DOJ Seizes HuiOne Cloud Account, Treasury Sanctions Prince Group Network
Cambodia-based conglomerates accused of laundering proceeds from pig-butchering and cyber-enabled fraud face coordinated U.S. action.

The Justice Department on Tuesday seized a cloud computing account operated by subsidiaries of HuiOne Group, the Cambodia-based conglomerate that has spent the past two years cementing itself as a central plumbing layer of the Southeast Asian scam economy.
The seizure landed alongside fresh Treasury sanctions against nine individuals and 26 entities tied to Prince Group, a separate but overlapping Cambodian corporate network.
HuiOne is not a typical target. Its messaging-app marketplaces and payments arms have been repeatedly flagged by researchers and the Treasury's Financial Crimes Enforcement Network as the connective tissue for compounds running romance-investment fraud, also known as pig butchering. FinCEN moved in May to cut HuiOne off from the U.S. financial system under Section 311 of the Patriot Act.
Prosecutors allege the seized cloud account was used by HuiOne subsidiaries to help move criminal proceeds — including funds tied to cyber-enabled investment scams that have drained billions from American victims.
The Treasury action targets Prince Group's leadership tier and a web of affiliated firms spanning real estate, gaming and financial services. The designations freeze any U.S.-held assets and bar Americans from transacting with the named parties. The full OFAC press release and updated SDN list carry the entity names and identifiers compliance teams will need.
For a quick orientation: HuiOne Guarantee, the group's Telegram-based marketplace, has hosted thousands of vendors openly advertising money-laundering services, stolen data and the technical scaffolding scam compounds rely on. Independent analysts at Elliptic estimated last year that HuiOne-linked addresses had processed more than $24 billion in crypto inflows since 2021. The group rebranded portions of its operation after the FinCEN action but kept the same vendor base largely intact.
Prosecutors did not name a dollar figure on the seized cloud assets. No arrests were announced.
The broader pattern is hard to miss. U.S. authorities are increasingly going after infrastructure — hosting, payments rails, cloud accounts — rather than the scam operators themselves, who sit in jurisdictions where extradition is unrealistic. Pig-butchering losses reported to the FBI's Internet Crime Complaint Center reached $5.8 billion in 2024, and the actual figure is almost certainly higher given chronic underreporting.
Neither HuiOne nor Prince Group has publicly responded to the U.S. actions. Both have previously denied knowingly facilitating fraud.
What's notable here is the cloud seizure itself. Domain takedowns and crypto address freezes are routine; pulling a live tenant out from under a sanctioned conglomerate is rarer, and signals that U.S. agencies are willing to lean on American cloud providers as enforcement chokepoints when the underlying activity sits offshore.



