Ardit Kutleshi has pleaded guilty over his role administering the Rydox marketplace, an illegal platform that traded in stolen personal data, login credentials, credit card details and cybercrime tools, leaving him facing a maximum of 22 years in federal prison. The Rydox marketplace guilty plea caps a case that began with coordinated arrests across two countries and a server seizure on the other side of the world.
Kosovo law enforcement and Albania’s Special Anti-Corruption Body (SPAK) arrested Kutleshi, then 28, alongside two fellow Rydox administrators, Jetmir Kutleshi and Shpend Sokoli, in December 2024. The operation simultaneously shut down the platform, seized the rydox[.]cc domain, and, with the assistance of the Royal Malaysian Police, seized the marketplace’s servers in Kuala Lumpur.
From Kosovo to a US courtroom
Ardit Kutleshi was subsequently extradited to the United States in 2025. He faced charges including conspiracy to commit identity theft, aggravated identity theft, two counts of identity theft, access device fraud and money laundering. He has now pleaded guilty to aggravated identity theft and money laundering conspiracy specifically, and is scheduled to be sentenced on 9 February 2027. The money laundering count carries a maximum penalty of 20 years; the aggravated identity theft count carries a mandatory minimum of two years, which must run consecutively.
‘Rydox put cybercriminal tools and sensitive data up for sale, including the stolen identities and logins of thousands of people,’ said Brett Leatherman, assistant director of the FBI‘s Cyber Division. ‘The FBI and its foreign partners shut the marketplace down, and now the man who created it and ran it pleaded guilty.’
The scale of the Rydox operation
Court documents paint a picture of a platform that ran for nearly a decade. Between February 2016 and its shutdown in 2024, Rydox sellers conducted over 7,600 sales of login credentials, credit card information and stolen personal data, including Social Security numbers, names and addresses belonging to thousands of US citizens.
Beyond that, the platform listed over 321,000 other cybercrime products (devices, software tools and materials for committing fraud) to a user base of more than 18,000 registered accounts. According to SecurityWeek, the operators received at least $232,000 in revenue across the platform’s lifetime, a figure that underscores how commercially structured the marketplace had become.
The business model was straightforward and deliberately incentivised participation. Users had to deposit cryptocurrency before making any purchase, with Bitcoin, Monero, Ripple, Ethereum, Litecoin, Perfect Money, Tron and Verge all accepted as payment methods. Funds were deposited into a Rydox-controlled wallet and used to buy illicit products and services from other sellers on the platform.
Those who wanted to sell, rather than just buy, paid a one-time registration fee that fluctuated between $200 and $500. In return, sellers received 60% of the proceeds from each transaction, with the marketplace retaining the remaining 40%. It is the kind of revenue-share model that would not look out of place on a legitimate e-commerce platform, which was presumably rather the point.
The Rydox case is one of several high-profile dark web prosecutions to progress recently. The owner of the Incognito dark web drugs market was sentenced to 30 years in prison in February, while a California man who sold fentanyl and methamphetamine on the Nemesis dark web marketplace received a sentence of more than 26 years in federal prison. Kutleshi’s sentencing, now fixed for early 2027, will add another data point to what is becoming a consistent pattern of lengthy custodial terms for marketplace operators.

