INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
ATTENTION: This report is based on previous data. New intelligence sources have been linked and the Executive Summary and Mitigations need to be re-synthesized.

The Gentlemen

| 2026-05-11 09:59 CRITICAL HIGH
Executive Summary AI-generated
The Gentlemen, a notorious ransomware-as-a-service (RaaS) group, has been linked to multiple high-profile attacks in recent months. Their tactics involve exploiting vulnerabilities in software companies from the UK and Turkey, using stolen data as leverage to extort victims into payingransom demands. The group's operators have also advertised their services on underground forums, recruiting other actors to join as affiliates. With over 332 published victims in just five months of 2026, The Gentlemen appears to be one of the most active RaaS programs in recent history.
Technical Mitigations AI-generated
* Implement a secure communication protocol: Use end-to-end encryption and secure communication channels to protect sensitive information exchanged between the RaaS administrator, affiliates, and victims. Consider using protocols like Signal or Wire for secure messaging. * Use robust password management: Implement strong password policies and use multi-factor authentication (MFA) whenever possible to prevent unauthorized access to backend databases and other sensitive systems. * Regularly update and patch infrastructure components: Ensure that the RaaS administrator's internal database, locker, and ransomware panel are regularly updated with the latest security patches and updates to prevent exploitation of known vulnerabilities. * Implement a secure data storage solution: Use encrypted or isolated storage solutions for sensitive information such as victim data, payment records, and other confidential details. Consider using cloud-based services like AWS S3 or Google Cloud Storage with encryption. * Monitor and respond to potential security threats: Establish incident response procedures to quickly identify and contain any potential security breaches or ransomware attacks on the RaaS administrator's systems or infrastructure components. These technical mitigations can help protect against various types of cyber threats, including ransomware attacks.
Technical Observables
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence distributed on:
Incident Link
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Operation CronosOperation Cronos EmbargoEmbargoContiContiSystemBCSystemBCQilinQilinBlack BastaBlack Basta CVE-2025-32433CVE-2025-32433 CVE-2025-33073CVE-2025-33073 CVE-2024-55591CVE-2024-55591 CVE-2025-61882CVE-2025-61882
Target & Sectors
ASEAN ASEAN NORTH_AMERICA NORTH_AMERICA FIVE_EYES FIVE_EYES DACH DACH healthcarehealthcare manufacturingmanufacturing legallegal
Incident Timeline
‎Q1 2023
Threat actors used LockBit to target victims of DLS (Dark Web Service) platforms.
‎Q1 2024
Threat actors used the Top-10 groups to target victims in Q1 2026.
general_metric 10 %
general_metric 71.1 %
general_metric 12.2 %
victims 2,416 victims
general_metric 117 %
victims 977 victims
general_metric 68 %
general_metric 57 %
‎early 2024
LockBit was the most dominant ransomware-as-a-service (RaaS) operation globally until its takedown in early 2024.
‎Q1 2025
Threat actors used Cl0p's Cleo mass-exploitation campaign to target approximately 1,894 victims in Q1 2025.
victims 1,894 victims
general_metric 5.3 %
organisation YoY
general_metric 7.1 %
victims 2,285 victims
victims 390 victims
‎Q3 2025
Threat actors used the Top-10 ransomware groups to target 30 South Korean organizations.
tactic Ransomware
financial 10 top ransomware groups
general_metric 71 %
general_metric 68 %
general_metric 57 %
target_region Korea, Republic of
malware Qilin
victims 30 Korean organizations
‎Q4 2025
LockBit 5.0 made a comeback in Q1 2026, posting 163 victims globally and climbing from outside the top 10 to fourth place after an increase of 106% compared to Q4 2025.
tactic Ransomware
general_metric 2026 Q1
victims 40 victims
general_metric 10 %
general_metric 106 %
general_metric 5.0 comeback
victims 163 victims
general_metric 29 unique campaigns
organisation DragonForce
victims 101 victims
victims 10 victims
data_breach 56 steep climb
target_region United States
general_metric 30 percentage point
general_metric 12.2 %
victims 2,416 victims
general_metric 117 %
victims 977 victims
general_metric 21 new names
‎July 2025
Threat actors used the cartel model to target Devman.
‎August 2025
Threat actors used pre-existing access stockpiles to target the United States.
target_region United States
‎September 2025
The ransomware group, The Gentlemen, used the TOX ID 98C132E2B20B531BE6604397D97040C1E9EB42FCE12EDF119BCE8B4031CA5C70DAF5E65FA3C3 to advertise and promote their RaaS program.
infrastructure 14,700 device
general_metric 5.0 comeback
organisation RAMP
organisation VirusTotal
victims 412 current public victims
‎Q1 2026
LockBit 5.0 posted 163 victims in Q1 2026, climbing from outside the top 10 to fourth place globally.
target_region United States
target_region Brazil
target_region Italy
general_metric 21.2 %
general_metric 8.6 %
general_metric 5.1 %
tactic Ransomware
general_metric 49.6 %
organisation The State of Ransomware
financial 10 top ransomware groups
general_metric 71 %
general_metric 2026 Q1
victims 40 victims
organisation LockBit
general_metric 5.0 comeback
victims 163 victims
organisation Conclusion In
victims 707 victims
victims 1,894 victims
general_metric 5.3 %
general_metric 10 %
general_metric 71.1 %
general_metric 50 %
malware Qilin
general_metric 2025 Q4
general_metric 315 %
general_metric 106 %
general_metric 29 unique campaigns
organisation DragonForce
victims 101 victims
victims 10 victims
data_breach 56 steep climb
organisation Oracle EBS
‎January 2026
The ransomware operator "Tramp", a former Conti and Black Basta affiliate, was added to Interpol's wanted list in January 2026.
tactic Ransomware
malware Black Basta
malware Conti
organisation Interpol
‎mid-March 2026
Threat actors used a compromised payment processing system to target the SafePay centralized, non-RaaS operation.
‎April 2026
The Gentlemen ransomware operation used a compromised consultancy from the United Kingdom to exfiltrate data and published it on their DLS.
target_region United Kingdom
organisation OAuth
infrastructure Linux
infrastructure Windows
organisation UNC
organisation Okta
organisation Program / Group
organisation Hello Kitty
organisation Kraken Mention
organisation PPs
organisation Neutral
organisation LockBit
victims 320 public victims
‎May 4th, 2026
The RaaS administrator of The Gentlemen used SystemBC to target victims and exploited vulnerabilities in Windows systems.
organisation Rocket
organisation Check Point Research
organisation TOX
organisation affiliates
infrastructure Windows
organisation NTDLL
organisation ETW
organisation Fortinet
organisation NTLM
organisation OWA
organisation CVE-2025
organisation Screenshots
organisation C&C
victims 1,570 victims
organisation NAS
‎May 5th, 2026
The Gentlemen RaaS operators used the FortiGate management interface to exploit CVE-2025-33073, a vulnerability that fits into their broader focus on high-value initial access points.
general_metric 10,000 USD
organisation LLM
infrastructure Linux
organisation TOR
organisation OSINT
organisation Cloudflare
organisation Zero Trust
organisation NetExec
organisation PrivHound
organisation Active Directory
organisation TaskHound
infrastructure Windows
organisation AV
organisation Erlang SSH
organisation CVE-2025-33073
infrastructure Fortigate
organisation Fortinet FortiGate
organisation FortiGate
organisation CVE
organisation BloodHound
organisation OSINT / Helper Tools
organisation The Gentlemen RaaS Data
organisation MediaFire
organisation LDW
organisation Roles & Structure
organisation EDR
organisation higher‑value
organisation GB RAM
data_breach 128 GB RAM
organisation OV
organisation Mamba
organisation Group
organisation BYOD
organisation Tools & Infra
organisation C2 / Remote Access
organisation C2 / Remote Access Velociraptor
organisation C2 / Remote Access Cloudflare Zero Trust
organisation HTTPS
organisation VPN / Network Access
organisation Automates WireGuard
organisation NXC
organisation SMB
organisation MSI
organisation EDR / AV Evasion EDRStartupHinder Blocks
organisation EDR / AV Evasion
organisation EDR / AV Evasion DumpBrowserSecrets Dumps
organisation EDR / AV Evasion zerosalarium
organisation GLOCKER
organisation Panel
organisation Emi
organisation high‑value
organisation SSH
organisation PoC
organisation Dell
organisation WPR
organisation AutoLogger
organisation Payments & Negotiations
organisation AML
organisation Anti-Money Laundering
organisation Zeta88
organisation Kunder
organisation скупов
organisation AML Checking They
organisation BTC
organisation KYC
data_breach 44.4 MB
data_breach 16.22 GB
‎2026/05/13
The Gentlemen, a Russian-speaking ransomware operation, targeted 82 US victims in February.
victims 338 victims
organisation Ransomware Attacks by Industry
infrastructure Linux
infrastructure Windows
data_breach 300 GB
organisation CVE-2024-55591
infrastructure Fortigate
organisation FortiGate
infrastructure 14,700 device
organisation FortiOS/FortiProxy
data_breach 969 validated forced VPN credentials
organisation Genesis
victims 29 confirmed victims
victims 79 victims
victims 8 victims
organisation Nightspire
organisation OneDrive
organisation Cl0p
organisation Anubis
organisation Hastalamuerte
organisation IR
victims 21 victims
victims 6 victims
victims 4 victims
victims 3 victims
victims 23 victims
victims 5 victims
organisation Devman
victims 82 victims
organisation EBS
infrastructure 53.5
infrastructure 18.6
organisation Business Services
organisation Obscura
data_breach 1 GB
organisation SafePay
victims 97 victims
organisation Sinobi
victims 139 victims
organisation Interpol’s Red Notice for Devman
organisation Nefedov
victims 10 victims
organisation ShinyHunters
organisation Per-Actor Geographic
organisation Country-Level Actor Dominance
organisation Consumer Goods
organisation Industrial Manufacturing
data_breach 41.7 combined %
data_breach 732 recorded victims
data_breach 684 recorded victims
victims 74 victims
victims 56 victims
victims 7 victims
victims 38 victims
victims 85 victims
victims 33 victims
‎just the first five months of 2026
Threat actors used the Data Leak platform to target approximately 332 victims in just five months of 2026.
tactic Data Leak
organisation DLS
victims 332 published victims
‎the first quarter of 2026
Threat actors used a data leak service to target 70 active sites that collectively listed new victims.
tactic Data Leak
organisation DLS
general_metric 70 active leak sites
victims 2,122 new victims
‎January to 35
DragonForce launched 101 attacks in Q1, with a rapid escalation from January to March.
general_metric 29 unique campaigns
organisation DragonForce
victims 101 victims
victims 10 victims
data_breach 56 steep climb
Tactical Metrics
Metrics
victims
8
Victims
Metrics
victims
29
Confirmed Victims
Metrics
infrastructure
‎Fortigate
Affected Product
Metrics
infrastructure
14,700
Device
Metrics
victims
21
Victims
Metrics
victims
6
Victims
Metrics
victims
4
Victims
Metrics
victims
3
Victims
Metrics
data_breach
42
Combined %
Metrics
financial
10
Top Ransomware Groups
Metrics
victims
338
Victims
Metrics
victims
40
Victims
Metrics
victims
163
Victims
Metrics
victims
2,122
New Victims
Metrics
data_breach
300
Gb
Metrics
data_breach
969
Validated Forced Vpn Credentials
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎Linux
Affected Product
Metrics
infrastructure
‎53.5
Software Version
Metrics
infrastructure
‎18.6
Software Version
Metrics
victims
2,416
Victims
Metrics
victims
977
Victims
Metrics
victims
707
Victims
Metrics
victims
2,285
Victims
Metrics
victims
390
Victims
Metrics
victims
1,894
Victims
Metrics
data_breach
1
Gb
Metrics
victims
97
Victims
Metrics
victims
82
Victims
Metrics
victims
139
Victims
Metrics
victims
101
Victims
Metrics
victims
10
Victims
Metrics
data_breach
56
Steep Climb
Metrics
victims
30
Korean Organizations
Metrics
data_breach
732
Recorded Victims
Metrics
data_breach
684
Recorded Victims
Metrics
victims
79
Victims
Metrics
victims
74
Victims
Metrics
victims
56
Victims
Metrics
victims
7
Victims
Metrics
victims
38
Victims
Metrics
victims
85
Victims
Metrics
victims
33
Victims
Metrics
victims
23
Victims
Metrics
victims
5
Victims
Metrics
victims
332
Published Victims
Metrics
victims
412
Current Public Victims
Metrics
victims
1,570
Victims
Metrics
data_breach
128
Gb Ram
Metrics
victims
320
Public Victims
Metrics
data_breach
44
Mb
Metrics
data_breach
16
Gb
Intelligence Sources
Zero Day Fans 2026-05-11
Zero Day Fans 2026-05-13
Zero Day Fans 2026-05-13
Zero Day Fans 2026-05-11