BreachCensus

thegentlemen

Also known as: Storm-2697First seen September 9, 2025Active816 claimed victims

The claims below are reproduced as posted by thegentlemen on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.

Listed organisation? Contact [email protected].

Profile

The Gentlemen is a RaaS group that emerged in July–August 2025, rapidly claiming over 320 victims across 17+ countries by offering affiliates a 90% revenue share, deploying a Go-based locker against Windows, Linux, NAS, and BSD systems; a compromised C2 server in 2026 revealed more than 1,570 linked victims.

Description from ransomware.live.

Claimed victims (as posted by the group — unverified)

Victim (as posted)Claimed onSourcePress coverage
DTI Foreign Trade Service CorpsFebruary 19, 2025ransomware_live
Hog SlatFebruary 19, 2025ransomware_live
DekoyapFebruary 19, 2025ransomware_live
Pos Bilişim TeknolojileriFebruary 19, 2025ransomware_live
Rogers CapitalFebruary 19, 2025ransomware_live
British School of BrasiliaFebruary 19, 2025ransomware_live
BIB Insurance BrokersFebruary 19, 2025ransomware_live
PaltrackFebruary 19, 2025ransomware_live
CPF Financial ServicesFebruary 19, 2025ransomware_live
AbatixFebruary 19, 2025ransomware_live
LawsoftFebruary 19, 2025ransomware_live
SeacFebruary 19, 2025ransomware_live
Universidade Federal de SergipeFebruary 19, 2025ransomware_live
PT Pupuk Iskandar MudaApril 3, 2024ransomware_live
Garuda Indonesia AirlinesJuly 9, 2023ransomware_live
LSA InternationalFebruary 28, 2023ransomware_live
← NewerPage 9 of 9

Claim data from ransomware.live and RansomLook (CC BY 4.0).