TLDR
The US Justice Department has seized a cloud computing account used by Cambodias Huione Group to launder billions from crypto fraud and online scams.
- DOJ targeted the cloud backend of Huione Guarantee, a Telegram-based marketplace accused of helping move at least $4 billion in illicit crypto flows.
- This marks a shift from just freezing wallets to attacking the technical infrastructure supporting pig-butchering and investment scams that cost Americans over $7.2 billion in 2025 alone.
- Expect tighter scrutiny of cloud and messaging-based crypto services, plus further Treasury and FinCEN actions against Southeast Asia scam networks and their stablecoin/payment rails.
Deep Dive
1. What DOJ Actually Seized
US authorities seized a cloud computing account used by subsidiaries of the Huione Group, described as "one of the world's most prolific criminal marketplaces" for laundering proceeds from crypto investment fraud and cyber scams. The account hosted backend infrastructure for Huione Guarantee (also called Haowang Guarantee), a Telegram-based marketplace that advertised stolen card and identity data, malware proceeds and crypto escrow services for romance and investment scams. This infrastructure allegedly supported billions in fraud proceeds, much of it tied to Southeast Asian scam centers and some linked to North Korean cyber heists, according to court filings and Treasury findings.
Law enforcement is not just chasing individual addresses anymore, it is going after the computing backbone that lets large-scale crypto crime operate at scale.
2. Why Targeting Infrastructure Matters
By seizing the cloud account, DOJ effectively crippled Huiones ability to process, store and route illicit transactions, rather than only blocking visible on-chain endpoints. FinCEN previously labeled Huione a "primary money laundering concern" and estimates Huione-linked networks moved at least $4 billion in illegal funds between 2021 and 2025. At the same time, the FBIs Internet Crime Complaint Center reports Americans lost over $7.2 billion to crypto investment fraud in 2025, within roughly $21 billion of total cybercrime losses. Taking down infrastructure gives investigators potential access to logs and user data, and signals that tech intermediaries hosting high-risk flows will face far more pressure to vet clients.
3. What To Watch Next
Treasury is already extending its Huione-related rules to successor entities like H-Pay Service PLC to prevent simple rebranding workarounds, and has sanctioned additional individuals and entities tied to Southeast Asian scam compounds. Huione has tried to adapt by launching its own stablecoin (USDH) and related on-chain ecosystem, which will likely become a focus for analytics firms and regulators. Going forward, watch for: 1) further DOJ/FinCEN designations around pig-butchering and Telegram markets, 2) new expectations on cloud and messaging platforms that touch crypto flows, and 3) knock-on effects for privacy tools and lightly regulated offshore venues that resemble Huiones model.
Conclusion
The seizure of Huiones cloud infrastructure shows US authorities are escalating from wallet-by-wallet actions to dismantling the digital plumbing of large crypto fraud networks. For crypto users, the main implications are stricter scrutiny of unregulated platforms, higher risks of funds being frozen if they touch tainted ecosystems, and a gradual push toward venues with stronger AML and KYC controls.
