// THREAT ACTOR
PRINZ-EUGEN_
ActivePRINZ-EUGEN is a ransomware operator tracked through its public data-leak infrastructure. The group operates under the double-extortion model that defines the modern ransomware ecosystem — file encryption combined with the threat of stolen-data publication on a public leak site — and continues to post fresh victim claims as part of an ongoing extortion campaign.
For Ransomnews editorial coverage of PRINZ-EUGEN — incident write-ups, attribution notes, and additional context — see the Threat Groups archive or run a site search.
Victims by year
- 2026 6
Leak site mirrors
3 mirrors tracked, 1 currently reachable. These are criminal-infrastructure URLs — links are deliberately not provided.
-
6cudc5cqa2bjpwdhcwm2lj6dbqejjjqzeo6ipwvmbazr6cgu7vfk3dad.onionPrinz Eugen — Prinz Eugen snapshot · 2026-05-19 03:30 -
prinzfkbjiazbrur4mjje6mntjc4vydx3iatkkzycufoylqcoo4y7pqd.onionCase Files — Prinz Eugen snapshot · 2026-06-30 01:15 -
prinzkpn6d3itrgcytmsmlcpt5mgwn3ihpck2hsed5cezlbtbi3wklid.onion✠ snapshot · 2026-08-06 21:13
Recent victims
The 50 most recent victims claimed by PRINZ-EUGEN. Total in the index: 6.
| Date listed | Victim | Description |
|---|---|---|
| 2026-06-28 | Driving School Software | Hundreds of driving schools impacted. 16 Million rows of SQL, 8000 FU… |
| 2026-06-26 | prinzkpn6d3itrgcytmsmlcpt5mgwn3ihpck2hsed5cezlbtbi3wklid.onion [NEW LEAK POSTED ON OUR NEW | VISIT THE NEW SITE! prinzkpn6d3itrgcytmsmlcpt5mgwn3ihpck2hsed5cezlbt… |
| 2026-06-22 | NEW PRINZ EUGEN SITE [NOT A CASE FILE] | prinzkpn6d3itrgcytmsmlcpt5mgwn3ihpck2hsed5cezlbtbi3wklid.onion OLD SI… |
| 2026-06-13 | Transitions Pro Centre Val de Loire | The swift attack has resulted in both the exfiltration and encryption … |
| 2026-06-13 | Spratley's of Mortimer | spratleys.co.uk Hundreds of GBs of data encrypted across company file… |
| 2026-04-16 | Standard Bank Group | Beginning on February 27th 2026, The 3 week long attack on both Standa… |