As part of an international operation, law enforcement authorities seized dozens of domains linked to the BidenCash marketplace — one of the dark web's most notorious platforms for trafficking stolen credit cards, personal data , and remote access credentials.

The platform's main domain on the dark web now redirects to a US Secret Service (USSS), where the familiar banner of seizure due to illegal activities appears.
The police operation was carried out under the coordination of the USSS and the Federal Bureau of Investigation (FBI), with the assistance of the Dutch National Police, the organization The ShadowServer Foundation and the company Searchlight Cyber, which specializes in monitoring cyber attacks.
See also: AVCheck: Authorities shut down service used by cybercriminals
Security researcher g0njxa reported that even the clear web domain in the .asia TLD now redirects to the usssdomainseizure.com . However, there are reports that some subdomains remain accessible.
In a related announcement by the US Department of Justice, it is emphasized that a total of 145 domains as well as digital cryptocurrency wallets, which were directly linked to the operation and financing of the BidenCash market.
BidenCash: Over $17 million in revenue from stolen payment data
According to the US Department of Justice, the operators of the illegal BidenCash profited from every transaction made on the platform, generating total revenue of more than $17 million from 2022 to date.
The marketplace had attracted more than 117,000 users and facilitated the buying and selling of more than 15 million credit and debit card, combined with the personal information of the holders.
These types of purchases are not a new phenomenon; similar dark web stores have been operating for two decades. Initially, data was collected mainly through Point-of-Sale (PoS), which extracted unencrypted card details directly from the memory of terminal systems.
See also: Germany shuts down crypto exchange service eXch

In recent years, however, more modern tactics have become prevalent, such as web skimmers - malicious scripts integrated into e-shops that steal payment data during the completion of purchases.
BidenCash appeared in March 2022, after the closure of the Joker's Stash and the crackdown of several major stores by Russian authorities (e.g. Forum, Trump Dumps, and UniCC).
From the very beginning, the platform's administrators chose an aggressive publicity strategy. In addition to the unique name of the market, they began publishing massive leaks, starting in June 2022 with the leak of a database containing 6,600 cards and millions of email addresses.
In October 2022, the platform made another sensational move, publicly leaking over 1.2 million credit card. This action was allegedly aimed at promoting the marketplace’s services to the cybercriminal ecosystem. Most of the cards belonged to American citizens, while the expiration dates ranged between 2023 and 2026. The leak involved a wide range of regions, suggesting massive and widespread data collection.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
During 2023, BidenCash returned with two more leaks, making public a total of over 4 million payment card numbers, thus continuing the tactic of “marketing through leaks” — a practice increasingly seen in illegal dark web markets.
However, the seizure of domains by the authorities was a strong blow. Despite the efforts of the administrators of such services to rebuild after the strikes, the coordinated seizure operations have a significant impact on their operations.
The U.S. Secret Service (USSS) remains on the front lines of the battle against digital financial fraud — including card theft, cryptocurrency fraud, money laundering, and identity theft.
See also: Authorities shut down six DDoS-for-hire services (+ arrests)
Combating cybercrime requires constant vigilance and cooperation from all parties involved in order to protect individuals and businesses from falling victim to these types of crimes. We can only hope that with continued efforts and advances in technology, we can stay one step ahead of cybercriminals and make the Internet a safer place for everyone.
Therefore, it is important for both government and private actors to work together to identify and address potential vulnerabilities in the digital space . This includes regularly updating security measures , educating the public about online safety, and proactively reporting any suspicious activity to the authorities. By taking a proactive approach, we can help prevent cybercrime and protect ourselves from falling victim to these malicious acts.
Source: www.bleepingcomputer.com
