U.S. Authorities Shut Down Major Dark Web Marketplace with 117,000 Users
On Tue, Jul 9, 2024, the U.S. Attorney’s Office for the Eastern District of Virginia announced the seizure of approximately 145 domains related to the BidenCash marketplace. This operation was executed with support from the U.S. Secret Service, FBI,…
On Tue, Jul 9, 2024, the U.S. Attorney’s Office for the Eastern District of Virginia announced the seizure of approximately 145 domains related to the BidenCash marketplace. This operation was executed with support from the U.S. Secret Service, FBI, Dutch National High Tech Crime Unit, and cybersecurity firms including Searchlight Cyber and The Shadowserver Foundation. Additionally, cryptocurrency funds linked to illicit transactions were confiscated.
BidenCash has been operational since March 2022, serving as a platform for the trade of stolen payment card data, login credentials, and server access. Administrators charged transaction fees, facilitating over 117,000 customers to traffic more than 15 million credit card numbers and personally identifiable information (PII), generating upwards of $17 million in illicit revenue.
The BidenCash marketplace specialized in carding, the trade of stolen credit card data, and also sold compromised credentials, including Secure Shell Protocol (SSH) access for unauthorized server entry. To attract cybercriminals and build trust, BidenCash periodically released large datasets for free. Between October 2022 and February 2023, the marketplace published 3.3 million stolen credit card records, including sensitive data such as card numbers, expiration dates, Card Verification Value (CVV) codes, account holder names, addresses, emails, and phone numbers.
The site utilized both clear web and dark web domains, including:
https://bidencash.bid https://bidencash.asia http://biden3veilozweo2xubiusixn4kbfbbih23s6xsd35bzsuaz2weiz4yd.onion
Following the takedown, these domains now redirect to a law enforcement-controlled server, displaying an official seizure notice.
Impact, Law Enforcement Strategy, and Next Steps
The seizure of BidenCash’s infrastructure marks a significant step in combating cyber-enabled financial crime. By redirecting seized domains to law enforcement-controlled servers, authorities have disrupted a major hub for carding and credential theft, reducing the risk of further victimization. However, many individuals whose data was sold remain vulnerable if they have not updated their banking or personal information.
Attorney’s Office for the Eastern District of Virginia announced the seizure of approximately 145 domains related to the BidenCash marketplace.
The operation also included the legal seizure of cryptocurrency assets, targeting the financial lifeblood of these illicit markets. This aligns with broader efforts to dismantle crypto-enabled criminal networks, as seen in recent global operations targeting malware-as-a-service and infostealer platforms.
Carding : The trafficking and unauthorized use of stolen credit card data. PII (Personally Identifiable Information) : Data that can be used to identify individuals, such as names, addresses, and account details. SSH (Secure Shell Protocol) : A cryptographic network protocol for secure remote server access, often sold on illicit markets for unauthorized entry. CVV (Card Verification Value) : A security feature for credit card transactions, essential for online purchases. DDoS (Distributed Denial-of-Service) : Attacks that overwhelm a server or network to disrupt services—a tactic sometimes used against or by illicit marketplaces.
Metric Value
Operational Period March 2022 – June 2025
Domains Seized ~145
Customers
117,000
Payment Cards Trafficked
15 million
Revenue Generated
$17 million
Free Card Data Leaked 3.3 million records
Cryptocurrency Seized Undisclosed
The BidenCash takedown demonstrates the increasing sophistication and international coordination of law enforcement in combating cybercrime. While the immediate threat from this marketplace has been neutralized, ongoing vigilance and public awareness remain crucial to protect against the persistent risk of identity theft and financial fraud.
Based on reporting by GBHackers.
