The Gentlemen, a financially motivated, Russian-speaking ransomware-as-a-service operation, has become one of the world’s two most active ransomware groups after splitting from Qilin’s affiliate programme in July 2025. Comparitech reported 600 claimed attacks between January and July 2026, second to Qilin’s 771, but only 68 were confirmed by targeted organizations; confirmed incidents involved approximately 787,400 breached records. Belgium’s Centre for Cybersecurity reported 269 victims in Q2 2026, including at least six confirmed Belgian victims, and impacts on critical infrastructure elsewhere in the EU. The operation reportedly emerged from Qilin affiliate ArmCorp following a payment dispute, offers affiliates 90% of ransom proceeds, and announced a BreachForums partnership. Manufacturers represented roughly 24% of claimed victims, with healthcare, government and education also targeted.
The group supports affiliates with encryption and self-propagation capabilities, an operator-maintained endpoint detection and response (EDR) killer service, and a shared pool of compromised FortiGate devices and validated VPN credentials. Observed intrusions exploit known vulnerabilities using public proof-of-concept exploits; no zero-day capability has been identified. Comparitech linked rising activity to recruitment and rumored exploitation of CVE-2025-32433 and CVE-2025-33073, but did not establish exploitation of either vulnerability. Belgian authorities assess with moderate confidence that the operation is independently based in Russia or a Russian-speaking CIS jurisdiction, with no evidence of direct Russian state tasking or control. Defenders should prioritize patching internet-facing systems, reviewing VPN access and credentials, and hardening endpoint defenses against tampering.

TTPs, infrastructure, and targeting history in one profile.
51 events from the most recent confirmed update back to the earliest known activity.
Ecopetrol S.A. experienced an attack in July 2026. It reported that 3,300 user accounts could have been affected.
Italy’s HIWIN S.r.l. experienced a July 2026 attack identified among The Gentlemen’s confirmed manufacturing incidents.
Portugal’s Metro Mondego experienced a July 2026 incident included among confirmed government-sector attacks attributed to The Gentlemen.
The Kenaitze Indian Tribe in the United States experienced a July 2026 attack included among confirmed government-sector incidents attributed to The Gentlemen.
U.S. healthcare organization AnMed experienced a confirmed attack in July 2026. The Gentlemen subsequently claimed the incident in August.
U.S. manufacturer TKMS ATLAS North America, LLC experienced a June 2026 attack identified among The Gentlemen’s confirmed incidents.
An Indra Group subsidiary in Spain experienced a June 2026 attack identified among The Gentlemen’s confirmed manufacturing incidents.
Poland’s Akademia Leona Koźmińskiego–Kozminski University experienced a confirmed June 2026 attack included among The Gentlemen’s education-sector incidents.
Germany’s Feuerwehr Allensbach experienced a June 2026 incident included among confirmed government-sector attacks attributed to The Gentlemen.
Denmark’s Nationalmuseet experienced a June 2026 incident included among confirmed government-sector attacks attributed to The Gentlemen.
Croatia’s Ministry of Health experienced a June 2026 incident included among confirmed government-sector attacks attributed to The Gentlemen.
U.S. healthcare organization Hooke Laboratories experienced a June 2026 incident included among The Gentlemen’s confirmed attacks.
The Gentlemen briefly overtook Qilin for the highest single-month reported victim count in June 2026.
India’s IP Rings Limited experienced a May 2026 attack identified among The Gentlemen’s confirmed manufacturing incidents.
Japan’s Koa Glass Co., Ltd. experienced a May 2026 attack identified among The Gentlemen’s confirmed manufacturing incidents.
Japan’s Oriental Diamond Co., Ltd. experienced a May 2026 attack identified among The Gentlemen’s confirmed manufacturing incidents.
Vysoká škola finanční a správní in the Czech Republic experienced a confirmed May 2026 attack included among The Gentlemen’s education-sector incidents.
Boyne City in the United States experienced a May 2026 attack included among confirmed government-sector incidents attributed to The Gentlemen.
Poland’s Wielkopolskie Centrum Medyczne REMEDIUM sp. z o.o. confirmed a late-May 2026 systems breach affecting a broad group of patients.
Soniva Dental Care’s remote desktop web services infrastructure was attacked in May 2026. Approximately 30,000 Texas residents were potentially affected because access to patient data could not be ruled out.
A May 2026 leak of The Gentlemen’s backend infrastructure exposed roughly nine named operators. It also revealed a 90/10 revenue split, relationships with initial access brokers, and a documented chain-victimisation technique.
The Gentlemen announced a partnership with BreachForums in May 2026. It sought teams, individual penetration testers, and access brokers to expand its affiliate program worldwide.
Hospital Caribbean Medical Center began breach notifications in April 2026 following its February attack. The hospital notified 92,000 people.
U.S. manufacturer Gator Cases, LLC experienced an April 2026 attack and subsequently notified 1,171 people.
Turkey’s Arçelik A.Ş. experienced an April 2026 attack identified among The Gentlemen’s confirmed manufacturing incidents.
Taiwan’s Gem Terminal Industry Co., Ltd. experienced an April 2026 attack identified among The Gentlemen’s confirmed manufacturing incidents.
Germany’s Heinrich Kopp GmbH experienced an April 2026 attack identified among The Gentlemen’s confirmed manufacturing incidents.
Anderlues la Commune in Belgium experienced an April 2026 attack included among The Gentlemen’s confirmed government incidents. Its systems were paralyzed for nearly a month.
IntraCare resumed medical procedures on March 30, 2026, following the attack that began ten days earlier.
New Zealand’s IntraCare experienced an attack beginning March 20, 2026. The incident was included among The Gentlemen’s confirmed healthcare attacks.
JRK Property Holdings, Inc. detected suspicious activity in March 2026 and subsequently notified 19,919 people across seven U.S. states. The report stated that the total number affected remained unknown.
Japan’s MEDICUS SHUPPAN, Publishers Co., Ltd. experienced a March 2026 attack. It subsequently reported 641,000 affected personal-data entries, which could include duplicate entries for individuals.
Japan’s Omikenshi Co., Ltd. experienced a March 2026 attack identified among The Gentlemen’s confirmed manufacturing incidents.
Panama’s Caja de Seguro Social experienced a March 2026 attack included among confirmed government-sector incidents attributed to The Gentlemen.
Náměšť nad Oslavou in the Czech Republic experienced a March 2026 attack included among confirmed government-sector incidents attributed to The Gentlemen.
India’s Rajagiri Hospital confirmed that its March 2026 attack began with phishing and resulted in 800 GB of stolen data.
Thailand’s Sasin School of Management experienced a February 2026 attack. It reported no evidence that critical data systems were compromised.
Austria’s CHS Villach experienced a February 2026 attack and confirmed a data breach.
Brazil’s Universidade Federal de Sergipe experienced a confirmed February 2026 attack included in Comparitech’s account of The Gentlemen’s education-sector incidents.
Brazil’s Centro Universitário Filadélfia experienced a confirmed February 2026 attack included in Comparitech’s account of The Gentlemen’s education-sector incidents.
Chile’s Instituto Nacional de Derechos Humanos experienced a February 2026 attack included among confirmed government-sector incidents attributed to The Gentlemen.
Hospital Caribbean Medical Center in Puerto Rico contained an attack in early February 2026. The incident was included among The Gentlemen’s confirmed healthcare attacks.
Brazil’s Unimed Anápolis confirmed an attack on January 12, 2026, but reported no evidence of a data leak.
Poland’s Wamtechnik sp. z o.o. experienced a January 2026 attack identified among The Gentlemen’s confirmed manufacturing incidents.
HAFA in France experienced a January 2026 attack identified among The Gentlemen’s confirmed manufacturing incidents.
Japan’s Nishiyama Seisakusho Co., Ltd. experienced a January 2026 attack identified among The Gentlemen’s confirmed manufacturing incidents.
Beniel in Spain experienced a January 2026 attack included among confirmed government-sector incidents attributed to The Gentlemen.
South Africa’s Witzenberg Municipality experienced a January 2026 attack included among confirmed government-sector incidents attributed to The Gentlemen.
The ransomware operation began adding victims to its leak site in September 2025.
The Gentlemen separated from Qilin’s affiliate program in July 2025. Experts cited by Comparitech attributed its formation to Qilin affiliate ArmCorp breaking away following a payment dispute.
Reporting arising from the leak of The Gentlemen’s internal Rocket.Chat infrastructure linked LARVA-368 to Alexander Andreevich Yapaev of Izhevsk, Russia.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
ccb.belgium.be
Open sourcecomparitech.com
Open sourceblog.barracuda.com
Open sourcehalcyon.ai
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.