DOJ Seizes HuiOne Cloud Account, Treasury Sanctions Prince Group Network
Cambodia-based conglomerates accused of laundering proceeds from pig-butchering and cyber-enabled fraud face coordinated U.S. action.

Key points
- The Justice Department seized a cloud computing account operated by HuiOne Group subsidiaries alleged to have helped move criminal proceeds.
- The Treasury simultaneously sanctioned nine individuals and 26 entities linked to Cambodia's Prince Group.
- HuiOne's Telegram-based marketplace has hosted vendors openly advertising money-laundering services and stolen data.
- Independent analysts at Elliptic estimated HuiOne-linked addresses processed more than $24 billion in crypto inflows since 2021.
- No arrests were announced and no dollar figure was placed on the seized cloud assets.
What did the Justice Department actually seize?
On Tuesday the Justice Department announced the seizure of a cloud computing account used by subsidiaries of HuiOne Group, the Cambodia-based conglomerate that has spent the past two years cementing itself as a central plumbing layer of the Southeast Asian scam economy. Prosecutors allege those subsidiaries helped move criminal proceeds tied to cyber-enabled investment scams that have drained billions from American victims.
The seizure landed alongside fresh Treasury sanctions against nine individuals and 26 entities tied to Prince Group, a separate but overlapping Cambodian corporate network. Designations freeze any U.S.-held assets and bar Americans from transacting with the named parties. The full OFAC press release and updated SDN list carry the entity names compliance teams will need.
Why is HuiOne at the center of this?
HuiOne is not a typical target. Its messaging-app marketplaces and payments arms have been repeatedly flagged by researchers and the Treasury's Financial Crimes Enforcement Network as the connective tissue for compounds running romance-investment fraud, also known as pig butchering, in which fraudsters cultivate fake relationships to lure victims into fake investment platforms. FinCEN moved earlier this year to cut HuiOne off from the U.S. Financial system, a designation that bars U.S. Banks from maintaining accounts for the group.
HuiOne Guarantee, the group's Telegram-based marketplace, has hosted thousands of vendors openly advertising money-laundering tools and stolen data. Elliptic estimated last year that HuiOne-linked addresses had processed more than $24 billion in crypto inflows since 2021. The group rebranded portions of its operation after the FinCEN action but kept the same vendor base largely intact.
Should you be watching the Prince Group designations too?
The Treasury action targets Prince Group's leadership tier and a web of affiliated firms spanning real estate and financial services. Neither HuiOne nor Prince Group has publicly responded. Both have previously denied knowingly facilitating fraud.
We first reported on HuiOne's role in the Southeast Asian fraud infrastructure on 24 June 2026, when a DOJ-led sweep against pig-butchering rings went after infrastructure rather than individual operators, the same playbook visible here.
What this means for compliance teams and cloud providers
The cloud seizure is the detail that matters most. Domain takedowns and crypto address freezes are routine; pulling a live tenant out from under a sanctioned conglomerate is rarer. It signals that U.S. Agencies are willing to lean on American cloud providers as enforcement chokepoints when the underlying activity sits offshore and extradition is unrealistic.
For compliance teams, the SDN additions expand the counterparty screening burden across real estate and gaming-adjacent financial services tied to Prince Group. The pattern of going after hosting and payments rails rather than scam operators is now consistent enough to treat as doctrine, not improvisation.



