Ransomware Group intelligence
PrinzEugen
ActiveTrack PrinzEugen with 9 published victims and 3 known leak locations in a single intelligence view.
Overview
PrinzEugen is tracked by Breach House as a ransomware group with 9 published victims.
United States is currently the most targeted country in this dataset.
3 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (3)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 3 | Onion service | Up checked 52m ago | prinzkpn6d3itrgcytmsmlcpt5mgwn3ihpck2hsed5cezlbtbi3wklid.onion |
| Leak location 2 | Onion service | Down checked 51m ago | prinzfkbjiazbrur4mjje6mntjc4vydx3iatkkzycufoylqcoo4y7pqd.onion |
| Leak location 1 | Onion service | Down checked 52m ago | 6cudc5cqa2bjpwdhcwm2lj6dbqejjjqzeo6ipwvmbazr6cgu7vfk3dad.onion |
Top Activity Sectors (4)
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue PrinzEugen, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: PrinzEugen executes malicious payloads via PowerShell to automate system reconnaissance and privilege escalation.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1569.002 Service Execution Execution
What they do: PrinzEugen executes ransomware binaries through Windows Service mechanisms to ensure persistence and broad deployment.
What that means: Adversaries may abuse the Windows service control manager to execute malicious commands or payloads.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: PrinzEugen disables security tools by modifying Windows Defender and AV processes to prevent detection and recovery.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: PrinzEugen deletes Volume Shadow Copies and backup directories via vssadmin to eliminate recovery options.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1083 File and Directory Discovery Discovery
What they do: PrinzEugen employs file and directory discovery to enumerate critical system paths and user data before encryption.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1135 Network Share Discovery Discovery
What they do: PrinzEugen uses network share discovery to locate victim file shares and identify high-value data for exfiltration.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: PrinzEugen moves laterally through SMB/Windows Admin Shares to compromise additional hosts across networks.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: PrinzEugen encrypts victim files using custom ransomware binaries targeting business documents and backups.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: PrinzEugen inhibits system recovery by corrupting restore points and disabling backup services during impact phase.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
-
T1491.001 Internal Defacement Impact
What they do: PrinzEugen performs internal defacement by replacing victim web content with ransom notices on accessible servers.
What that means: An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems.
Victims (9)
Search, filter and paginate the victim timeline for PrinzEugen. Showing 1–9 of 9.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Driving School Software id30080 View details | United States | Education | ||
|
Driving School Software is an education sector company based in the US, providing software solutions to driving schools. The company operates in the education sector, offering various software tools to manage driving school operations. Driving School Software was listed as a ransomware victim associated with PrinzEugen. |
|||||
| Ransomware | Driving School Software id30080 View details | United States | Education | ||
|
Hundreds of driving schools impacted. 16 Million rows of SQL, 8000 FULL credit cards, and more. Full leak post + data available on the new PRINZ EUGEN site. prinzkpn6d3itrgcytmsmlcpt5mgwn3ihpck2hsed5cezlbtbi3wklid.onion |
|||||
| Ransomware | prinzkpn6d3itrgcytmsmlcpt5mgwn3ihpck2hsed5cezlbtbi3wklid.onion [NEW LEAK POSTED ON OUR NEW... id30031 View details | Other | |||
|
Prinzkpn6d3itrgcytmsmlcpt5mgwn3ihpck2hsed5cezlbtbi3wklid onion appears to be a website operating on the dark web, likely used for publishing data related to ransomware attacks. The site is associated with the threat actor PrinzEugen. It is located on the onion network, which is a part of the dark web. Prinzkpn6d3itrgcytmsmlcpt5mgwn3ihpck2hsed5cezlbtbi3wklid onion was listed as a ransomware victim associated with PrinzEugen |
|||||
| Ransomware | prinzkpn6d3itrgcytmsmlcpt5mgwn3ihpck2hsed5cezlbtbi3wklid.onion [NEW LEAK POSTED ON OUR NEW... id30031 View details | Other | |||
|
VISIT THE NEW SITE! prinzkpn6d3itrgcytmsmlcpt5mgwn3ihpck2hsed5cezlbtbi3wklid.onion prinzkpn6d3itrgcytmsmlcpt5mgwn3ihpck2hsed5cezlbtbi3wklid.onion prinzkpn6d3itrgcytmsmlcpt5mgwn3ihpck2hsed5cezlbtbi3wklid.onion prinzkpn6d3itrgcytmsmlcpt5mgwn3ihpck2hsed5cezlbtbi3wklid.onion |
|||||
| Ransomware | NEW PRINZ EUGEN SITE [NOT A CASE FILE] id30089 View details | Other | |||
|
prinzkpn6d3itrgcytmsmlcpt5mgwn3ihpck2hsed5cezlbtbi3wklid.onion OLD SITE (this site) WILL BE TAKEN OFFLINE SHORTLY |
|||||
| Ransomware | Spratley's of Mortimer id29707 View details | Retail / E-commerce | |||
|
spratleys.co.uk Hundreds of GBs of data encrypted across company file shares, If you would like the decryption key you just need to ask. |
|||||
| Ransomware | Spratley's id29709 View details | Other | |||
|
Hundreds of GBs of data encrypted across company file shares. If you would like the decryption key you just need to ask. |
|||||
| Ransomware | Transitions Pro Centre Val de Loire id29193 View details | France | Other | ||
|
The swift attack has resulted in both the exfiltration and encryption of hundreds of gigabytes. In the event of complete non-compliance; Files will be fully released for public download. |
|||||
| Ransomware | Standard Bank Group id29194 View details | South Africa | Finance / Legal / Insurance | ||
|
Beginning on February 27th 2026, The 3 week long attack on both Standard Bank and Liberty has resulted in 1.2TB of data being exfiltrated from internal servers. |
|||||