CARDS
CARDS
Thegentlemen is a financially motivated ransomware group that emerged in early June 2026, engaging in double extortion by encrypting victim networks and exfiltrating sensitive data. The group is characterized by its aggressive and non-negotiating tactics, as observed in specific incidents where threats were made instead of engaging in ransom negotiations. Their operations span diverse global industries, demonstrating a broad targeting approach.
This profile is generated from the same canonical actor-card record used by the Threat Actor Cards directory, so aliases, targeting fields, activity notes, and source links stay aligned as the database is enriched.
Actor Card Detail
Identity
Aliases1
Source Boundary
SOCRadar is the retained baseline for this profile. IntelliOS preserves source labels as discovery and comparison signals until a cited source explicitly supports a merge, split, or actor-boundary change.
Targeting
Associated Activity1
ATT&CK IDs1
Campaign Context
| Campaign / Operation | Source-Backed Context |
|---|---|
| The Gentlemen RaaS Operations3,4 | The Gentlemen RaaS Operations is retained in the campaign database for The Gentlemen. The Gentlemen combines affiliate-driven ransomware with access to pre-compromised FortiGate infrastructure and purchased credentials, targeting Windows, Linux, and ESXi while stealing data and impairing defenses. |
Indicators
216 IOCs are reported by SOCRadar, but the underlying observable values are not yet retained in IntelliOS. The profile therefore cites the source count without republishing unstored IOC values.
Source coverage: 1 source group tracked; 0 currently contribute retained observable or context rows.
Retained Public Observables1,2
216 IOCs are reported by SOCRadar, but the underlying observable values are not yet retained in IntelliOS. The profile therefore cites the source count without republishing unstored IOC values.
| Source | Reported | Retained | Coverage Status |
|---|---|---|---|
| SOCRadar2 | 216 | 0 | Reported IOC count retained; underlying SOCRadar feed values are not republished unless stored as cited public observables. |
IntelliOS Intel Products
None Found
Source Reconciliation
| Source | Primary Name | Treatment | Boundary |
|---|---|---|---|
| SOCRadar | Thegentlemen | Baseline actor-card record retained for the current profile view. | Fields reflect the retained database record. Additional source consensus, collisions, and canonical identity mappings can be layered into this profile without automatically merging actors. |
| IntelliOS | Thegentlemen | Normalizes this record for directory search, card display, profile lookup, and future product linking. | Normalization is a presentation and workflow aid; it is not an independent attribution claim. |
Citations
| # | Source | Use In Card |
|---|---|---|
| 1 | SOCRadar Threat Actor Database https://socradar.io/free-tools/threat-actor/ransomware | Baseline actor-card corpus source for retained profile fields. |
| 2 | SOCRadar Actor Profile https://socradar.io/free-tools/ransomware-intelligence/groups/thegentlemen | Per-actor SOCRadar profile source for ransomware profile metadata and IOC count when available. |
| 3 | Check Point: The Gentlemen internal leak analysis https://blog.checkpoint.com/research/when-the-ransomware-gang-gets-hacked-what-the-gentlemen-leak-reveals-about-modern-ransomware-risk/ | Check Point Research campaign row source for The Gentlemen RaaS Operations. |
| 4 | Check Point: June 2026 ransomware landscape https://blog.checkpoint.com/research/a-new-ransomware-leader-emerges-as-june-2026-attack-volumes-climb-worldwide/ | Check Point Research campaign row source for The Gentlemen RaaS Operations. |
Source Collision Notes
IntelliOS starts this detail page from the retained source record for Thegentlemen.
No possible same-actor, alias reuse, sub-cluster, duplicate-boundary, or external-source collision is currently retained for this actor.
| Collision Source | Candidate Records | Shared Evidence | Treatment |
|---|---|---|---|
| None retained | No candidate records | No shared evidence recorded | No collision action needed. |
| External sources | Mandiant, CrowdStrike, other non-SOCRadar sources | None retained | External collisions are shown separately when retained. |