01
The Gentlemen is a fast-scaling Ransomware-as-a-Service operation.1
It emerged in mid-2025 and combines a ransomware affiliate program with an initial-access-broker capability rather than functioning only as an encryptor brand.
CARDS
The Gentlemen developed into a leading Ransomware-as-a-Service operation after emerging in mid-2025. Check Point reported that it led June 2026 shame-site disclosures with 17% of published attacks, ahead of Qilin at 11%.
Directory Briefing
01
It emerged in mid-2025 and combines a ransomware affiliate program with an initial-access-broker capability rather than functioning only as an encryptor brand.
02
That lineage helps explain why the group reached operational maturity and meaningful victim volume much faster than a typical new entrant.
03
Public research describes a large inventory of already exploited FortiGate devices and validated VPN credentials that affiliates can use without first sourcing their own foothold.
04
Unpatched Internet-facing appliances, purchased credentials, brute-forced VPN accounts, and valid-account use should be immediate scoping priorities.
05
Cross-platform lockers let affiliates concentrate disruption in server and virtualization infrastructure, not merely Windows endpoints.
06
Data theft preserves leverage even when restoration is possible, so recovery and breach analysis must run in parallel.
07
Reported operator communications describe movement from blunt BYOVD-based EDR killing toward more selective userland evasion.
08
Public analysis documents use of information taken from one service provider to support a later compromise of that provider's client, expanding third-party exposure.
09
Check Point measured The Gentlemen at 17% of June 2026 shame-site disclosures versus Qilin at 11%; the ranking is important but should retain its leak-site methodology label.
10
Patch and isolate exposed appliances, rotate and investigate VPN credentials, review privileged sessions, and protect ESXi and immutable backups before encryption expands.
Bottom Line Up Front
It emerged in mid-2025 and combines a ransomware affiliate program with an initial-access-broker capability rather than functioning only as an encryptor brand.
That lineage helps explain why the group reached operational maturity and meaningful victim volume much faster than a typical new entrant.
Public research describes a large inventory of already exploited FortiGate devices and validated VPN credentials that affiliates can use without first sourcing their own foothold.
Unpatched Internet-facing appliances, purchased credentials, brute-forced VPN accounts, and valid-account use should be immediate scoping priorities.
Cross-platform lockers let affiliates concentrate disruption in server and virtualization infrastructure, not merely Windows endpoints.
Data theft preserves leverage even when restoration is possible, so recovery and breach analysis must run in parallel.
Reported operator communications describe movement from blunt BYOVD-based EDR killing toward more selective userland evasion.
Public analysis documents use of information taken from one service provider to support a later compromise of that provider's client, expanding third-party exposure.
Check Point measured The Gentlemen at 17% of June 2026 shame-site disclosures versus Qilin at 11%; the ranking is important but should retain its leak-site methodology label.
Patch and isolate exposed appliances, rotate and investigate VPN credentials, review privileged sessions, and protect ESXi and immutable backups before encryption expands.
Decision Context
Actor Card Detail
Entity Type1
Ransomware profile
First Seen1
2025-08-01
Last Seen1
2026-07-09
Origin1
RU
Motivation1
Financially motivated Ransomware-as-a-Service and initial-access brokerage
Primary Access Pattern1
Unpatched edge devices, FortiGate VPN infrastructure, purchased credentials, Windows/Linux servers, and VMware ESXi.
Objective1
Financially motivated Ransomware-as-a-Service and initial-access brokerage
Victimology
No named victim organizations are retained in the cited source artifacts for this profile. Countries and sectors are targeting context, not victim identities.
Identity
Aliases1
Source Boundary
SOCRadar is the retained baseline for this profile. IntelliOS preserves source labels as discovery and comparison signals until a cited source explicitly supports a merge, split, or actor-boundary change.
Targeting
Target Countries / Exposure1,2
Associated Activity1
ATT&CK IDs1
Campaign Context
| Campaign / Operation | Source-Backed Context |
|---|---|
| The Gentlemen RaaS Operations4,3 | The Gentlemen RaaS Operations is retained in the campaign database for The Gentlemen. The Gentlemen combines affiliate-driven ransomware with access to pre-compromised FortiGate infrastructure and purchased credentials, targeting Windows, Linux, and ESXi while stealing data and impairing defenses. |
Indicators
216 IOCs are reported by SOCRadar, but the underlying observable values are not yet retained in IntelliOS. The profile therefore cites the source count without republishing unstored IOC values.
Source coverage: 1 source group tracked; 0 currently contribute retained observable or context rows.
Retained Public Observables1,2
216 IOCs are reported by SOCRadar, but the underlying observable values are not yet retained in IntelliOS. The profile therefore cites the source count without republishing unstored IOC values.
| Source | Reported | Retained | Coverage Status |
|---|---|---|---|
| SOCRadar2 | 216 | 0 | Reported IOC count retained; underlying SOCRadar feed values are not republished unless stored as cited public observables. |
Actor Chronology
No source-backed actor-activity dates are currently retained. Publication and record-maintenance dates are not promoted into activity dates.
IntelliOS Intel Products
None Found
Source Reconciliation
| Source | Primary Name | Treatment | Boundary |
|---|---|---|---|
| SOCRadar | The Gentlemen | Baseline actor-card record retained for the current profile view. | Fields reflect the retained database record. Additional source consensus, collisions, and canonical identity mappings can be layered into this profile without automatically merging actors. |
| IntelliOS | The Gentlemen | Normalizes this record for directory search, card display, profile lookup, and future product linking. | Normalization is a presentation and workflow aid; it is not an independent attribution claim. |
Source Collision Notes
IntelliOS starts this detail page from the retained source record for The Gentlemen.
No possible same-actor, alias reuse, sub-cluster, duplicate-boundary, or external-source collision is currently retained for this actor.
| Collision Source | Candidate Records | Shared Evidence | Treatment |
|---|---|---|---|
| None retained | No candidate records | No shared evidence recorded | No collision action needed. |
| External sources | Mandiant, CrowdStrike, other non-SOCRadar sources | None retained | External collisions are shown separately when retained. |
Citations
| # | Source | Use In Card |
|---|---|---|
| 1 | SOCRadar Threat Actor Database https://socradar.io/free-tools/threat-actor/ransomware | Threat actor directory source for profile fields and reported activity. |
| 2 | SOCRadar Actor Profile https://socradar.io/free-tools/ransomware-intelligence/groups/thegentlemen | Actor-specific source for ransomware profile metadata and reported IOC counts when available. |
| 3 | Check Point: June 2026 ransomware landscape https://blog.checkpoint.com/research/a-new-ransomware-leader-emerges-as-june-2026-attack-volumes-climb-worldwide/ | Primary Threat Research |
| 4 | Check Point: The Gentlemen internal leak analysis https://blog.checkpoint.com/research/when-the-ransomware-gang-gets-hacked-what-the-gentlemen-leak-reveals-about-modern-ransomware-risk/ | Primary Threat Research |