Rydox marketplace admin pleads guilty, faces 22 years in prison

A major online marketplace that facilitated the sale of stolen personal data and cybercrime tools has been brought to justice, with its administrator facing up to 22 years in prison. Ardit Kutleshi, a 28-year-old Kosovar national, pleaded guilty to operating Rydox, a platform that allowed buyers to purchase sensitive information, login credentials, and malicious software.

Rydox was shut down in December 2024 as part of an international law enforcement operation involving Kosovo, Albania, and Malaysia. The arrests were made after a joint investigation by the two countries’ authorities and the FBI’s Cyber Division. Kutleshi was extradited to the United States in 2025 and charged with various crimes related to his role at Rydox.

The platform was notorious for allowing users to purchase stolen identities, login credentials, credit card information, and other sensitive data. According to court documents, between February 2016 and its shutdown in 2024, Rydox facilitated over 7,600 sales of stolen personal information, including Social Security numbers, names, and addresses of thousands of U.S. citizens. Additionally, the platform offered more than 321,000 “cybercrime products” for sale to over 18,000 users.

To make purchases on Rydox, users had to deposit cryptocurrency into their accounts via various payment methods, including Bitcoin, Monero, and Ethereum. The marketplace charged registered sellers a one-time fee of between $200 and $500 to become authorized sellers, who then received 60% of the sale proceeds while the platform retained 40%.

The guilty plea is significant not only because it marks another major blow against online cybercrime operations but also because it highlights the need for greater vigilance when it comes to protecting personal data. With the rise of dark web marketplaces and cryptocurrency-facilitated transactions, law enforcement agencies face a daunting task in tracking down and prosecuting those responsible.

As we continue to see high-profile cases like this one, it’s essential that individuals take steps to safeguard their personal information and stay informed about online threats. This includes being cautious when sharing sensitive data online, using strong passwords and two-factor authentication, and staying up-to-date with the latest security best practices.

In practical terms, consumers can protect themselves by monitoring their credit reports regularly, using reputable antivirus software, and being wary of unsolicited emails or messages that ask for personal information. Additionally, organizations should prioritize data protection and invest in robust cybersecurity measures to prevent breaches and minimize the impact of any potential attacks.


Source: Bleeping Computer — 2026-09-25