Kosovar Owner of Rydox Marketplace Pleads Guilty in US Court
At a glance
- Severity
- Low
- Used in attacks
- No flaws named
- Reported by
- 1 outlet
A Kosovar national pleaded guilty in a US court to charges related to the creation and administration of the Rydox cybercrime marketplace.
The individual, Ardit Kutleshi, 28, was arrested in December 2024 along with two other suspects, Jetmir Kutleshi and Shpend Sokoli. He was extradited to the US last year.
Rydox was disrupted in December 2024, when the US obtained judicial authorization to seize www.Rydox.cc, the domain that hosted the marketplace. The Rydox servers were also seized, along with roughly $225,000 in cryptocurrency.
According to court documents, Rydox allowed cybercriminals to trade stolen personally identifiable information (PII), stolen payment card data, account credentials, and cybercrime tools.
At least 321,372 cybercrime products were allegedly offered on Rydox, including stolen information such as names, addresses, credentials, credit cards, and Social Security numbers, along with phishing kits, stealer logs, and spamming tools.
Rydox was estimated to have had approximately 18,000 users when taken down.
Advertisement. Scroll to continue reading.
More than 7,600 transactions were made through the marketplace between 2016 and 2024, and its operators received at least $232,000 in revenue.
Kutleshi pleaded guilty to identity theft and money laundering conspiracy charges and is scheduled for sentencing on February 9, 2027.
He faces two years of mandatory prison for the aggravated identity theft and up to 20 years in prison for money laundering.
Related: US Court Sentences Armenian Man to Prison for Ryuk Ransomware Attacks
Related: AI-Powered Phishing Platform EvilTokens Disrupted by Microsoft
Related: In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw
Related: NightmareStresser DDoS Service Disrupted in International Operation
Originally published by SecurityWeek. © SecurityWeek. Written by Ionut Arghire.
Fastnexa security experts
Dealing with this in your own company?
If this story touches software, suppliers or systems you use, a Fastnexa security expert can tell you what it means for you and what to do first.
Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →
Coverage
One outlet has carried this so far.
2026-09-25 12:16 UTC
Related stories
- OpenAI apologizes for agents breaching Australian government websites without authorization
The Record · 2026-09-29
- French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks
The Hacker News · 2026-09-29
- Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor
The Hacker News · 2026-09-29
- Automated AI agent used to breach cybersecurity nonprofit DIVD
BleepingComputer · 2026-09-29
- Dotted Line: How construction is dealing with cybersecurity in the age of AI
Cybersecurity Dive · 2026-09-29