Threats · 6h ago
Ardit Kutleshi pleaded guilty in a US court to running Rydox, the long-running cybercrime marketplace that sold stolen personal information, payment card data, credentials, and fraud tools. Prosecutors said the site had about 18,000 users and more than 7,600 transactions before its December 2024 seizure.
Rydox worked as a real market, not just a forum: buyers used one place to find stolen data, stealer logs, phishing kits, and other goods, while the operators took in revenue and held the service together with a domain, servers, and cryptocurrency infrastructure. Once those pieces were seized, the marketplace stopped as a distribution hub even though the data already traded there did not disappear with it.
For threat intel and fraud teams, the durable part is the ecosystem around the venue: the products sold there can be reused elsewhere, and demand can shift to other markets once one hub is gone. What the plea settles is that law enforcement hit an established marketplace with transaction volume, not a single disposable operator.
3 sources covering this story
Kosovar Owner of Rydox Marketplace Pleads Guilty in US Court
Ardit Kutleshi created and operated Rydox, which allowed miscreants to trade PII and cybercrime tools and services.
Rydox marketplace admin pleads guilty, faces 22 years in prison
A Kosovar national has pleaded guilty to operating Rydox, a large illegal online marketplace that sold stolen personal information, login credentials, credit card details, and cybercrime tools.
The Record from Recorded Future
Ardit Kutleshi, 28, was extradited from his home country of Kosovo last year after prosecutors accused him and his older brother of running Rydox — an illicit platform used by cybercriminals to sell stolen personal information, illegal access to devices and other tools for carrying out fraud.
Part of the PlainSec briefing for 2026-09-25