Ransomware Group intelligence
PrinzEugen
ActiveTrack PrinzEugen with 2 published victims and 2 known leak locations in a single intelligence view.
Overview
PrinzEugen is tracked by Breach House as a ransomware group with 2 published victims.
South Africa is currently the most targeted country in this dataset.
2 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (2)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Unknown | 6cudc5cqa2bjpwdhcwm2lj6dbqejjjqzeo6ipwvmbazr6cgu7vfk3dad.onion |
| Leak location 2 | Onion service | Unknown | prinzfkbjiazbrur4mjje6mntjc4vydx3iatkkzycufoylqcoo4y7pqd.onion |
Top Activity Sectors
No sector intelligence available.
Ransom Notes (0)
▼No ransom notes available for this group.
Tools Used
▼No tools used available.
YARA Rules (0)
▼No YARA rules available.
Indicators of Compromise (0)
▼No IoCs available for this group.
Negotiation Chats (0)
▼No negotiation chats available.
Research Sources
No external research sources linked yet.
Victims (2)
Search, filter and paginate the victim timeline for PrinzEugen.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Transitions Pro Centre Val de Loire id29193 View details | France | Other | ||
|
The swift attack has resulted in both the exfiltration and encryption of hundreds of gigabytes. In the event of complete non-compliance; Files will be fully released for public download. |
|||||
| Ransomware | Standard Bank Group id29194 View details | South Africa | Finance / Legal / Insurance | ||
|
Beginning on February 27th 2026, The 3 week long attack on both Standard Bank and Liberty has resulted in 1.2TB of data being exfiltrated from internal servers. |
|||||