Who Runs the Ransomware Group ‘The Gentlemen?’
A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim…
> CLASSIFIED_DOSSIER :: THREAT_ACTOR_PROFILE
/actor/thegentlemen-ransomware/ · 3 intel reports
TheGentlemen Ransomware is a relatively new ransomware operation that emerged in 2024, employing double-extortion tactics to pressure victims into paying ransom demands. The group encrypts victim files while simultaneously exfiltrating sensitive data, threatening to publish stolen records on their dedicated leak site if payment is not received within a set deadline.
The group has targeted small to medium-sized enterprises (SMEs) across multiple sectors including logistics, retail, and professional services. Their ransomware payload has been observed spreading through phishing campaigns and exploitation of unpatched Remote Desktop Protocol (RDP) vulnerabilities.
TheGentlemen operate their own Tor-based data leak site, where they publish victim names and sample data as leverage. Their ransom demands typically range from $10,000 to $500,000 USD, calibrated based on the estimated revenue of the victim organisation.
Despite their sophisticated extortion methodology, the group's technical malware development capabilities are assessed to be moderate, suggesting they may be leveraging Ransomware-as-a-Service (RaaS) infrastructure from established criminal marketplaces.
TheGentlemen (2025-) sells a RaaS panel and a BYOVD helper so affiliates can mute EDR before encryption. August 2026 leak-site cards named organisations in the United States, Saudi Arabia, and Poland. Those cards are claims until the victim or a national CERT agrees. Manufacturing and mid-market critical-services firms remain the default affiliate hunt because weekend OT coverage is thin.
Do not confuse TheGentlemen with LockBit remnants or Play. Different panel, different note, overlapping initial-access brokers. Hunt vulnerable drivers and unused VPN accounts first. Hunt brand drama second.
Affiliate notes recovered in public reporting emphasise speed after EDR is blinded: map file shares, stage a locker, then drop the leak timer. That sequence is why a manufacturing SOC that only watches the plant floor will miss the domain-wide encryption until Monday. If TheGentlemen appears on your leak site, assume VPN and a driver load first, then argue about the brand later.
A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim…
The ransomware collective operating under the designation TheGentlemen has purportedly listed Israeli energy solutions manufacturer Amicell – Amit…
The aggressive Ransomware-as-a-Service (RaaS) group known as TheGentlemen has claimed a new wave of global victims in August…