Mandurah SES Ransomware Claim by thegentlemen (Oct 2026)
Unverified dark web claim. This report is based on a post observed on a dark web forum. Yazoul Security has not independently verified the authenticity of this claim.
Claim Summary
The ransomware group known as “thegentlemen” has allegedly listed Mandurah State Emergency Service (mandurahses.org.au) on its dark web leak site. According to the threat actor, the claimed attack date is October 2, 2026. The group has purportedly posted an entry describing the victim as a volunteer emergency rescue unit operating under the Department of Fire and Emergency Services (DFES) in Western Australia.
Notably, the listing does not disclose a data volume. This is an important detail. Many ransomware groups lead with a headline figure to maximize pressure. The absence of any stated volume means there is currently no way to gauge the alleged scope of any exposure, and no evidence has been provided publicly to substantiate the claim.
Yazoul Security has not independently verified this claim. It remains unconfirmed.
Threat Actor Profile
The group tracked as thegentlemen is a relatively low-profile ransomware operation. Public research on this actor is limited, and its total number of known victims is unknown. No established toolset has been publicly attributed to the group at this time.
Because of this thin track record, the group’s credibility should be treated with caution. Ransomware operations frequently exaggerate the sensitivity or scale of stolen data to pressure victims into paying. Some actors also list victims based on minimal or opportunistic access rather than deep intrusion. Without corroborating evidence, the claim should be viewed as unproven.
No YARA rules or detection signatures specific to this group are publicly available at the time of writing. Organizations should rely on general ransomware detection guidance, including monitoring for unusual data staging, mass file access, and anomalous outbound transfers.
Alleged Data Exposure
According to the threat actor’s listing, the claimed target is a non-profit volunteer unit founded in the late 1970s and celebrating its 50th anniversary in 2026. The listing purportedly references operational details such as volunteer counts, cadet program information, and annual operational hours.
The group has not published any data samples, download links, or proof-of-compromise artifacts that Yazoul Security can assess. No personal information, credentials, or file listings are included in this report by design. The alleged data volume remains undisclosed.
It is worth noting that the listing’s descriptive text reads more like open-source background material than stolen internal records. This is a common pattern in low-confidence claims and warrants skepticism.
Potential Impact
If the claim were substantiated, potential impacts could include disruption to volunteer coordination, exposure of internal communications, and reputational harm to a community-focused emergency service. Emergency response organizations may also face heightened scrutiny given the sensitive nature of their operations.
However, because the claim is unverified and no data volume has been stated, the practical impact remains speculative. There is currently no public evidence that operational response capabilities have been affected.
What to Watch For
- Any publication of data samples or proof-of-compromise artifacts by the group.
- Official statements from DFES Western Australia or Mandurah SES.
- Corroborating reports from incident response firms or government agencies.
- Changes to the leak site entry, including added data volume or deadlines.
- Whether the group escalates, remains silent, or removes the listing.
Disclaimer
This report is based solely on an unverified claim posted to a ransomware group’s leak site. Yazoul Security has not independently confirmed the attack, the data exposure, or any details described by the threat actor. All statements attributed to the group are allegations. Ransomware actors routinely exaggerate or fabricate claims. Readers should treat this information as unconfirmed and monitor official channels for verified updates.
Never miss a threat intelligence alert
Get real-time security alerts delivered to your preferred platform.
Related Claims
Westrop Primary & Nursery School — thegentlemen
VUS - The English Center — thegentlemen
Aforpa — thegentlemen
Air Canada — thegentlemen