The Gentlemen
The Gentlemen (also styled "TheGentlemen"; tracked as Storm-2697 by Microsoft Threat Intelligence) is a ransomware-as-a-service (RaaS) group first observed in September 2025. Still relatively new, it has become the second-most-active ransomware group of 2026 by claimed victim volume. Its defining feature is not novel malware but a 90/10 affiliate revenue split (vs the 80/20 market standard) that bought scale by attracting experienced operators from rival programmes. (Security Reports/2025/NCCGroup-Cyber-Threat-Intelligence-Report-2025.md) (Security Reports/2026/Guidepoint-Ransomware-Annual_Report-2026.md)
Emergence and TTPs
- First observed: Microsoft records the group as emerging around mid-2025, initially closed, opening its RaaS to affiliates around September 2025.
- By the end of October 2025, the group had made 21 public ransomware attack claims across Asia, South America, Europe and Africa. (Security Reports/2025/NCCGroup-Cyber-Threat-Intelligence-Report-2025.md)
- Trend Micro highlighted The Gentlemen for its advanced, tailored attacks on enterprise systems. (Trend Micro, "Unmasking the Gentlemen Ransomware", 2025)(https://www.trendmicro.com/en_us/research/25/i/unmasking-the-gentlemen-ransomware.html)
- Operates a Data Leak Site (DLS) with countdown timers and publication threats β consistent with double-extortion ransomware activity. (Security Reports/2025/NCCGroup-Cyber-Threat-Intelligence-Report-2025.md)
- Claimed sectors include healthcare, financial services, IT, consumer discretionary, manufacturing and food. The group does not observe the informal "no hospitals" or "no critical infrastructure" conventions some operators claim.
- Encryptor and propagation (Microsoft, 28 May 2026): written in Go (obfuscated with Garble), per-file ephemeral Curve25519 keys with XChaCha20, and a self-propagation engine attempting 21 remote-execution operations per target host (PsExec, SMB share, WMI, scheduled task, service, WinRM) after a defence-evasion PowerShell blob.
Scale and escalation
- By the end of October 2025, 21 public victim claims. (Security Reports/2025/NCCGroup-Cyber-Threat-Intelligence-Report-2025.md)
- 483+ public victims across ~66 countries by 13 Jun 2026 (Security Affairs; researcher Gregory Devans), with 580 victims across 77 countries by 7 Jul 2026 (Unit 42 tracking). These are self-claimed leak-site figures, not independently verified.
- A single affiliate's C2 infrastructure was linked by Check Point Research to 1,570+ probable corporate victims β well above the public leak-site tally, meaning public claims understate the operation's reach.
- CYFIRMA reporting lists The Gentlemen as one of the top ransomware groups active in South-East Asia (22 incidents in the collated dataset), behind the regionally dominant Qilin. (Philippines Threat Assessment/COLLATED_INTELLIGENCE.md)
The May 2026 backend leak β "when the gang got hacked"
- On 4 May 2026 the operator acknowledged the group's internal backend database had been compromised and leaked, likely tied to the breach of its hosting provider, 4VPS.
- Check Point Research obtained a portion: internal chat logs, affiliate rosters, ransom negotiation transcripts and tooling discussions β a rare attacker-side window.
- The leak revealed the group is run by roughly nine named operators around a single administrator, and underpinned the June 2026 named attribution.
Attribution
- Microsoft Threat Intelligence tracks the operator group as Storm-2697, "a financially motivated threat actor that manages the RaaS platform while affiliates carry out attacks".
- A 10 June 2026 Krebs on Security investigation (corroborated by Check Point, Intel 471, PRODAFT, Constella Intelligence) linked the leading operator persona (Hastalamuerte / SantaMuerte / Zeta88) to Alexander Andreevich Yapaev, a 36-year-old Izhevsk, Russia. This is an identification based on correlation, not a conviction.
- The administrator is described as a former affiliate of the Qilin ransomware programme, learning the trade under an established operation before building a rival.
Confidence in claims: legitimate data, not recycling
NCC Group's review of The Gentlemen's public claims found no overlap with other groups' claims between 2021 and 2025 β a differentiator from high-volume groups assessed to rely on recycled breach data. NCC assessed the claim against 2GO (a large Philippines-based logistics company) as likely genuine. The group appears to generate fresh breach data rather than relabelling older compromises. (Security Reports/2025/NCCGroup-Cyber-Threat-Intelligence-Report-2025.md)
Notable incidents
AnMed (US healthcare) β August 2026
The Gentlemen claimed responsibility in the August 2026 disruption of AnMed, a nonprofit health system serving South Carolina and Georgia. The group hijacked AnMed's Facebook page, posting ransom demands claiming exfiltration of records including sexual assault, mental health, abortion and sexual harassment β claims for which no evidence had been provided. The incident stems from the disruption AnMed disclosed on 26 July 2026. See Anmed Closes Almost 80 Facilities Amid Cyberattack.
Philippine Savings Bank (PSBank) β 2 August 2026
A ThreatMon alert (Undercode News) claimed The Gentlemen added Philippine Savings Bank to its victim list. Low-confidence, unconfirmed lead β no independent evidence. Do not report as a confirmed breach. (Philippines Threat Assessment/RESEARCH_UPDATE_2026-08-03.md)
Chain-victimisation β April 2026 (UK β Turkey)
In April 2026 the group breached a UK software consultancy, then used data stolen from it to attack a client in Turkey, publishing both and citing the UK firm as its "access broker".
Australian angle
Australia is a demonstrated, repeated target β Check Point ranks Australia as the group's fourth-most-targeted nation. Confirmed Australian victims:
- Einstein Technology Pty Ltd (IT services) β claim 12 March 2026. Sources: DeXpose, SOCRadar.
- Mackay Sugar (North Queensland sugar producer) β claimed 10 June 2026 cyber attack that shutdown Farleigh and Racecourse mills at crushing-season start; Cyber Daily exclusive corroborated by SecurityWeek/ABC; company confirmed a dark-web claim but not the specific group (ModerateβHigh). See the full incident analysis in Security Reports/2026/Mackay-Sugar-Cyber-Attack-Analysis-2026.
- Royal Foods Pty Ltd (food distribution) β claim 11 July 2026; confirmed by Cyber Daily and Echo Newspaper.
The heavy food/agri representation (two of three) matches the group's global dominance of manufacturing/industrial targets. Australian food, agriculture and managed-service providers holding harvest, grower or client data are squarely in scope. Full analysis: Security Reports/2026/The-Gentlemen-Ransomware-Intelligence-Assessment-2026. Au Impact
Related Pages
- Anmed Closes Almost 80 Facilities Amid Cyberattack β AnMed healthcare disruption attributed in-part to The Gentlemen
- Scattered Spider β Prolific cybercrime group; comparison point
- Mitre Attack β TTP framework for mapping The Gentlemen's activity
Mackay Sugar AU attack analysis: Security Reports/2026/Mackay-Sugar-Cyber-Attack-Analysis-2026.