FBI and Ukrainian cops disrupt nine crypto exchanges used by ransomware actors

FBI and Ukrainian cops disrupt nine crypto exchanges used by ransomware actors

The US Federal Bureau of Investigation (FBI) in cooperation with the National Police of Ukraine have seized domains of nine virtual currency exchange services used by ransomware groups and other cybercriminals for money laundering.

The domains were seized on April 25, 2023, the FBI said in a press release. The disrupted services include 24xbtc.com, 100btc.pro, pridechange.com, 101crypta.com, uxbtc.com, trust-exchange.org, bitcoin24.exchange, paybtc.pro, and owl.gold. The websites provided support both in Russian and English.

“Domain names offered by organizations which were engaged in cryptocurrency conversions and provided assistance to cybercriminals were seized, and related servers were shut down. US based servers used in the scheme were taken offline by US authorities,” the FBI said.

“Many of these services are advertised on online forums dedicated to discussing criminal activity. By providing these services, the virtual currency exchanges knowingly support the criminal activities of their clients and become co-conspirators in criminal schemes,” the agency added.

The FBI said that the investigation is ongoing, without sharing further details on the operation.


Back to the list

Latest Posts

Cyber Security Week in Review: May 23, 2025

Cyber Security Week in Review: May 23, 2025

In brief: Several major malware operations disrupted,  hackers exploit Ivanti and Cityworks zero-days, and more.
23 May 2025
Russian GRU hackers accused of massive espionage campaign across NATO and allied nations

Russian GRU hackers accused of massive espionage campaign across NATO and allied nations

The cyber offensive reportedly struck dozens of entities, spanning both government and private sectors.
22 May 2025
Chinese-speaking threat actors exploit Cityworks zero-day to hack into US govt agencies

Chinese-speaking threat actors exploit Cityworks zero-day to hack into US govt agencies

The attacks have been ongoing since at least January 2025.
22 May 2025