Skip to content

🇷🇺 The Gentlemen

Threat-actor battle card · maintained from public sources · last updated 2026-09-10

CategoryRansomware-as-a-Service
AttributionQilin splinter (formerly ArmCorp, a Qilin affiliate; payment dispute triggered split July 22, 2025; founded by "hastalamuerte" / "zeta88"; Krebs Jun 2026 identifies admin as Alexander Andreevich Yapaev, 36, Izhevsk, Russia — corroborated by Check Point backend-leak analysis)
First seenMid-2025 (ArmCorp); rebranded as The Gentlemen July 2025
StatusActive
Rank#2
Victims L3M234
Victims YTD335
Primary targetsManufacturing, Critical infrastructure, Professional services, Healthcare, Defense, Finance, Government

Overview

The Gentlemen is a Qilin splinter that surfaced mid-2025 after a payment dispute, founded by a disgruntled former Qilin affiliate ("hastalamuerte" / "zeta88"). It is the fastest-scaling ransomware group on record600+ claimed victims in 2026 alone through end of July (675 total since launch) per Comparitech and The Insurer Q2 reporting, putting it second only to Qilin. Currently #2 globally with worm-like LAN propagation confirmed by Huntress and Halcyon. 24% of 2026 victims are in manufacturing; 21% are US-based. Third-party analysis (The Insurer, July 24, 2026) named TheGentlemen the most active threat actor in Q2 2026. The group is also documented (unit 42 / Aug 26 briefing) as an early adopter of AI-orchestrated attack tooling. (Note: YTD in frontmatter reflects the site leaderboard figure derived from ransomware.live; third-party DLS aggregators report higher counts due to different deduplication methodology.)

Tradecraft

  • Go-based locker targeting Windows, Linux, NAS and CSD, with a dedicated C locker for ESXi.
  • Aggressive 90% affiliate payout to attract operators; official BreachForums partnership announced May 2026.
  • Worm-like self-propagation: encryptor launches automated lateral-movement sub-routines across adjacent subnets on execution; can autonomously compromise an entire Active Directory within hours from a single foothold. Confirmed in the Mackay Sugar OT incident (two mills shut simultaneously from one initial access).
  • Actively exploiting Fortinet FortiGate vulnerabilities for initial access (confirmed by Rescana/Huntress).
  • Reconnaissance suite: SharpADWS for Active Directory enumeration — wraps LDAP queries in SOAP messages to bypass standard event logging (noted by Kaspersky/Securelist as an evasion differentiator); NetScan and Advanced IP Scanner for network/service mapping; netsh for network configuration probing. (Securelist June 30, 2026)
  • GentleKiller — an in-house, centrally maintained BYOVD EDR-killer suite (≥8 variants, each abusing a different vulnerable/malicious driver) integrating HexKiller, ThrottleBlood, HavocKiller, and OxideHarvest credential stealer; targets 400+ processes across 48 security products (CrowdStrike, SentinelOne, Defender, ESET, Palo Alto, Sophos, etc.); can operationalise newly public BYOVD PoCs within days. Analysed by ESET in June 2026.
  • New Go obfuscator variant (identified by Kaspersky June 2026): renames symbols, source code files, and structures; alters function signatures — making static analysis significantly harder than the original mid-2025 locker.
  • SystemBC proxy malware (RC4-encrypted SOCKS5 tunnel + in-memory payload execution) deployed across C2 infrastructure; C2 server seizure/analysis revealed 1,570+ infections across affiliates.

Notable victims

  • Mackay Sugar (Australia) — agri-industrial/OT; Farleigh and Racecourse mills (North Queensland) suspended cane haulage and milling June 10 during peak crushing season; partial manual restart June 12; harvest supply chain disrupted for local growers; first confirmed OT-disrupting victim. SecurityWeek · The Record
  • Thyssenkrupp Marine Systems (TKMS) / Atlas Elektronik (Germany) — defense electronics; Atlas Elektronik makes submarine sonar systems, acoustic sensors, and torpedo guidance for the German Navy and allied export customers; DLS claim June 28, 2026; estimated attack June 25; 🟥 unverified — no TKMS public statement.
  • Au Vieux Campeur (France) — outdoor retail (24 stores, 180,000+ members); confirmed cyberattack June 2; DLS June 25 after 23-day ransom stalemate.
  • Canada Wide Media (Canada) — media/publishing; DLS June 23.
  • GIA Partners LLC (US) — financial services; DLS June 23.
  • Keretapi Tanah Melayu Berhad (KTMB) (Malaysia) — national railway; 3,858 employees and 8,428 users exposed; DLS May 6.
  • Mahajak Development (Thailand) — technology distribution; DLS June 15.
  • Pou Sheng International Holdings (China/HK) — footwear retail (Yue Yuen subsidiary; exclusive distributor of Nike, adidas, PUMA, Under Armour in China); DLS June 30, 2026; 🟥 unverified. ransomware.live · RedPacket Security
  • KALIACT ANCHETA et Associés (France) — legal services; DLS June 30; 🟥 unverified.
  • KUNERT Fashion (Germany) — legwear manufacturer; DLS June 30; 🟥 unverified.
  • Indus Protech Solutions (India) — IT services; DLS July 30; 🟥 unverified.
  • Malaysian Nuclear Agency (Malaysia) — government / nuclear research; DLS July 30; 🟥 unverified — high-sensitivity target consistent with TheGentlemen's expanding government/critical-infrastructure targeting.
  • MicroPhase Corporation (US) — defense electronics / RF/microwave components; DLS July 30; 🟥 unverified.
  • Philippine Savings Bank (PSBank) (Philippines) — retail banking; DLS August 1, 2026; 🟥 unverified — separate from the January 2026 Qilin listing; two different groups claiming the same institution in one calendar year warrants PSBank disclosure investigation. RedPacket Security
  • Veradigm (US) — healthcare technology (EHR/e-prescribing/practice-management); DLS claim Sep 5, 2026, alleging 3.5M patient records including SSNs; company confirms a narrow, credential-based API compromise (no clinical data, no network/server breach) but has not confirmed the attacker's record-count claim; largest-profile 2026 target to date for this group. BleepingComputer

Assessment

A tier-1 capability threat at the level of Qilin and LockBit. If it is in your sector, assume EDR bypass is the default pre-encryption step and that a single compromised endpoint can become an entire-domain incident within hours. The Mackay Sugar case demonstrates that OT/ICS environments are now in scope — the worm-like propagation does not distinguish between IT and OT network segments. The TKMS/Atlas Elektronik DLS claim (June 28, 🟥 unverified) raises the stakes to potential defense-industrial exposure. As of September 2026, TheGentlemen continues DLS postings at a sustained pace into new geographies and sectors: Malaysia (Nuclear Agency, July 30 — government/critical infrastructure), Philippines (PSBank, August 1 — banking), US defense electronics (MicroPhase, July 30). The Southeast Asian and government targeting pattern that emerged in July 2026 appears structural rather than opportunistic. A notable September 2026 development: TheGentlemen is documented (Unit 42 investigation, published Sep 2–3) as an early adopter of AI-orchestrated attack tooling — a case study attributed to their affiliate ecosystem showed AI agents executing a full enterprise compromise in under 10 hours. A May 2026 internal backend leak exposed the operator's identity: Krebs on Security (Jun 10, 2026) identifies admin "hastalamuerte"/"zeta88" as Alexander Andreevich Yapaev, 36, of Izhevsk, Republic of Udmurtia, Russia — a marketing professional by day; attribution corroborated by Constella Intelligence phone-number pivot and Check Point's analysis of the leaked Rocket backend. No arrest or indictment has been publicly reported as of September 2026. Third-party aggregators (Comparitech, The Insurer) now place The Gentlemen as the second-most prolific ransomware operation of 2026 — a position consistent with the site leaderboard (rank 2) and the competitive L3M trajectory.

Sources

🗂️ Attacks & victims

All disclosed victims attributed to this actor, newest first.

September 2026

Sep 08 Veradigm The Gentlemen Ransomware · healthcare technology · US Chicago-based EHR/e-prescribing/practice-management vendor confirms an attacker used compromised third-party vendor credentials to access a specific Veradigm API and download patient data, including Social Security numbers for a subset of customers; no clinical/medical data, network or server compromise. The Gentlemen posted Veradigm to its leak site Sep 5, asserting 3.5M patient records (names, addresses, SSNs, emails, phones) were taken, and set a Sep 11 publication deadline absent ransom negotiation. The access itself is company-confirmed; the 3.5M-record scope is the attacker's own figure. · Sources: BleepingComputer · The Record

August 2026

Aug 24 Espac The Gentlemen Ransomware · Construction · Chile Chilean construction company; The Gentlemen DLS claim Aug 24 threatening sensitive data exposure · Sources: https://www.dexpose.io/thegentlemen-ransomware-attack-on-espac/
Aug 22 Thialf The Gentlemen Ransomware · Sports / Entertainment · Netherlands TheGentlemen ransomware DLS claim August 22 2026; Thialf is an international speed skating venue in Heerenveen, Netherlands; data scope unconfirmed · Sources: https://www.ransomware.live/
Aug 22 Promatrix The Gentlemen Ransomware · Technology / IT Services · USA TheGentlemen ransomware DLS claim August 22 2026; Promatrix is a US IT services firm; data scope unconfirmed · Sources: https://www.ransomware.live/
Aug 19 Senvest Capital The Gentlemen Ransomware · Financial Services · USA TheGentlemen ransomware group DLS claim Aug 19 2026 against international hedge fund and investment firm; data theft threatened; Senvest manages billions in public equities, private markets, and real estate; no public confirmation from Senvest · Sources: https://www.dexpose.io/thegentlemen-ransomware-targets-senvest-capital/
Aug 19 Babcock Africa The Gentlemen Ransomware · Engineering / Asset Management · South Africa TheGentlemen ransomware DLS claim August 19 2026; Babcock Africa is a major engineering and asset management company serving critical infrastructure and heavy equipment across Africa; data scope unconfirmed; 🟥 unverified DLS claim · Sources: https://ransomware.live/id/QmFiY29ja0B0aGVnZW50bGVtZW4=
Aug 10 AIMS Group The Gentlemen Ransomware · Conglomerate · AE TheGentlemen DLS posting August 10, 2026; UAE-based conglomerate; data scope unconfirmed · Sources: https://www.ransomware.live/
Aug 10 Canopy Support Services The Gentlemen Ransomware · Nonprofit · CA TheGentlemen DLS posting August 10, 2026; Canadian nonprofit; data scope unconfirmed · Sources: https://www.ransomware.live/
Aug 01 Philippine Savings Bank The Gentlemen Ransomware · Finance · PH TheGentlemen claim on DLS August 1 2026; separate from January 2026 Qilin listing (different group, independent claim). No statement from PSBank; no data published. · Sources: https://www.redpacketsecurity.com/thegentlemen-ransomware-victim-philippine-savings-bank/

July 2026

Jul 30 Indus Protech Solutions The Gentlemen Ransomware · industrial supply chain / MRO · India TheGentlemen DLS claim July 30, 2026; Chennai-based bulk MRO and supply chain services provider for global trade; data scope and impact unconfirmed; 🟥 unverified · Sources: https://www.redpacketsecurity.com/thegentlemen-ransomware-victim-indus-protech-solutions/ · https://www.ransomware.live/
Jul 30 Malaysian Nuclear Agency The Gentlemen Ransomware · government / nuclear research · Malaysia TheGentlemen DLS claim July 30, 2026; Malaysian government nuclear research and technology organisation; data scope and impact unconfirmed; 🟥 unverified · Sources: https://www.breachsense.com/breaches/ · https://www.ransomware.live/
Jul 30 MicroPhase Corporation The Gentlemen Ransomware · defense electronics / IT · US TheGentlemen DLS claim July 30, 2026; US defense electronics and IT company; data scope and impact unconfirmed; 🟥 unverified · Sources: https://www.breachsense.com/breaches/ · https://www.ransomware.live/
Jul 23 Czech Philharmonic The Gentlemen Ransomware · arts/culture · Czech Republic TheGentlemen DLS claim July 23; data volume not yet disclosed; cultural heritage institution based in Prague. Unverified DLS claim. · Sources: https://www.ransomware.live/
Jul 20 Advantage Home Health Care The Gentlemen Ransomware · healthcare · US US home healthcare company claimed by The Gentlemen extortion group July 20; no confirmation from organization · Sources: https://www.ransomware.live/
Jul 15 BRAC The Gentlemen Ransomware · Humanitarian/NGO · Bangladesh World's largest NGO listed on The Gentlemen DLS July 15; no public statement from BRAC. Unverified claim. · Sources: https://www.ransomware.live/group/the-gentlemen
Jul 11 Carita The Gentlemen Ransomware · retail · France French luxury skincare and cosmetics brand claimed on The Gentlemen data leak site July 11; data type and volume unconfirmed; company has not issued a public statement · Sources: ransomware.live · breachsense.com
Jul 07 Mercado Libre The Gentlemen Ransomware · e-commerce · technology/Argentina Latin America's largest e-commerce and fintech platform; The Gentlemen DLS claim July 7, 2026; approximately 118,244 users reportedly affected; company has not issued a public statement; data scope and impact unconfirmed; 🟥 unverified — verify before treating as breach · https://www.escudodigital.com/en/cybersecurity/mercado-libre-hit-by-ransomware-attack.html · https://blog.rankiteo.com/mer1783492030-mercado-libre-ransomware-july-2026/ · https://www.ransomware.live/id/TWVyY2FkbyBMaWJyZUB0aGVnZW50bGVtZW4= · Sources: [EscudoDigital] · [Rankiteo] · [ransomware.live]
Jul 06 CSEC RATP The Gentlemen Ransomware · services · France The Gentlemen DLS claim July 6, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/thegentlemen · Sources: [ransomware.live]
Jul 06 Arabia Falcon Insurance Company The Gentlemen Ransomware · insurance · Oman The Gentlemen DLS claim July 6, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/thegentlemen · Sources: [ransomware.live]
Jul 03 CUI Agency The Gentlemen Ransomware · insurance · US US insurance agency based in Utah; The Gentlemen DLS claim July 3, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/ · Sources: [DeXpose]
Jul 03 MakoLab S.A. The Gentlemen Ransomware · IT consulting · Poland Polish IT and digital transformation consultancy providing software development, cloud, and data analytics services; The Gentlemen DLS claim July 3, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/ · Sources: [DeXpose]
Jul 03 Shamrock The Gentlemen Ransomware · sector unknown · US The Gentlemen DLS claim July 3, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/thegentlemen · Sources: [ransomware.live]
Jul 01 Boyne City The Gentlemen Ransomware · local government · US City of Boyne City, northern Michigan municipality; The Gentlemen DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.breachsense.com/breaches/2026/july/ · Sources: [Breachsense]
Jul 01 FAC Logistique The Gentlemen Ransomware · logistics · France French logistics company; The Gentlemen DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.breachsense.com/breaches/2026/july/ · Sources: [Breachsense]
Jul 01 Centre Ophtalmologique d'Ermont The Gentlemen Ransomware · healthcare · ophthalmology/France French ophthalmology centre; The Gentlemen DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.breachsense.com/breaches/2026/july/ · Sources: [Breachsense]
Jul 01 CTM India Limited motherson INDIA The Gentlemen Ransomware · metalworking · automotive manufacturing/India Motherson Group subsidiary; precision metalworking and automotive component manufacturer; The Gentlemen DLS claim July 1, 2026; estimated attack June 22, 2026; data scope unconfirmed; 🟥 unverified · https://www.redpacketsecurity.com/thegentlemen-ransomware-victim-ctm-india-limited-motherson-india/ · https://ransomware.live/id/Q1RNIEluZGlhIExpbWl0ZWQgbW90aGVyc29uIElORElBQHRoZWdlbnRsZW1lbg== · Sources: [RedPacket Security] · [ransomware.live]

June 2026

Jun 30 Pou Sheng International Holdings The Gentlemen Ransomware · footwear retail · China+Hong Kong China-based athletic footwear retailer and Yue Yuen Group subsidiary; The Gentlemen DLS claim June 30, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/thegentlemen · Sources: [ransomware.live]
Jun 30 SDEZ The Gentlemen Ransomware · textile services · France historic French family-owned company (est. 1816) specialising in industrial rental and maintenance of professional linen, workwear, and hygiene equipment; national network of industrial laundries across France and Belgium; 700+ employees; The Gentlemen DLS claim June 30, 2026; data scope and impact unconfirmed; 🟥 unverified · https://ransomware.live/id/U0RFWkB0aGVnZW50bGVtZW4= · Sources: [ransomware.live]
Jun 30 Mondottica The Gentlemen Ransomware · fashion · luxury eyewear/Italy global luxury eyewear company specialising in design, production, and worldwide distribution of premium sunglasses and optical frames under licensed brand names; international operations across Europe and APAC; The Gentlemen DLS claim June 30, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.redpacketsecurity.com/thegentlemen-ransomware-victim-mondottica/ · https://www.ransomware.live/group/thegentlemen · Sources: [RedPacket Security] · [ransomware.live]
Jun 30 Melcor Developments Ltd The Gentlemen Ransomware · real estate · construction/Canada diversified real estate developer and asset manager headquartered in Edmonton, Alberta; community development, commercial property, and residential construction across Western Canada; The Gentlemen DLS claim June 30, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.redpacketsecurity.com/thegentlemen-ransomware-victim-melcor-developments-ltd/ · https://www.ransomware.live/group/thegentlemen · Sources: [RedPacket Security] · [ransomware.live]
Jun 30 Indra Group The Gentlemen Ransomware · defense · aerospace/technology/Spain one of Europe's largest defense, aerospace, and technology companies; €5B annual revenue; 62,000 employees; operates in 140+ countries; first Spanish company to join NATO's cyberdefence coalition; provides critical defense systems, air traffic management, space infrastructure, and IT to governments, militaries, and CNI operators worldwide; The Gentlemen DLS claim June 30, 2026; Indra confirmed attack was limited to a non-critical subsidiary environment; CSIRT protocols activated; operations unaffected; data type and volume unknown; data publication deadline July 9, 2026; 🟥 unverified · https://cybernews.com/security/indra-group-ransomware-attack-data-leak/ · https://www.cybersecurity-insiders.com/the-gentleman-ransomware-targets-prominent-european-nato-contractor/ · https://socradar.io/free-tools/ransomware-intelligence/victims/indra-group-9773ee2c · Sources: [Cybernews] · [Cybersecurity Insiders] · [SOCRadar]
Jun 28 Thyssenkrupp Marine Systems (TKMS) GmbH / Atlas Elektronik The Gentlemen Ransomware · defense electronics · Germany TKMS is Germany's principal naval shipbuilding group; Atlas Elektronik is its naval electronics subsidiary (HQ Bremen), specialising in submarine sonar systems, acoustic measurement, and heavyweight torpedo guidance for the German Navy and allied export customers; The Gentlemen DLS claim June 28, 2026; estimated attack date June 25, 2026; data scope unconfirmed; 🟥 unverified — no TKMS or Atlas Elektronik public statement · https://www.ransomware.live/id/VGh5c3NlbmtydXBwIE1hcmluZSBTeXN0ZW1zIChUS01TKSBHbWJIIC8gQXRsYXMgRWxla3Ryb25pa0B0aGVnZW50bGVtZW4= · https://www.ransomware.live/summary/ · Sources: [ransomware.live] · [ransomware.live summary]
Jun 25 Au Vieux Campeur The Gentlemen Ransomware · outdoor equipment retail · France French outdoor gear chain (24 stores, 180,000+ members); company confirmed cyberattack June 2, 2026 and mobilised incident response; DLS claim appeared June 25 after 23-day negotiation window closed without ransom payment; data scope unconfirmed · https://frenchbreaches.com/alertes/au-vieux-campeur-mq5ponk61juevh4e5fj · https://www.cyberattaque.org/au-vieux-campeur-victime-dune-cyberattaque-une-enquete-est-en-cours/ · https://www.ransomware.live/ · Sources: [FrenchBreaches] · [Cyberattaque.org] · [ransomware.live]
Jun 25 Al-Dhow The Gentlemen Ransomware · diversified business group · Kuwait Kuwaiti multi-sector business conglomerate; DLS claim June 25, 2026; data scope and impact unconfirmed · https://www.ransomware.live/ · https://www.breachsense.com/breaches/ · Sources: [ransomware.live] · [Breachsense]
Jun 25 Gegenbauer Elektrotechnik & IT The Gentlemen Ransomware · electrical engineering · IT services/Austria Austrian electrical engineering and IT services company; DLS claim June 25, 2026; data scope and impact unconfirmed · https://www.ransomware.live/ · https://www.breachsense.com/breaches/ · Sources: [ransomware.live] · [Breachsense]
Jun 25 BDS CZ The Gentlemen Ransomware · real estate · Czech Republic Czech real estate agency; DLS claim June 25, 2026; data scope and impact unconfirmed · https://www.breachsense.com/breaches/ · https://www.ransomware.live/group/thegentlemen · Sources: [Breachsense] · [ransomware.live]
Jun 25 Bell Hardware The Gentlemen Ransomware · commercial hardware · US family-owned commercial hardware company; DLS claim June 25, 2026; data scope and impact unconfirmed · https://www.breachsense.com/breaches/ · https://www.ransomware.live/group/thegentlemen · Sources: [Breachsense] · [ransomware.live]
Jun 25 Beran Concrete, Inc. The Gentlemen Ransomware · construction · building materials/US concrete construction and materials company; DLS claim June 25, 2026; data scope and impact unconfirmed · https://www.breachsense.com/breaches/ · https://www.ransomware.live/group/thegentlemen · Sources: [Breachsense] · [ransomware.live]
Jun 24 Stadttheater Giessen The Gentlemen Ransomware · arts · culture/Germany municipal theatre serving the city of Giessen in the Mittelhessen region; publicly funded civic cultural venue; The Gentlemen DLS claim June 24, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.redpacketsecurity.com/thegentlemen-ransomware-victim-stadttheater-giessen/ · https://www.ransomware.live/group/thegentlemen · Sources: [RedPacket Security] · [ransomware.live]
Jun 23 (Jun 22-23 DLS batch: 15 new victims claimed past 24h incl. healthcare×3, hospitality, manufacturing, transportation The Gentlemen Ransomware · individual org names not yet enumerated in public feeds; to be split as sources firm up) · — https://purple-ops.io/blog/gentlemen-ransomware-victims · Sources: [PurpleOps]
Jun 23 Canada Wide Media The Gentlemen Ransomware · media · Canada https://www.breachsense.com/breaches/ · https://www.ransomware.live/ · Sources: [Breachsense] · [ransomware.live]
Jun 23 GIA Partners LLC The Gentlemen Ransomware · financial services · US https://www.breachsense.com/breaches/ · https://www.ransomware.live/ · Sources: [Breachsense] · [ransomware.live]
Jun 22 Hooke Laboratories The Gentlemen Ransomware · biotechnology · US preclinical contract research supplier specialising in autoimmune disease model kits (Hooke Kits) used by academic and pharma research laboratories; The Gentlemen DLS claim June 22, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.redpacketsecurity.com/thegentlemen-ransomware-victim-hooke-laboratories/ · https://www.ransomware.live/id/SG9va2UgTGFib3JhdG9yaWVzQHRoZWdlbnRsZW1lbg== · https://www.breachsense.com/breaches/hooke-laboratories-data-breach/ · Sources: [RedPacket Security] · [ransomware.live] · [Breachsense]
Jun 22 Royal Thai Navy Housing Cooperative The Gentlemen Ransomware · public sector · housing cooperative/Thailand cooperative managing housing projects, financial services, and welfare programs for Royal Thai Navy personnel and their families; The Gentlemen DLS claim June 22, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.redpacketsecurity.com/thegentlemen-ransomware-victim-royal-thai-navy-housing-cooperative/ · https://www.ransomware.live/group/thegentlemen · Sources: [RedPacket Security] · [ransomware.live]
Jun 20 AmiGest The Gentlemen Ransomware · IT services · France French IT integrator specialising in cloud, network, and managed services for SME clients; The Gentlemen ransomware DLS claim June 20, 2026; data scope and impact unconfirmed; attribution confirmed by DeXpose reporting · https://www.dexpose.io/theGentlemen-ransomware-attack-on-amigest/ · https://www.ransomware.live/group/thegentlemen · Sources: [DeXpose] · [ransomware.live]
Jun 15 Mahajak Development Co., Ltd. The Gentlemen Ransomware · technology distribution · Thailand leading IT and technology distributor in Thailand; The Gentlemen DLS claim June 15, 2026; data scope and impact unconfirmed · https://www.dexpose.io/the-gentlemen-ransomware-targets-mahajak-development/ · https://www.ransomware.live/group/thegentlemen · Sources: [DeXpose] · [ransomware.live]
Jun 10 Mackay Sugar The Gentlemen Ransomware · agri-industrial · Australia mills shut, harvest disrupted; ransomware confirmed (The Gentlemen attribution) · Sources: SecurityWeek / The Record
Jun 04 National Industries The Gentlemen Ransomware · automotive manufacturing · India Indian precision-engineered automotive components manufacturer under the Metalman Group; supplies major two-wheeler OEMs; The Gentlemen DLS claim June 4, 2026; data scope and impact unconfirmed; 🟥 unverified — no victim statement · https://www.dexpose.io/thegentlemen-ransomware-attack-on-national-industries/ · https://www.ransomware.live/group/thegentlemen · Sources: [DeXpose] · [ransomware.live]

May 2026

May 06 Keretapi Tanah Melayu Berhad The Gentlemen Ransomware · transportation · railway/Malaysia Malaysia's national railway company; The Gentlemen DLS claim May 6, 2026; 3,858 employees and 8,428 users exposed; 21 third-party employee credentials and 143 external attack surface vulnerabilities identified; estimated attack date May 3, 2026; rail operations unaffected · https://www.dexpose.io/the-gentlemen-ransomware-group-targets-keretapi-tanah-melayu-berhad/ · https://www.ransomware.live/id/S2VyZXRhcGkgVGFuYWhAdGhlZ2VudGxlbWVu · Sources: [DeXpose] · [ransomware.live]

← All threat actors · Full victim database →