National Cyber Warfare Foundation (NCWF)

Rydox Admin Faces 20 Years After Selling Stolen Data and Fraud Tools


0 user ratings
2026-09-27 10:29:06
milo
Breach
Kosovo national Ardit Kutleshi pleaded guilty to running Rydox, a cybercrime marketplace that sold stolen identities and credentials for years. Ardit Kutleshi, 28 years old and a citizen of Kosovo, pleaded guilty last week to building and running the cybercrime marketplace Rydox. The Rydox marketplace has been active since February 2016; it facilitated over 7,600 […


Kosovo national Ardit Kutleshi pleaded guilty to running Rydox, a cybercrime marketplace that sold stolen identities and credentials for years.





Ardit Kutleshi, 28 years old and a citizen of Kosovo, pleaded guilty last week to building and running the cybercrime marketplace Rydox.





The Rydox marketplace has been active since February 2016; it facilitated over 7,600 sales of stolen PII, access devices, and cybercrime tools, generating $230,000 since 2016. It offered over 321,000 products to 18,000 users, including names, social security numbers, and hacking tools. Thousands of U.S. victims were affected.





“According to court documents, since at least 2016, Rydox conducted over 7,600 transactions involving stolen personally identifiable information (PII), stolen access devices, means of identification, and cybercrime tools and services, receiving at least $232,000 in revenue.  These transactions involved the sale of PII stolen from victims located in the United States.” reads the DoJ’s press release. “Kutleshi pleaded guiltyin the District Court for the Western District of Pennsylvania to aggravated identity theft and money laundering conspiracy. “





The U.S. authorities seized the Rydox domain in 2025, a coordinated operation by the FBI and Royal Malaysian Police seized servers in Kuala Lumpur, Malaysia, that hosted the illicit marketplace. The US authorities also seized $225,000 in cryptocurrency.





Kutleshi did not run Rydox alone. His brother, Jetmir, also helped operate the marketplace. He pleaded guilty separately and was sentenced in December 2025 before being deported to Kosovo.





Both brothers have now pleaded guilty in US federal court for their roles in running the same criminal marketplace, bringing the case to a close after an investigation that involved several countries.





The FBI arrested Kutleshi in Kosovo in December 2024, seized the Rydox.cc domain at the same time, and extradited him to the US in 2025. Coordination on this case included Kosovo’s Special Prosecution Office and Cybercrime Investigation Directorate, Albania’s anti-corruption body, and Malaysia’s Royal Police and Attorney General’s office, which is a genuinely international lineup for what was, at its core, a website selling other people’s information.





Kutleshi pleaded guilty in the Western District of Pennsylvania to aggravated identity theft and money laundering conspiracy. He faces a mandatory minimum of two years on the identity theft count and up to 20 years on the money laundering charge. Sentencing is scheduled for February 9, 2027.





The FBI’s cyber division assistant director put the harm in plain terms. Rydox, he said, put





“Cybercriminals Ardit Kutleshi and his brother Jetmir — who pleaded guilty and was sentenced in December 2025 prior to his deportation back to Kosovo — operated the Rydox marketplace for their own gain, making hundreds of thousands of dollars from the marketplace where cyber criminals could purchase information and tools to effect and further their online crime,” said U.S. Attorney Troy Rivetti of the Western District of Pennsylvania. “These types of cybercrimes cause not only financial loss, but also ongoing psychological harm to the victims who lose both money as well as trust in institutions and the online market infrastructure. Our office will continue to work with our law enforcement partners to find and prosecute individuals who attempt to profit from the illegal sharing and sale of other people’s personal information and access devices, and related cybercrime.”





That second part is easy to undercount. Identity theft isn’t a one-time event that ends when the fraudulent charge gets reversed. It follows people through credit checks, background checks, and account recovery processes for years, and the damage to how someone trusts systems they have to keep using is harder to quantify than the dollar figure prosecutors cite in press releases.





The Justice Department’s Criminal Division said that, since 2020, its Computer Crime and Intellectual Property Section has secured convictions against more than 180 cyber and intellectual property criminals. Courts have also ordered the return of more than $350 million to victims.





Kutleshi’s case adds to those figures. His extradition from Kosovo also shows that operating outside the United States does not necessarily protect cybercriminals from US prosecution.





Follow me on Twitter: @securityaffairs and Facebook and Mastodon





Pierluigi Paganini





(SecurityAffairs – hacking, cybercrime)







Source: SecurityAffairs
Source Link: https://securityaffairs.com/199825/uncategorized/rydox-admin-faces-20-years-after-selling-stolen-data-and-fraud-tools.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Breach



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.