Cointime

Download App
iOS & Android

Fraud Shop Genesis Market Shut Down in International Law Enforcement Operation, Sanctioned by OFAC

Validated Project

On April 4, 2023, authorities shut down popular fraud shop Genesis Market and arrested hundreds of its users around the world in a coordinated international law enforcement effort dubbed Operation Cookie Monster. Additionally, OFAC sanctioned the criminal marketplace the next day on April 5.

Fraud shops like Genesis are an important part of the cybercriminal ecosystem. Typically operating on the dark web, they facilitate the sale of stolen data and personally identifiable information (PII), which in turn can be used for several different forms of cybercrime, including scamming, identity theft, and ransomware. Below, we’ll break down Genesis Market’s role in the cybercriminal ecosystem plus its on-chain activity, and show you how today’s law enforcement action makes the internet a safer place.

What was Genesis Market?

Genesis Market was a fraud shop catering to users around the world. Its marketplace allowed for the sale of several different forms of stolen PII such as credentials for email addresses, social media accounts, bank accounts, and cryptocurrency service accounts, all available to be perused in a searchable database. In many cases, Genesis could provide active session cookies for these accounts that allowed buyers to bypass multi-factor authentication. The screenshot below shows a typical listing on Genesis.

The listing is for a single, compromised victim device, and shows the services that device accessed and for which the seller has user credentials. Those services include three cryptocurrency exchanges (whose names we’ve blurred out) meaning a buyer of this user’s data could potentially steal any funds the victim holds in those accounts. Victims like the one shown above typically have had their machines compromised by information stealing malware, which can access credentials stored in web browsers like Chrome and Firefox. In addition to individual users’ PII, Genesis also offered compromised remote access credentials that could allow cybercriminals like ransomware gangs to break into organizations’ computer networks.

Genesis Market’s on-chain activity

Genesis Market has received tens of millions of dollars’ worth of cryptocurrency during its lifetime, primarily in Bitcoin. Most of its incoming funds since May came from mainstream exchanges, with crypto ATMs also contributing a significant amount.

We also see a few spikes in value received from services we’ve labeled risky, most of which are exchanges with low or no KYC. The Chainalysis Reactor graph below shows a number of actors sending funds to Genesis, including ransomware attackers, underground money laundering services, and other cybercriminals.

Note the relatively low amounts sent from each of these clusters. Credentials purchased on Genesis could cost as little as $1 or less, so while $15 sent from a credit card broker may not seem like a huge deal, it could represent serious financial losses for 15 individuals.

Shutting down Genesis makes all internet users safer

Data sellers like Genesis aren’t necessarily the first thing you think of when it comes to cybercrime, but these sorts of ancillary service providers are crucial to enabling scamming, hacking, and ransomware attacks. For that reason, we commend all of the agencies around the world who contributed to the shutdown of Genesis.

While Genesis’ OFAC designation doesn’t list any of the service’s cryptocurrency addresses, Chainalysis has identified hundreds of thousands of Genesis addresses, with more likely to come as our data improves over time. We’ve already labeled these addresses as belonging to a sanctioned entity in all of our products, and any Chainalysis KYT users with exposure prior to designation would have received alerts for its previous category — fraud shop — per their alert preferences. We will share any other relevant updates on this case as is possible.

This material is for informational purposes only, and is not intended to provide legal, tax, financial, or investment advice. Recipients should consult their own advisors before making these types of decisions. Chainalysis has no responsibility or liability for any decision made or any other acts or omissions in connection with Recipient’s use of this material.

Chainalysis does not guarantee or warrant the accuracy, completeness, timeliness, suitability or validity of the information in this report and will not be responsible for any claim attributable to errors, omissions, or other inaccuracies of any part of such material.

Read more: https://blog.chainalysis.com/reports/genesis-market-fraud-shop-shutdown-sanction/

Comments

All Comments

Recommended for you

  • US Military Begins Interception of Vessels in the Strait of Hormuz

    On the 13th local time, the US military has started intercepting vessels entering and exiting the Strait of Hormuz. The US Central Command stated on the 12th that, following a presidential order, it would begin a blockade of all maritime traffic to and from Iranian ports at 10 AM Eastern Time on the 13th. The statement indicated that this blockade applies to all vessels from various countries entering and exiting Iranian ports and the coastal areas of the country, covering all Iranian ports located in the Persian Gulf and the Gulf of Oman. The Central Command noted that vessels traveling to and from non-Iranian ports through the Strait of Hormuz will not be interfered with. (CCTV)

  • BTC Surpasses $72,000

    Market data shows that BTC has surpassed $72,000, currently priced at $72,007.19, with a 24-hour increase of 1.63%. The market is experiencing significant volatility, so please ensure proper risk management.

  • Iran Considers Abandoning Uranium Enrichment as Condition for U.S. to End War

    On April 13, according to the New York Post: Iranian officials are exploring the possibility of abandoning uranium enrichment activities as a condition for the United States to end the war.

  • BitMine Increases ETH Holdings by Over 71,000, Total Holdings Exceed 4.87 Million ETH

    As of April 12, Eastern Time, BitMine's total cryptocurrency and cash holdings amount to $11.8 billion. BitMine holds 4,874,858 ETH (an increase of 71,524 ETH from last week), which represents 4.04% of the total Ethereum supply of 120.7 million ETH. Additionally, it holds 197 BTC, shares in Beast Industries valued at $200 million, shares in Eightco Holdings (NASDAQ: ORBS) worth $102 million, and $719 million in uncollateralized cash. As of April 13, 2026, the total amount of staked ETH by BitMine is 3,334,637 ETH (valued at $2,206 per ETH, totaling $7.4 billion).

  • UBS Group Raises Brent Crude Oil Price Forecast to $85 per Barrel by March 2027

    On April 13, UBS Group announced an increase in its Brent crude oil price forecast, projecting $100 per barrel by the end of June, $95 per barrel by the end of September, and $90 per barrel by the end of December. UBS Group has raised its forecast for Brent crude oil prices to $85 per barrel by the end of March 2027. (Jin Shi)

  • People's Bank of China: M2 Balance Reaches 353.86 Trillion Yuan at End of March, Up 8.5% Year-on-Year

    On April 13, it was reported that at the end of March, the broad money supply (M2) balance was 353.86 trillion yuan, an increase of 8.5% year-on-year. The narrow money supply (M1) balance stood at 119.32 trillion yuan, rising by 5.1% year-on-year. The currency in circulation (M0) balance was 14.71 trillion yuan, up 12.5% year-on-year. In the first quarter, a net cash injection of 613.5 billion yuan was made.

  • Trump: U.S. to Block Ships Entering and Exiting Iranian Ports on April 13 at 10 AM ET

    On April 13, President Trump announced that the United States will block ships entering and exiting Iranian ports at 10 AM Eastern Time on April 13. (Jin Shi)

  • Trump: The World Relies on the U.S. for Oil Without Crossing the Strait of Hormuz

    On April 13, Trump stated that due to Iran's actions regarding the Strait of Hormuz, the entire world is relying on the U.S. for oil. "We will implement blockade measures tomorrow at 10 AM... Other countries are also working to ensure that Iran cannot sell oil, and this will be very effective! Many ships are heading to our country, refueling, and then leaving to transport this oil, so they won't have to cross the Strait of Hormuz. This issue will ultimately be resolved. The whole world is relying on the U.S. Thanks to the 'Drill, Baby, Drill' campaign, our oil reserves have increased, surpassing the combined total of Russia and Saudi Arabia. The current situation is that ships are arriving, refueling, and no longer needing to cross the Strait of Hormuz!" (Jinshi)

  • BTC Surpasses $71,000

    Market data shows that BTC has surpassed $71,000, currently priced at $71,007.73, with a 24-hour decline of 2.79%. The market is experiencing significant volatility, so please ensure proper risk management.

  • ETH Falls Below $2200

    Market data shows that ETH has fallen below $2200, currently priced at $2199.99, with a 24-hour decline of 3.64%. The market is experiencing significant volatility, so please ensure proper risk management.