The United States imposed a new round of sanctions on Cambodia’s Prince Group network, targeting nine individuals and 26 companies over alleged involvement in cyber scams, forced labor, human trafficking, and human rights abuses tied to scam compounds in Southeast Asia. Treasury identified Hu Xiaowei, described as Prince Group’s second-in-command, along with figures including Chen Bo, Brendon Luo, Qiu Wei Ren, and Fang Zhizhen, and entities such as CCU Commercial Bank PLC and White Horse Hotel Management Group. U.S. officials said the operations lured workers with fake job offers, confiscated passports, and coerced victims through debt bondage, violence, and threats into running online fraud schemes, including digital-asset investment scams that contributed to at least $10 billion in losses to Americans in 2024.
The Justice Department also seized a cloud computing account used as backend infrastructure by subsidiaries of Cambodia-based Huione Group, which authorities described as a major criminal marketplace and laundering hub linked to scam centers and cyber-enabled theft. Officials said the infrastructure supported Huione Guarantee or Haowang Guarantee, which allegedly facilitated money laundering, stolen-data sales, malware-enabled theft, cryptocurrency escrow services, and other criminal activity. The enforcement action came as Japanese police arrested Hu Xiaowei in Osaka on suspicion of filing a fraudulent address change while living under the Cypriot identity "Hu Shi" and seeking permanent residency, adding to mounting international pressure on Prince Group and associated networks, which have denied the allegations and said their businesses are legitimate.

See the reporting duties and controls this puts on the clock.
5 events from the most recent confirmed update back to the earliest known activity.
OCCRP reported that U.S. lawmakers are advancing bipartisan legislation to create a task force targeting criminal syndicates behind global online scams, with Cambodia highlighted as a major scam hub. The article says an earlier draft named Cambodian Deputy Prime Minister Sar Sokha among potential targets, but that list was removed in the latest version as Sokha retained U.S. legal and lobbying representation.
The U.S. Justice Department announced the seizure of a cloud computing account used as backend infrastructure by subsidiaries of Cambodia-based Huione Group. Authorities said the infrastructure supported Huione Guarantee/Haowang Guarantee, which allegedly facilitated cyber scams, money laundering, stolen data sales, malware-enabled theft, human trafficking schemes, and cryptocurrency escrow services.
The U.S. Treasury Department announced sanctions against nine individuals and 26 companies linked to Cambodia's Prince Group, citing cyber scams, forced labor, and human rights abuses tied to scam compounds in Southeast Asia. The action expanded targeting of Hu Xiaowei and included entities such as CCU Commercial Bank PLC and White Horse Hotel Management Group.
Japanese police arrested Hu Xiaowei in Osaka on suspicion of filing a fraudulent change-of-address notification, alleging he was living in Japan under the Cypriot identity "Hu Shi." Authorities described him as an associate of Cambodia-based Prince Group.
OCCRP reports that Prince Group was sanctioned by the United States, the United Kingdom, and South Korea at the end of the previous year. Several jurisdictions also froze assets linked to the group.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
9 references tracked. Mallory keeps watching after this page renders.
occrp.org
Open sourcecysecurity.news
Open sourcecyberscoop.com
Open sourcejustice.gov
Open sourceoccrp.org
Open sourceenglish.kyodonews.net
Open sourceoccrp.org
Open sourceoccrp.org
Open sourceasahi.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.