thegentlemen
Known ransomware group ACTIVE Active · high-tempo
The Gentlemen is a RaaS group that emerged in July–August 2025, rapidly claiming over 320 victims across 17+ countries by offering affiliates a 90% revenue share, deploying a Go-based locker against Windows, Linux, NAS, and BSD systems; a compromised C2 server in 2026 revealed more than 1,570 linked victims.
21
Total Claims
14
Critical
—
Records Claimed
7
Industries Hit
Active span: Apr 26, 2026 – Jun 8, 2026 · 21 organizations targeted
Active · high-tempo
Actor Threat Profile
Activity Timeline
Peak: May 2026 (11)Apr 2026
LessMore
Jun 2026Top Targeted Industries
Healthcare 9
Financial Services 4
Education 2
Consumer Services 2
Energy 1
Technology 1
Tradecraft & Infrastructure
34
Documented tools
12 / 56
MITRE tactics / techniques
1
Known leak sites
CredentialTheftDefenseEvasionDiscoveryEnumExfiltrationNetworkingOffsecRMM-Tools
Full intelligence profile on ransomware.live →
Targeted Organizations
Central Arkansas PediatricsThe ClinicWCM RemediumInstitucion CervantesSuburban WaterDownriver Medical AssociatesEdgewood Surgical HospitalMichigan Surgical CenterBrian Jessel BMWSanatorio DeltaLe Perreux sur MarneYMCA of ColumbiaInternal MedicineInternet Technologies DesignsUniversity of Finance and AdministrationRoss Yerger InsuranceAmstel SecuritiesShajarpak SecuritiesValue Exchange InternationalDermaPharmEEC Group
Claims by thegentlemen
Critical
Ransomware Claim: Central Arkansas Pediatrics
Central Arkansas Pediatrics
thegentlemen
Ransomware Healthcare
Jun 8, 2026 Critical
Ransomware Claim: The Clinic
The Clinic
thegentlemen
Ransomware Healthcare
Jun 8, 2026 Critical
Ransomware Claim: WCM Remedium
WCM Remedium
thegentlemen
Ransomware Healthcare
Jun 8, 2026 Low
Ransomware Claim: Institucion Cervantes
Institucion Cervantes
thegentlemen
Ransomware Education
Jun 8, 2026 Critical
Ransomware Claim: Suburban Water
Suburban Water
thegentlemen
Ransomware Energy
Jun 7, 2026 Critical
Ransomware Claim: Downriver Medical Associates
Downriver Medical Associates
thegentlemen
Ransomware Healthcare
Jun 4, 2026 Critical
500 GB leaked Ransomware Claim: Edgewood Surgical Hospital
Edgewood Surgical Hospital
thegentlemen
Ransomware Healthcare
Jun 4, 2026 Critical
Ransomware Claim: Michigan Surgical Center
Michigan Surgical Center
thegentlemen
Ransomware Healthcare
Jun 4, 2026 Low
Ransomware Claim: Brian Jessel BMW
Brian Jessel BMW
thegentlemen
Ransomware Consumer Services
Jun 4, 2026 Critical
Ransomware Claim: Sanatorio Delta
Sanatorio Delta
thegentlemen
Ransomware Healthcare
May 24, 2026 Low
Ransomware Claim: Le Perreux sur Marne
Le Perreux sur Marne
thegentlemen
Ransomware
May 24, 2026 Low
Ransomware Claim: YMCA of Columbia
YMCA of Columbia
thegentlemen
Ransomware Consumer Services
May 21, 2026 Critical
Ransomware Claim: Internal Medicine
Internal Medicine
thegentlemen
Ransomware Healthcare
May 19, 2026 Low
Ransomware Claim: Internet Technologies Designs
Internet Technologies Designs
thegentlemen
Ransomware Technology
May 19, 2026 Low
Ransomware Claim: University of Finance and Administration
University of Finance and Administration
thegentlemen
Ransomware Education
May 19, 2026 Critical
Ransomware Claim: Ross Yerger Insurance
Ross Yerger Insurance
thegentlemen
Ransomware Financial Services
May 17, 2026 Critical
Ransomware Claim: Amstel Securities
Amstel Securities
thegentlemen
Ransomware Financial Services
May 13, 2026 Critical
Ransomware Claim: Shajarpak Securities
Shajarpak Securities
thegentlemen
Ransomware Financial Services
May 13, 2026 Critical
Ransomware Claim: Value Exchange International
Value Exchange International
thegentlemen
Ransomware Financial Services
May 13, 2026 Critical
Ransomware Claim: DermaPharm
DermaPharm
thegentlemen
Ransomware Healthcare
May 10, 2026 High
Ransomware Claim: EEC Group
EEC Group
thegentlemen
Ransomware Business Services
Apr 27, 2026