🇷🇺 The Gentlemen
Threat-actor battle card · maintained from public sources · last updated 2026-09-10
CategoryRansomware-as-a-Service
AttributionQilin splinter (formerly ArmCorp, a Qilin affiliate; payment dispute triggered split July 22, 2025; founded by "hastalamuerte" / "zeta88"; Krebs Jun 2026 identifies admin as Alexander Andreevich Yapaev, 36, Izhevsk, Russia — corroborated by Check Point backend-leak analysis)
First seenMid-2025 (ArmCorp); rebranded as The Gentlemen July 2025
StatusActive
Rank#2
Victims L3M234
Victims YTD335
Primary targetsManufacturing, Critical infrastructure, Professional services, Healthcare, Defense, Finance, Government
Overview
The Gentlemen is a Qilin splinter that surfaced mid-2025 after a payment dispute, founded by a disgruntled former Qilin affiliate ("hastalamuerte" / "zeta88"). It is the fastest-scaling ransomware group on record — 600+ claimed victims in 2026 alone through end of July (675 total since launch) per Comparitech and The Insurer Q2 reporting, putting it second only to Qilin. Currently #2 globally with worm-like LAN propagation confirmed by Huntress and Halcyon. 24% of 2026 victims are in manufacturing; 21% are US-based. Third-party analysis (The Insurer, July 24, 2026) named TheGentlemen the most active threat actor in Q2 2026. The group is also documented (unit 42 / Aug 26 briefing) as an early adopter of AI-orchestrated attack tooling. (Note: YTD in frontmatter reflects the site leaderboard figure derived from ransomware.live; third-party DLS aggregators report higher counts due to different deduplication methodology.)
Tradecraft
- Go-based locker targeting Windows, Linux, NAS and CSD, with a dedicated C locker for ESXi.
- Aggressive 90% affiliate payout to attract operators; official BreachForums partnership announced May 2026.
- Worm-like self-propagation: encryptor launches automated lateral-movement sub-routines across adjacent subnets on execution; can autonomously compromise an entire Active Directory within hours from a single foothold. Confirmed in the Mackay Sugar OT incident (two mills shut simultaneously from one initial access).
- Actively exploiting Fortinet FortiGate vulnerabilities for initial access (confirmed by Rescana/Huntress).
- Reconnaissance suite: SharpADWS for Active Directory enumeration — wraps LDAP queries in SOAP messages to bypass standard event logging (noted by Kaspersky/Securelist as an evasion differentiator); NetScan and Advanced IP Scanner for network/service mapping; netsh for network configuration probing. (Securelist June 30, 2026)
- GentleKiller — an in-house, centrally maintained BYOVD EDR-killer suite (≥8 variants, each abusing a different vulnerable/malicious driver) integrating HexKiller, ThrottleBlood, HavocKiller, and OxideHarvest credential stealer; targets 400+ processes across 48 security products (CrowdStrike, SentinelOne, Defender, ESET, Palo Alto, Sophos, etc.); can operationalise newly public BYOVD PoCs within days. Analysed by ESET in June 2026.
- New Go obfuscator variant (identified by Kaspersky June 2026): renames symbols, source code files, and structures; alters function signatures — making static analysis significantly harder than the original mid-2025 locker.
- SystemBC proxy malware (RC4-encrypted SOCKS5 tunnel + in-memory payload execution) deployed across C2 infrastructure; C2 server seizure/analysis revealed 1,570+ infections across affiliates.
Notable victims
- Mackay Sugar (Australia) — agri-industrial/OT; Farleigh and Racecourse mills (North Queensland) suspended cane haulage and milling June 10 during peak crushing season; partial manual restart June 12; harvest supply chain disrupted for local growers; first confirmed OT-disrupting victim. SecurityWeek · The Record
- Thyssenkrupp Marine Systems (TKMS) / Atlas Elektronik (Germany) — defense electronics; Atlas Elektronik makes submarine sonar systems, acoustic sensors, and torpedo guidance for the German Navy and allied export customers; DLS claim June 28, 2026; estimated attack June 25; 🟥 unverified — no TKMS public statement.
- Au Vieux Campeur (France) — outdoor retail (24 stores, 180,000+ members); confirmed cyberattack June 2; DLS June 25 after 23-day ransom stalemate.
- Canada Wide Media (Canada) — media/publishing; DLS June 23.
- GIA Partners LLC (US) — financial services; DLS June 23.
- Keretapi Tanah Melayu Berhad (KTMB) (Malaysia) — national railway; 3,858 employees and 8,428 users exposed; DLS May 6.
- Mahajak Development (Thailand) — technology distribution; DLS June 15.
- Pou Sheng International Holdings (China/HK) — footwear retail (Yue Yuen subsidiary; exclusive distributor of Nike, adidas, PUMA, Under Armour in China); DLS June 30, 2026; 🟥 unverified. ransomware.live · RedPacket Security
- KALIACT ANCHETA et Associés (France) — legal services; DLS June 30; 🟥 unverified.
- KUNERT Fashion (Germany) — legwear manufacturer; DLS June 30; 🟥 unverified.
- Indus Protech Solutions (India) — IT services; DLS July 30; 🟥 unverified.
- Malaysian Nuclear Agency (Malaysia) — government / nuclear research; DLS July 30; 🟥 unverified — high-sensitivity target consistent with TheGentlemen's expanding government/critical-infrastructure targeting.
- MicroPhase Corporation (US) — defense electronics / RF/microwave components; DLS July 30; 🟥 unverified.
- Philippine Savings Bank (PSBank) (Philippines) — retail banking; DLS August 1, 2026; 🟥 unverified — separate from the January 2026 Qilin listing; two different groups claiming the same institution in one calendar year warrants PSBank disclosure investigation. RedPacket Security
- Veradigm (US) — healthcare technology (EHR/e-prescribing/practice-management); DLS claim Sep 5, 2026, alleging 3.5M patient records including SSNs; company confirms a narrow, credential-based API compromise (no clinical data, no network/server breach) but has not confirmed the attacker's record-count claim; largest-profile 2026 target to date for this group. BleepingComputer
Assessment
A tier-1 capability threat at the level of Qilin and LockBit. If it is in your sector, assume EDR bypass is the default pre-encryption step and that a single compromised endpoint can become an entire-domain incident within hours. The Mackay Sugar case demonstrates that OT/ICS environments are now in scope — the worm-like propagation does not distinguish between IT and OT network segments. The TKMS/Atlas Elektronik DLS claim (June 28, 🟥 unverified) raises the stakes to potential defense-industrial exposure. As of September 2026, TheGentlemen continues DLS postings at a sustained pace into new geographies and sectors: Malaysia (Nuclear Agency, July 30 — government/critical infrastructure), Philippines (PSBank, August 1 — banking), US defense electronics (MicroPhase, July 30). The Southeast Asian and government targeting pattern that emerged in July 2026 appears structural rather than opportunistic. A notable September 2026 development: TheGentlemen is documented (Unit 42 investigation, published Sep 2–3) as an early adopter of AI-orchestrated attack tooling — a case study attributed to their affiliate ecosystem showed AI agents executing a full enterprise compromise in under 10 hours. A May 2026 internal backend leak exposed the operator's identity: Krebs on Security (Jun 10, 2026) identifies admin "hastalamuerte"/"zeta88" as Alexander Andreevich Yapaev, 36, of Izhevsk, Republic of Udmurtia, Russia — a marketing professional by day; attribution corroborated by Constella Intelligence phone-number pivot and Check Point's analysis of the leaked Rocket backend. No arrest or indictment has been publicly reported as of September 2026. Third-party aggregators (Comparitech, The Insurer) now place The Gentlemen as the second-most prolific ransomware operation of 2026 — a position consistent with the site leaderboard (rank 2) and the competitive L3M trajectory.
Sources
🗂️ Attacks & victims
All disclosed victims attributed to this actor, newest first.
September 2026
Sep 08
Veradigm
The Gentlemen
Ransomware · healthcare technology · US
Chicago-based EHR/e-prescribing/practice-management vendor confirms an attacker used compromised third-party vendor credentials to access a specific Veradigm API and download patient data, including Social Security numbers for a subset of customers; no clinical/medical data, network or server compromise. The Gentlemen posted Veradigm to its leak site Sep 5, asserting 3.5M patient records (names, addresses, SSNs, emails, phones) were taken, and set a Sep 11 publication deadline absent ransom negotiation. The access itself is company-confirmed; the 3.5M-record scope is the attacker's own figure. · Sources: BleepingComputer · The Record
August 2026
Aug 24
Espac
The Gentlemen
Ransomware · Construction · Chile
Chilean construction company; The Gentlemen DLS claim Aug 24 threatening sensitive data exposure · Sources: https://www.dexpose.io/thegentlemen-ransomware-attack-on-espac/
Aug 22
Thialf
The Gentlemen
Ransomware · Sports / Entertainment · Netherlands
TheGentlemen ransomware DLS claim August 22 2026; Thialf is an international speed skating venue in Heerenveen, Netherlands; data scope unconfirmed · Sources: https://www.ransomware.live/
Aug 22
Promatrix
The Gentlemen
Ransomware · Technology / IT Services · USA
TheGentlemen ransomware DLS claim August 22 2026; Promatrix is a US IT services firm; data scope unconfirmed · Sources: https://www.ransomware.live/
Aug 19
Senvest Capital
The Gentlemen
Ransomware · Financial Services · USA
TheGentlemen ransomware group DLS claim Aug 19 2026 against international hedge fund and investment firm; data theft threatened; Senvest manages billions in public equities, private markets, and real estate; no public confirmation from Senvest · Sources: https://www.dexpose.io/thegentlemen-ransomware-targets-senvest-capital/
Aug 19
Babcock Africa
The Gentlemen
Ransomware · Engineering / Asset Management · South Africa
TheGentlemen ransomware DLS claim August 19 2026; Babcock Africa is a major engineering and asset management company serving critical infrastructure and heavy equipment across Africa; data scope unconfirmed; 🟥 unverified DLS claim · Sources: https://ransomware.live/id/QmFiY29ja0B0aGVnZW50bGVtZW4=
Aug 10
AIMS Group
The Gentlemen
Ransomware · Conglomerate · AE
TheGentlemen DLS posting August 10, 2026; UAE-based conglomerate; data scope unconfirmed · Sources: https://www.ransomware.live/
Aug 10
Canopy Support Services
The Gentlemen
Ransomware · Nonprofit · CA
TheGentlemen DLS posting August 10, 2026; Canadian nonprofit; data scope unconfirmed · Sources: https://www.ransomware.live/
Aug 01
Philippine Savings Bank
The Gentlemen
Ransomware · Finance · PH
TheGentlemen claim on DLS August 1 2026; separate from January 2026 Qilin listing (different group, independent claim). No statement from PSBank; no data published. · Sources: https://www.redpacketsecurity.com/thegentlemen-ransomware-victim-philippine-savings-bank/
July 2026
Jul 30
Indus Protech Solutions
The Gentlemen
Ransomware · industrial supply chain / MRO · India
TheGentlemen DLS claim July 30, 2026; Chennai-based bulk MRO and supply chain services provider for global trade; data scope and impact unconfirmed; 🟥 unverified · Sources: https://www.redpacketsecurity.com/thegentlemen-ransomware-victim-indus-protech-solutions/ · https://www.ransomware.live/
Jul 30
Malaysian Nuclear Agency
The Gentlemen
Ransomware · government / nuclear research · Malaysia
TheGentlemen DLS claim July 30, 2026; Malaysian government nuclear research and technology organisation; data scope and impact unconfirmed; 🟥 unverified · Sources: https://www.breachsense.com/breaches/ · https://www.ransomware.live/
Jul 30
MicroPhase Corporation
The Gentlemen
Ransomware · defense electronics / IT · US
TheGentlemen DLS claim July 30, 2026; US defense electronics and IT company; data scope and impact unconfirmed; 🟥 unverified · Sources: https://www.breachsense.com/breaches/ · https://www.ransomware.live/
Jul 23
Czech Philharmonic
The Gentlemen
Ransomware · arts/culture · Czech Republic
TheGentlemen DLS claim July 23; data volume not yet disclosed; cultural heritage institution based in Prague. Unverified DLS claim. · Sources: https://www.ransomware.live/
Jul 20
Advantage Home Health Care
The Gentlemen
Ransomware · healthcare · US
US home healthcare company claimed by The Gentlemen extortion group July 20; no confirmation from organization · Sources: https://www.ransomware.live/
Jul 15
BRAC
The Gentlemen
Ransomware · Humanitarian/NGO · Bangladesh
World's largest NGO listed on The Gentlemen DLS July 15; no public statement from BRAC. Unverified claim. · Sources: https://www.ransomware.live/group/the-gentlemen
Jul 11
Carita
The Gentlemen
Ransomware · retail · France
French luxury skincare and cosmetics brand claimed on The Gentlemen data leak site July 11; data type and volume unconfirmed; company has not issued a public statement · Sources: ransomware.live · breachsense.com
Jul 07
Mercado Libre
The Gentlemen
Ransomware · e-commerce · technology/Argentina
Latin America's largest e-commerce and fintech platform; The Gentlemen DLS claim July 7, 2026; approximately 118,244 users reportedly affected; company has not issued a public statement; data scope and impact unconfirmed; 🟥 unverified — verify before treating as breach · https://www.escudodigital.com/en/cybersecurity/mercado-libre-hit-by-ransomware-attack.html · https://blog.rankiteo.com/mer1783492030-mercado-libre-ransomware-july-2026/ · https://www.ransomware.live/id/TWVyY2FkbyBMaWJyZUB0aGVnZW50bGVtZW4= · Sources: [EscudoDigital] · [Rankiteo] · [ransomware.live]
Jul 06
CSEC RATP
The Gentlemen
Ransomware · services · France
The Gentlemen DLS claim July 6, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/thegentlemen · Sources: [ransomware.live]
Jul 06
Arabia Falcon Insurance Company
The Gentlemen
Ransomware · insurance · Oman
The Gentlemen DLS claim July 6, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/thegentlemen · Sources: [ransomware.live]
Jul 03
CUI Agency
The Gentlemen
Ransomware · insurance · US
US insurance agency based in Utah; The Gentlemen DLS claim July 3, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/ · Sources: [DeXpose]
Jul 03
MakoLab S.A.
The Gentlemen
Ransomware · IT consulting · Poland
Polish IT and digital transformation consultancy providing software development, cloud, and data analytics services; The Gentlemen DLS claim July 3, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/ · Sources: [DeXpose]
Jul 03
Shamrock
The Gentlemen
Ransomware · sector unknown · US
The Gentlemen DLS claim July 3, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/thegentlemen · Sources: [ransomware.live]
Jul 01
Boyne City
The Gentlemen
Ransomware · local government · US
City of Boyne City, northern Michigan municipality; The Gentlemen DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.breachsense.com/breaches/2026/july/ · Sources: [Breachsense]
Jul 01
FAC Logistique
The Gentlemen
Ransomware · logistics · France
French logistics company; The Gentlemen DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.breachsense.com/breaches/2026/july/ · Sources: [Breachsense]
Jul 01
Centre Ophtalmologique d'Ermont
The Gentlemen
Ransomware · healthcare · ophthalmology/France
French ophthalmology centre; The Gentlemen DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.breachsense.com/breaches/2026/july/ · Sources: [Breachsense]
Jul 01
CTM India Limited motherson INDIA
The Gentlemen
Ransomware · metalworking · automotive manufacturing/India
Motherson Group subsidiary; precision metalworking and automotive component manufacturer; The Gentlemen DLS claim July 1, 2026; estimated attack June 22, 2026; data scope unconfirmed; 🟥 unverified · https://www.redpacketsecurity.com/thegentlemen-ransomware-victim-ctm-india-limited-motherson-india/ · https://ransomware.live/id/Q1RNIEluZGlhIExpbWl0ZWQgbW90aGVyc29uIElORElBQHRoZWdlbnRsZW1lbg== · Sources: [RedPacket Security] · [ransomware.live]
June 2026
Jun 30
Pou Sheng International Holdings
The Gentlemen
Ransomware · footwear retail · China+Hong Kong
China-based athletic footwear retailer and Yue Yuen Group subsidiary; The Gentlemen DLS claim June 30, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/thegentlemen · Sources: [ransomware.live]
Jun 30
SDEZ
The Gentlemen
Ransomware · textile services · France
historic French family-owned company (est. 1816) specialising in industrial rental and maintenance of professional linen, workwear, and hygiene equipment; national network of industrial laundries across France and Belgium; 700+ employees; The Gentlemen DLS claim June 30, 2026; data scope and impact unconfirmed; 🟥 unverified · https://ransomware.live/id/U0RFWkB0aGVnZW50bGVtZW4= · Sources: [ransomware.live]
Jun 30
Mondottica
The Gentlemen
Ransomware · fashion · luxury eyewear/Italy
global luxury eyewear company specialising in design, production, and worldwide distribution of premium sunglasses and optical frames under licensed brand names; international operations across Europe and APAC; The Gentlemen DLS claim June 30, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.redpacketsecurity.com/thegentlemen-ransomware-victim-mondottica/ · https://www.ransomware.live/group/thegentlemen · Sources: [RedPacket Security] · [ransomware.live]
Jun 30
Melcor Developments Ltd
The Gentlemen
Ransomware · real estate · construction/Canada
diversified real estate developer and asset manager headquartered in Edmonton, Alberta; community development, commercial property, and residential construction across Western Canada; The Gentlemen DLS claim June 30, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.redpacketsecurity.com/thegentlemen-ransomware-victim-melcor-developments-ltd/ · https://www.ransomware.live/group/thegentlemen · Sources: [RedPacket Security] · [ransomware.live]
Jun 30
Indra Group
The Gentlemen
Ransomware · defense · aerospace/technology/Spain
one of Europe's largest defense, aerospace, and technology companies; €5B annual revenue; 62,000 employees; operates in 140+ countries; first Spanish company to join NATO's cyberdefence coalition; provides critical defense systems, air traffic management, space infrastructure, and IT to governments, militaries, and CNI operators worldwide; The Gentlemen DLS claim June 30, 2026; Indra confirmed attack was limited to a non-critical subsidiary environment; CSIRT protocols activated; operations unaffected; data type and volume unknown; data publication deadline July 9, 2026; 🟥 unverified · https://cybernews.com/security/indra-group-ransomware-attack-data-leak/ · https://www.cybersecurity-insiders.com/the-gentleman-ransomware-targets-prominent-european-nato-contractor/ · https://socradar.io/free-tools/ransomware-intelligence/victims/indra-group-9773ee2c · Sources: [Cybernews] · [Cybersecurity Insiders] · [SOCRadar]
Jun 28
Thyssenkrupp Marine Systems (TKMS) GmbH / Atlas Elektronik
The Gentlemen
Ransomware · defense electronics · Germany
TKMS is Germany's principal naval shipbuilding group; Atlas Elektronik is its naval electronics subsidiary (HQ Bremen), specialising in submarine sonar systems, acoustic measurement, and heavyweight torpedo guidance for the German Navy and allied export customers; The Gentlemen DLS claim June 28, 2026; estimated attack date June 25, 2026; data scope unconfirmed; 🟥 unverified — no TKMS or Atlas Elektronik public statement · https://www.ransomware.live/id/VGh5c3NlbmtydXBwIE1hcmluZSBTeXN0ZW1zIChUS01TKSBHbWJIIC8gQXRsYXMgRWxla3Ryb25pa0B0aGVnZW50bGVtZW4= · https://www.ransomware.live/summary/ · Sources: [ransomware.live] · [ransomware.live summary]
Jun 25
Au Vieux Campeur
The Gentlemen
Ransomware · outdoor equipment retail · France
French outdoor gear chain (24 stores, 180,000+ members); company confirmed cyberattack June 2, 2026 and mobilised incident response; DLS claim appeared June 25 after 23-day negotiation window closed without ransom payment; data scope unconfirmed · https://frenchbreaches.com/alertes/au-vieux-campeur-mq5ponk61juevh4e5fj · https://www.cyberattaque.org/au-vieux-campeur-victime-dune-cyberattaque-une-enquete-est-en-cours/ · https://www.ransomware.live/ · Sources: [FrenchBreaches] · [Cyberattaque.org] · [ransomware.live]
Jun 25
Al-Dhow
The Gentlemen
Ransomware · diversified business group · Kuwait
Kuwaiti multi-sector business conglomerate; DLS claim June 25, 2026; data scope and impact unconfirmed · https://www.ransomware.live/ · https://www.breachsense.com/breaches/ · Sources: [ransomware.live] · [Breachsense]
Jun 25
Gegenbauer Elektrotechnik & IT
The Gentlemen
Ransomware · electrical engineering · IT services/Austria
Austrian electrical engineering and IT services company; DLS claim June 25, 2026; data scope and impact unconfirmed · https://www.ransomware.live/ · https://www.breachsense.com/breaches/ · Sources: [ransomware.live] · [Breachsense]
Jun 25
BDS CZ
The Gentlemen
Ransomware · real estate · Czech Republic
Czech real estate agency; DLS claim June 25, 2026; data scope and impact unconfirmed · https://www.breachsense.com/breaches/ · https://www.ransomware.live/group/thegentlemen · Sources: [Breachsense] · [ransomware.live]
Jun 25
Bell Hardware
The Gentlemen
Ransomware · commercial hardware · US
family-owned commercial hardware company; DLS claim June 25, 2026; data scope and impact unconfirmed · https://www.breachsense.com/breaches/ · https://www.ransomware.live/group/thegentlemen · Sources: [Breachsense] · [ransomware.live]
Jun 25
Beran Concrete, Inc.
The Gentlemen
Ransomware · construction · building materials/US
concrete construction and materials company; DLS claim June 25, 2026; data scope and impact unconfirmed · https://www.breachsense.com/breaches/ · https://www.ransomware.live/group/thegentlemen · Sources: [Breachsense] · [ransomware.live]
Jun 24
Stadttheater Giessen
The Gentlemen
Ransomware · arts · culture/Germany
municipal theatre serving the city of Giessen in the Mittelhessen region; publicly funded civic cultural venue; The Gentlemen DLS claim June 24, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.redpacketsecurity.com/thegentlemen-ransomware-victim-stadttheater-giessen/ · https://www.ransomware.live/group/thegentlemen · Sources: [RedPacket Security] · [ransomware.live]
Jun 23
(Jun 22-23 DLS batch: 15 new victims claimed past 24h incl. healthcare×3, hospitality, manufacturing, transportation
The Gentlemen
Ransomware · individual org names not yet enumerated in public feeds; to be split as sources firm up) · —
https://purple-ops.io/blog/gentlemen-ransomware-victims · Sources: [PurpleOps]
Jun 23
Canada Wide Media
The Gentlemen
Ransomware · media · Canada
https://www.breachsense.com/breaches/ · https://www.ransomware.live/ · Sources: [Breachsense] · [ransomware.live]
Jun 23
GIA Partners LLC
The Gentlemen
Ransomware · financial services · US
https://www.breachsense.com/breaches/ · https://www.ransomware.live/ · Sources: [Breachsense] · [ransomware.live]
Jun 22
Hooke Laboratories
The Gentlemen
Ransomware · biotechnology · US
preclinical contract research supplier specialising in autoimmune disease model kits (Hooke Kits) used by academic and pharma research laboratories; The Gentlemen DLS claim June 22, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.redpacketsecurity.com/thegentlemen-ransomware-victim-hooke-laboratories/ · https://www.ransomware.live/id/SG9va2UgTGFib3JhdG9yaWVzQHRoZWdlbnRsZW1lbg== · https://www.breachsense.com/breaches/hooke-laboratories-data-breach/ · Sources: [RedPacket Security] · [ransomware.live] · [Breachsense]
Jun 22
Royal Thai Navy Housing Cooperative
The Gentlemen
Ransomware · public sector · housing cooperative/Thailand
cooperative managing housing projects, financial services, and welfare programs for Royal Thai Navy personnel and their families; The Gentlemen DLS claim June 22, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.redpacketsecurity.com/thegentlemen-ransomware-victim-royal-thai-navy-housing-cooperative/ · https://www.ransomware.live/group/thegentlemen · Sources: [RedPacket Security] · [ransomware.live]
Jun 20
AmiGest
The Gentlemen
Ransomware · IT services · France
French IT integrator specialising in cloud, network, and managed services for SME clients; The Gentlemen ransomware DLS claim June 20, 2026; data scope and impact unconfirmed; attribution confirmed by DeXpose reporting · https://www.dexpose.io/theGentlemen-ransomware-attack-on-amigest/ · https://www.ransomware.live/group/thegentlemen · Sources: [DeXpose] · [ransomware.live]
Jun 15
Mahajak Development Co., Ltd.
The Gentlemen
Ransomware · technology distribution · Thailand
leading IT and technology distributor in Thailand; The Gentlemen DLS claim June 15, 2026; data scope and impact unconfirmed · https://www.dexpose.io/the-gentlemen-ransomware-targets-mahajak-development/ · https://www.ransomware.live/group/thegentlemen · Sources: [DeXpose] · [ransomware.live]
Jun 10
Mackay Sugar
The Gentlemen
Ransomware · agri-industrial · Australia
mills shut, harvest disrupted; ransomware confirmed (The Gentlemen attribution) · Sources: SecurityWeek / The Record
Jun 04
National Industries
The Gentlemen
Ransomware · automotive manufacturing · India
Indian precision-engineered automotive components manufacturer under the Metalman Group; supplies major two-wheeler OEMs; The Gentlemen DLS claim June 4, 2026; data scope and impact unconfirmed; 🟥 unverified — no victim statement · https://www.dexpose.io/thegentlemen-ransomware-attack-on-national-industries/ · https://www.ransomware.live/group/thegentlemen · Sources: [DeXpose] · [ransomware.live]
May 2026
May 06
Keretapi Tanah Melayu Berhad
The Gentlemen
Ransomware · transportation · railway/Malaysia
Malaysia's national railway company; The Gentlemen DLS claim May 6, 2026; 3,858 employees and 8,428 users exposed; 21 third-party employee credentials and 143 external attack surface vulnerabilities identified; estimated attack date May 3, 2026; rail operations unaffected · https://www.dexpose.io/the-gentlemen-ransomware-group-targets-keretapi-tanah-melayu-berhad/ · https://www.ransomware.live/id/S2VyZXRhcGkgVGFuYWhAdGhlZ2VudGxlbWVu · Sources: [DeXpose] · [ransomware.live]
← All threat actors · Full victim database →