prinz eugen
ransomware group · aka unknown - no widely reported alternative names · unknown · active since First publicly reported around June 2025; exact date unknown
Prinz Eugen is a ransomware and data-extortion group first publicly reported in mid-2025 that operates a Tor-based leak site for naming and threatening victims. It drew broader attention in June 2025 when it claimed an attack tied to Standard Bank Group; the bank publicly confirmed that a breach at a third-party service provider exposed personal information of some of its customers. Public attribution, aliases, country of origin, and any confirmed ties to established ransomware families remain unknown. Listed victim volume is low - five victims per this dashboard's tracking since 2026-06-13, including announcements of its new leak site - and no public earnings estimates exist.
- double extortion: exfiltrates data and threatens publication on its Tor leak site
- third-party/supply-chain reach: accessed Standard Bank customer data via a breached debt-collection service provider
- uses leak site for both victim listings and operational announcements (e.g., site relaunch)
- observed targeting of banking, education/training, retail, and software/IT-service organizations across South Africa, France, and the UK
- whether ransomware encryption is deployed alongside exfiltration is not consistently documented; some incidents appear data-theft-focused
- initial access methods, tooling, and malware: unknown; no widely reported exploit or malware associations
Standard Bank Group (June 2025) - breach via a third-party service provider publicly confirmed by the bank, Transitions Pro Centre Val de Loire (France) - leak-site listing, not independently confirmed, Spratley's of Mortimer (UK) - leak-site listing, not independently confirmed, Driving School Software - leak-site listing, not independently confirmed
No public figure.
Leak-site victims6 posts · newest first
| Victim | Discovered | Details |
|---|---|---|
| Driving School Software | · Jun 28, 2026 | Hundreds of driving schools impacted. 16 Million rows of SQL, 8000 FULL credit cards, and more. Full leak post + data available on the new PRINZ EUGEN site. prinzkpn6d3itrgcytmsmlcpt5mgwn3ihpck2hsed5cezlbtbi3wklid.onion |
| prinzkpn6d3itrgcytmsmlcpt5mgwn3ihpck2hsed5cezlbtbi3wklid.onion [NEW LEAK POSTED ON OUR NEW | · Jun 26, 2026 | VISIT THE NEW SITE! prinzkpn6d3itrgcytmsmlcpt5mgwn3ihpck2hsed5cezlbtbi3wklid.onion prinzkpn6d3itrgcytmsmlcpt5mgwn3ihpck2hsed5cezlbtbi3wklid.onion prinzkpn6d3itrgcytmsmlcpt5mgwn3ihpck2hsed5cezlbtbi3wklid.onion prinzkpn6d3itrgcytmsmlcpt5mgwn3ihpck2hsed5cezlbtbi3wklid.onion |
| NEW PRINZ EUGEN SITE [NOT A CASE FILE] | · Jun 22, 2026 | prinzkpn6d3itrgcytmsmlcpt5mgwn3ihpck2hsed5cezlbtbi3wklid.onion OLD SITE (this site) WILL BE TAKEN OFFLINE SHORTLY |
| Transitions Pro Centre Val de Loire | · Jun 13, 2026 | The swift attack has resulted in both the exfiltration and encryption of hundreds of gigabytes. In the event of complete non-compliance; Files will be fully released for public download. |
| Spratley's of Mortimer | · Jun 13, 2026 | spratleys.co.uk Hundreds of GBs of data encrypted across company file shares, If you would like the decryption key you just need to ask. 6/10/2026 - PS. Our beacon is STILL calling back from within your network. |
| Standard Bank Group | · Apr 16, 2026 | Beginning on February 27th 2026, The 3 week long attack on both Standard Bank and Liberty has resulted in 1.2TB of data being exfiltrated from internal servers. |
In the newsAll →
No articles mention this group yet.