An international law enforcement coalition has taken down AudiA6, a professional cryptocurrency laundering service suspected of washing over EUR 336 million in illicit funds between 2022 and 2025.
The platform served as a critical financial pipeline for ransomware operators and cybercriminal networks seeking to cash out stolen digital assets while evading detection.
The coordinated takedown, executed on June 10, 2026, resulted in sweeping enforcement actions across multiple jurisdictions.
Europol Dismantles AudiA6 Crypto Laundering
Two alleged administrators of Ukrainian and Russian nationalities were arrested in Georgia, while 25 domains were seized and more than 30 servers taken offline.
Over 80 vehicles and multiple properties were confiscated in Georgia, and EUR 692,000 in cryptocurrency was frozen, with an additional EUR 86,000 seized outright, Europol said.
Telegram accounts operated by the network were blocked, and both the clear-web and dark-web sites were replaced with law-enforcement seizure banners.
The operation was jointly led by the U.S. Secret Service (USSS), IRS Criminal Investigation (IRS-CI), and Polish Police, with support from Europol, Eurojust, and law enforcement partners from Australia, Canada, France, Germany, Iceland, Japan, Switzerland, and the UK.
A preliminary arrest had already been made on September 15, 2025, when Polish Police detained a Ukrainian national connected to AudiA6. Forensic examination of devices seized during that arrest helped investigators identify additional members of the broader network.
Marketed on underground cybercrime forums as a professional cryptocurrency mixing service, AudiA6 promised criminals both speed and anonymity.
After establishing contact via private messaging platforms, customers transferred stolen cryptocurrency to wallets controlled by the group and received “cleaned” funds within approximately one hour via a complex chain of transactions designed to conceal the money’s origin. Operators charged commissions ranging from 3% to 10% per transaction.
Europol investigators linked the service to more than 15 active investigations worldwide involving ransomware attacks and large-scale cryptocurrency theft.
Over 6,000 KYC (Know Your Customer) records linked to money-mule accounts were uncovered, many of them connected to Russian-speaking intermediaries specifically recruited to move criminal proceeds through cryptocurrency exchanges.
The operators opened thousands of fraudulent exchange accounts using stolen or purchased identities and also administered Dark2Web, a dark web cybercrime forum that advertised illicit services and brokered connections across criminal networks.
Investigators publicly disclosed 18 domains used by the group to register mule accounts with cryptocurrency exchanges, including designli.pictures, pheontx.eu, technobrains.dev, lett.email, qube.black, and deliverlett.com, among others.
Cryptocurrency platforms are strongly urged to identify and immediately block any accounts associated with these domains to prevent further laundering activity.
The AudiA6 takedown underscores a trend highlighted in Europol’s 2026 Internet Organized Crime Threat Assessment (IOCTA): the industrialization of cryptocurrency laundering as a core cybercrime service.
Ransomware groups are increasingly leveraging chain-hopping, decentralized exchanges, and mixer-as-a-service platforms to rapidly move illicit funds across multiple blockchains, helping criminal profits disappear into the digital underground with minimal traceability.
Europol’s European Cybercrime Center (EC3) and the Joint Cybercrime Action Taskforce (J-CAT) provided intelligence analysis, operational coordination, and deconfliction support throughout the investigation.
Eurojust facilitated judicial cooperation, including coordination meetings and the execution of Mutual Legal Assistance, across France, Poland, Georgia, and Iceland, ensuring synchronized judicial action across all participating jurisdictions.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.