THREAT ACTOR
PRINZ-EUGEN_
DormantPRINZ-EUGEN is a ransomware operator tracked through its public data-leak infrastructure. The group operates under the double-extortion model that defines the modern ransomware ecosystem: file encryption combined with the threat of stolen-data publication on a public leak site. It continues to post fresh victim claims as part of an ongoing extortion campaign.
For Ransomnews editorial coverage of PRINZ-EUGEN, including incident write-ups, attribution notes and additional context, see the Threat Groups archive or run a site search.
Victims by year
- 2026 6
Leak site mirrors
3 mirrors tracked, 0 currently reachable. These are criminal-infrastructure URLs; links are deliberately not provided.
-
6cudc5cqa2bjpwdhcwm2lj6dbqejjjqzeo6ipwvmbazr6cgu7vfk3dad.onionPrinz Eugen — Prinz Eugen snapshot · 2026-05-19 03:30 -
prinzfkbjiazbrur4mjje6mntjc4vydx3iatkkzycufoylqcoo4y7pqd.onionCase Files — Prinz Eugen snapshot · 2026-06-30 01:15 -
prinzkpn6d3itrgcytmsmlcpt5mgwn3ihpck2hsed5cezlbtbi3wklid.onion✠ snapshot · 2026-09-18 04:28
Recent victims
The 50 most recent victims claimed by PRINZ-EUGEN. Total in the index: 6.
| Date listed | Victim | Description |
|---|---|---|
| 2026-06-28 | Driving School Software | Hundreds of driving schools impacted. 16 Million rows of SQL, 8000 FU… |
| 2026-06-26 | prinzkpn6d3itrgcytmsmlcpt5mgwn3ihpck2hsed5cezlbtbi3wklid.onion [NEW LEAK POSTED ON OUR NEW | VISIT THE NEW SITE! prinzkpn6d3itrgcytmsmlcpt5mgwn3ihpck2hsed5cezlbt… |
| 2026-06-22 | NEW PRINZ EUGEN SITE [NOT A CASE FILE] | prinzkpn6d3itrgcytmsmlcpt5mgwn3ihpck2hsed5cezlbtbi3wklid.onion OLD SI… |
| 2026-06-13 | Transitions Pro Centre Val de Loire | The swift attack has resulted in both the exfiltration and encryption … |
| 2026-06-13 | Spratley's of Mortimer | spratleys.co.uk Hundreds of GBs of data encrypted across company file… |
| 2026-04-16 | Standard Bank Group | Beginning on February 27th 2026, The 3 week long attack on both Standa… |
CONFIRMED ATTACKS
Prinz Eugen confirmed attacks: 1 verified incident
Ransomnews has verified 1 Prinz Eugen incident against named organisations, each corroborated by a public source such as a breach notification, regulatory filing or press report. All of them fall in February 2026. South Africa accounts for 1 of them (100%). The most affected sector is finance, at 1 confirmed victim.
Confirmed victims by year
Most affected sectors
Most affected countries
Verified Prinz Eugen incidents
| Date | Organisation | Sector | Location | Records | Ransom paid | Source |
|---|---|---|---|---|---|---|
| February 2026 | Standard Bank Group | Finance | Johannesburg, South Africa | — | Unknown | Source |
Claimed vs confirmed. The figures above the fold on this page come from Prinz Eugen's own leak-site postings and reflect what the operation claims. The table here is a separate evidence class: incidents Ransomnews verified against a public source. Confirmed counts are lower than claimed counts by design: most victims never disclose, and some leak-site listings are recycled, exaggerated or fabricated. Records and ransom figures are shown only where a named source disclosed them. See the full ransomware statistics or the Ransomtracker dataset.