, and seized their criminal proceeds. This announcement is a powerful demonstration of the value of our partnerships on cybercrime, without which these arrests and seizures would not have been possible.”

“The Rydox marketplace was a one-stop shop where upwards of 18,000 of its cybercriminal customers could choose from more than 300,000 cybercrime tools,” said U.S. Attorney Eric G. Olshan for the Western District of Pennsylvania. “While cybercrime often involves conduct occurring overseas and the actions of foreign nationals, its harms can be devastatingly local, with residents in our own communities suffering financial ruin as a result of the theft and misuse of their sensitive personal information. Today’s takedown reinforces our steadfast message that the Western District of Pennsylvania and our domestic and international law enforcement partners will use every available tool to hold accountable those who pursue illicit profit at the expense of ordinary citizens around the world.”

“The success of this international operation underscores the power of collaboration between the FBI and our partners worldwide,” said Special Agent in Charge Kevin Rojek of the FBI Pittsburgh Field Office. “It also serves as a clear warning: those who go after innocent people for financial gain will be pursued and brought to justice no matter where they are in the world. This operation marks a major blow against the criminal underground that seeks to profit from stolen information and fuels global cybercrime.”

As part of the actions announced today, the United States also obtained judicial authorization to seize the domain www.Rydox.cc, which hosted and facilitated access to the Rydox website. The seizure of this domain by the government will prevent the owners and third parties from using the site to continue to buy and sell cybercrime tools and stolen personal information. Anyone visiting this site will now see a seizure banner that notifies them that the domain has been seized by federal authorities.

This Website Has Been Seized as part of a coordinated law enforcement action taken against Rydox, a black-market website. This domain has been seized by the Federal Bureau of Investigation in accordance with a seizure warrant pursuant to 18 U.S. Code §§ 981, 982, and 953 issued by the United States District Court for the Western District of Pennsylvania as part of a joint international law enforcement operation and action by: • The United States Attorney’s Office for the Western District of Pennsylvania • F
Rydox Domain Splash Page

In coordination with today’s actions, the FBI and Royal Malaysian Police seized servers in Kuala Lumpur, Malaysia, that hosted the Rydox illicit marketplace and took the Rydox website offline. The United States also obtained judicial authorization to seize approximately $225,000 worth of cryptocurrency from accounts controlled by the defendants.

Ardit Kutleshi and Jetmir Kutleshi are each charged with two counts of identity theft, one count of conspiracy to commit identity theft, one count of aggravated identity theft, one count of access device fraud, and one count of money laundering, all arising from their roles as administrators of the Rydox website. If convicted, they each face a maximum penalty of 20 years in prison for the money laundering offense, a maximum penalty of 10 years in prison for the access device fraud offense, a maximum penalty of five years in prison for each of the identity theft offenses, and a mandatory minimum sentence of two years in prison for the aggravated identity theft charge, which is required to run consecutively to any other sentence imposed. A federal district court judge will determine any sentence after considering the U.S. Sentencing Guidelines and other statutory factors.

The FBI Pittsburgh Field Office investigated this case in coordination with the Kosovo State Prosecutor’s Special Prosecution Office, Kosovo Police’s Cybercrime Investigation Directorate, SPAK, Attorney General’s Chambers of Malaysia, and Royal Malaysia Police’s Commercial Crime Investigation Department.

Senior Counsel Thomas Dougherty of the Criminal Division’s Computer Crime and Intellectual Property Section and Assistant U.S. Attorney Nicole Stockey for the Western District of Pennsylvania are prosecuting the case. The Justice Department’s Office of International Affairs provided significant assistance.

An indictment is merely an allegation. All defendants are presumed innocent until proven guilty beyond a reasonable doubt in a court of law.

Updated December 12, 2024

Source:  U.S. Department of Justice


Related:

  • KT Chief to Resign After Cybersecurity Breach Resolution
  • Cyber-Attack On Bectu’s Parent Union Sparks UK National Security Concerns
  • A business's cyber insurance policy included ransom coverage, but when they needed it, the insurer refused to pay. Why?
  • Before Their Telegram Channel Was Banned Again, ScatteredLAPSUS$Hunters Dropped Files Doxing Government Employees (2)
  • Attorney General James Secures $14.2 Million from Car Insurance Companies Over Data Breaches
  • Months After Being Notified, a Software Vendor is Still Exposing Confidential and Sealed Court Records
Category: Breach Incidents

Post navigation

← Dutch people advised to carry cash in case of cyberattack by Russia
Minnesota schools must report cybersecurity incidents under new law →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • District of Massachusetts Allows Higher-Ed Student Data Breach Claims to Survive
  • End of the game for cybercrime infrastructure: 1025 servers taken down
  • Doctor Alliance Data Breach: 353GB of Patient Files Allegedly Compromised, Ransom Demanded
  • St. Thomas Brushed Off Red Flags Before Dark-Web Data Dump Rocks Houston
  • A Wiltshire police breach posed possible safety concerns for violent crime victims as well as prison officers
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Almost two years later, Alpha Omega Winery notifies those affected by a data breach.
  • Court of Appeal reaffirms MFSA liability in data leak case, orders regulator to shoulder costs
  • A jailed hacking kingpin reveals all about the gang that left a trail of destruction
  • Army gynecologist took secret videos of patients during intimate exams, lawsuit says

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • As shoplifting surges, British retailers roll out ‘invasive’ facial recognition tools
  • Data broker Kochava agrees to change business practices to settle lawsuit
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Changes in the Rules for Disclosure for Substance Use Disorder Treatment Records: 42 CFR Part 2: What Changed, Why It Matters, and How It Aligns with HIPAAs
  • Always watching: How ICE’s plan to monitor social media 24/7 threatens privacy and civic participation

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.