« All threats

Ransomware group

The Gentlemen

Profile

The Gentlemen is a ransomware group that has been operating since July 2025 under a ransomware-as-a-service (RaaS) model, meaning it develops the encryptor and extortion infrastructure and leases them to affiliates who carry out the intrusions. Its standard approach is double extortion: encrypting the victim's systems while also stealing data to publish on its leak site if no ransom is paid. Its activity grew quickly during 2026, with leak-site listings rising from 48 in January to 105 in July. According to Cisco Talos, it was the most active ransomware group in Japan in the first half of 2026, with 14 confirmed incidents, and it has also been linked to attacks in Taiwan, the United States and the Philippines. The most affected sectors are manufacturing, technology and professional services.

Active since: 2025-07

What defenders should watch

Victims in the last 90 days408

Most affected countries

  1. United States105
  2. India16
  3. Italy16
  4. France13
  5. Germany10
  6. Taiwan10
  7. Chile9
  8. United Kingdom9

Most affected sectors

  1. Manufacturing64
  2. Other47
  3. Technology39
  4. Retail33
  5. Construction30
  6. Professional services29
  7. Healthcare21
  8. Agriculture & food17

Recent victims

OrganisationCountrySectorClaimedStatus
Zelham, Inc.United StatesConstruction9/30/2026◌ Claimed (unverified)
Wooshin Safety Systems Co LtdSouth KoreaManufacturing9/30/2026◌ Claimed (unverified)
Wooshin Systems Co LtdSouth KoreaManufacturing9/30/2026◌ Claimed (unverified)
Aware IncUnited StatesTechnology9/30/2026◌ Claimed (unverified)
Corswarem GroupBelgiumManufacturing9/29/2026◌ Claimed (unverified)
Pulmonary Services GroupPuerto RicoHealthcare9/29/2026◌ Claimed (unverified)
Guy José Bendaña-Guerrero & AsociadosNicaraguaLegal9/29/2026◌ Claimed (unverified)
Don HierroPanamaConstruction9/29/2026◌ Claimed (unverified)
Tommy Garner Air Conditioning & HeatingUnited StatesConstruction9/29/2026◌ Claimed (unverified)
Auto HöllerAustriaAutomotive9/29/2026◌ Claimed (unverified)
VUS - The English CenterVietnamEducation9/29/2026◌ Claimed (unverified)
Northern New Jersey Eye InstituteUnited StatesHealthcare9/29/2026◌ Claimed (unverified)
Williamson Dacar AssociatesUnited StatesConstruction9/29/2026◌ Claimed (unverified)
AGOSPAPFranceNon-profit9/29/2026◌ Claimed (unverified)
DBU ConstructionUnited StatesConstruction9/29/2026◌ Claimed (unverified)
Topsport Italia / Quality Sport ItaliaItalyRetail9/29/2026◌ Claimed (unverified)
EuroprimFranceProfessional services9/29/2026◌ Claimed (unverified)
Telrad NetworksIsraelTelecommunications9/29/2026◌ Claimed (unverified)
Groupe APROSEPFrench GuianaNon-profit9/29/2026◌ Claimed (unverified)
Drinks Wines SpiritsTaiwanRetail9/29/2026◌ Claimed (unverified)
Custom Rx ShoppeUnited StatesHealthcare9/29/2026◌ Claimed (unverified)
AURENSpainProfessional services9/29/2026◌ Claimed (unverified)
Datacomm ServicesUnited StatesConstruction9/29/2026◌ Claimed (unverified)
Webb Electric Company of FloridaUnited StatesConstruction9/29/2026◌ Claimed (unverified)
SolariaIndonesiaHospitality & tourism9/29/2026◌ Claimed (unverified)

Sources analysed

Claims are published by the criminal groups themselves and are unverified until the organisation or the press confirms them. Names of natural persons (sole traders, individual professionals) are anonymised under the GDPR. We never link to leak sites or stolen data. To request the removal or anonymisation of an entry, contact the site administrator.

Sources: RansomLook (CC BY 4.0), MITRE ATT&CK®, MISP Galaxy, GDELT.