CARDS
CARDS
The Gentlemen combines affiliate-driven ransomware with self-service access to pre-compromised FortiGate infrastructure and purchased credentials. Its operations target Windows, Linux, and ESXi systems and include data theft, encryption, security-control evasion, and downstream client compromise.
Last updated Jul 17, 2026, 12:00 PM EDT
Evidence Boundary
Bottom Line Up Front
The Gentlemen combines affiliate-driven ransomware with self-service access to pre-compromised FortiGate infrastructure and purchased credentials. Its operations target Windows, Linux, and ESXi systems and include data theft, encryption, security-control evasion, and downstream client compromise.[1][2]
Cross-platform encryption, stolen-data exposure, and reuse of compromised provider information can create simultaneous business interruption, breach-response, and downstream third-party risk.[1][2]
Patch and isolate edge appliances, investigate FortiGate and VPN authentication, rotate exposed credentials, protect ESXi and immutable backups, and review service-provider access for downstream exposure.[1][2]
Decision Summary
The Gentlemen combines affiliate-driven ransomware with self-service access to pre-compromised FortiGate infrastructure and purchased credentials. Its operations target Windows, Linux, and ESXi systems and include data theft, encryption, security-control evasion, and downstream client compromise.
The retained record scopes this as raas affiliate operations / initial-access brokerage / double extortion activity during 2025-08-01 to 2026-07-09. Cross-platform encryption, stolen-data exposure, and reuse of compromised provider information can create simultaneous business interruption, breach-response, and downstream third-party risk.[1][2]
Patch and isolate edge appliances, investigate FortiGate and VPN authentication, rotate exposed credentials, protect ESXi and immutable backups, and review service-provider access for downstream exposure.[1][2]
Confirmed reporting is separated from attribution, victim, and prevalence claims that the retained sources do not establish. Confidence: High for the Check Point-reported operating model; leak-site volumes remain source-bounded actor claims..[1][2]
Actor Mapping
Targeting
Tradecraft
Tools / Observables
Source Reconciliation
Campaign rows are retained as source-backed context. Actor mappings do not automatically merge actor records; SOCRadar, MITRE, Mandiant, CrowdStrike, Microsoft, and other future sources can disagree on boundaries, aliases, or campaign ownership.
Do not treat shame-site victim counts as confirmed incident totals or infer that every affiliate uses the same access path.
Evidence Controls
IntelliOS
None Found
Citations