TH

thegentlemen

Known ransomware group ACTIVE
Active · high-tempo

The Gentlemen is a RaaS group that emerged in July–August 2025, rapidly claiming over 320 victims across 17+ countries by offering affiliates a 90% revenue share, deploying a Go-based locker against Windows, Linux, NAS, and BSD systems; a compromised C2 server in 2026 revealed more than 1,570 linked victims.

21

Total Claims

14

Critical

Records Claimed

7

Industries Hit

Active span: Apr 26, 2026 – Jun 8, 2026 · 21 organizations targeted

Active · high-tempo
Activity 8.4 Severity 7.7 Sectors 6.9 Tooling 10.0

Actor Threat Profile

Activity Timeline

Peak: May 2026 (11)
Apr 2026
LessMore
Jun 2026

Share this profile

Shareable intel card for thegentlemen

Top Targeted Industries

Healthcare 9
Financial Services 4
Education 2
Consumer Services 2
Energy 1
Technology 1

Tradecraft & Infrastructure

34

Documented tools

12 / 56

MITRE tactics / techniques

1

Known leak sites

CredentialTheftDefenseEvasionDiscoveryEnumExfiltrationNetworkingOffsecRMM-Tools
Full intelligence profile on ransomware.live →

Claims by thegentlemen

Critical

Ransomware Claim: Central Arkansas Pediatrics

Central Arkansas Pediatrics
thegentlemen
Ransomware Healthcare
Jun 8, 2026
Critical

Ransomware Claim: The Clinic

The Clinic
thegentlemen
Ransomware Healthcare
Jun 8, 2026
Critical

Ransomware Claim: WCM Remedium

WCM Remedium
thegentlemen
Ransomware Healthcare
Jun 8, 2026
Low

Ransomware Claim: Institucion Cervantes

Institucion Cervantes
thegentlemen
Ransomware Education
Jun 8, 2026
Critical

Ransomware Claim: Suburban Water

Suburban Water
thegentlemen
Ransomware Energy
Jun 7, 2026
Critical

Ransomware Claim: Downriver Medical Associates

Downriver Medical Associates
thegentlemen
Ransomware Healthcare
Jun 4, 2026
Critical
500 GB leaked

Ransomware Claim: Edgewood Surgical Hospital

Edgewood Surgical Hospital
thegentlemen
Ransomware Healthcare
Jun 4, 2026
Critical

Ransomware Claim: Michigan Surgical Center

Michigan Surgical Center
thegentlemen
Ransomware Healthcare
Jun 4, 2026
Low

Ransomware Claim: Brian Jessel BMW

Brian Jessel BMW
thegentlemen
Ransomware Consumer Services
Jun 4, 2026
Critical

Ransomware Claim: Sanatorio Delta

Sanatorio Delta
thegentlemen
Ransomware Healthcare
May 24, 2026
Low

Ransomware Claim: Le Perreux sur Marne

Le Perreux sur Marne
thegentlemen
Ransomware
May 24, 2026
Low

Ransomware Claim: YMCA of Columbia

YMCA of Columbia
thegentlemen
Ransomware Consumer Services
May 21, 2026
Critical

Ransomware Claim: Internal Medicine

Internal Medicine
thegentlemen
Ransomware Healthcare
May 19, 2026
Low

Ransomware Claim: Internet Technologies Designs

Internet Technologies Designs
thegentlemen
Ransomware Technology
May 19, 2026
Low

Ransomware Claim: University of Finance and Administration

University of Finance and Administration
thegentlemen
Ransomware Education
May 19, 2026
Critical

Ransomware Claim: Ross Yerger Insurance

Ross Yerger Insurance
thegentlemen
Ransomware Financial Services
May 17, 2026
Critical

Ransomware Claim: Amstel Securities

Amstel Securities
thegentlemen
Ransomware Financial Services
May 13, 2026
Critical

Ransomware Claim: Shajarpak Securities

Shajarpak Securities
thegentlemen
Ransomware Financial Services
May 13, 2026
Critical

Ransomware Claim: Value Exchange International

Value Exchange International
thegentlemen
Ransomware Financial Services
May 13, 2026
Critical

Ransomware Claim: DermaPharm

DermaPharm
thegentlemen
Ransomware Healthcare
May 10, 2026
High

Ransomware Claim: EEC Group

EEC Group
thegentlemen
Ransomware Business Services
Apr 27, 2026

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.