# The Gentlemen Ransomware: How a Splinter Group Became the Second-Most Prolific RaaS Operation
In just over a year of operation, The Gentlemen ransomware group has evolved from relative obscurity into one of the most dangerous cybercriminal operations on the planet. First emerging in mid-2025 as a breakaway faction, this ransomware-as-a-service (RaaS) outfit has already claimed more victims than established names like Cl0p, LockBit, and RansomHub—and the threat is accelerating.
This week, The Gentlemen demonstrated its reach and ambition by threatening to leak sensitive data from Indra, a major NATO defense contractor, adding geopolitical stakes to what was already a critical cybersecurity challenge. For organizations worldwide, The Gentlemen represents a new class of threat: fast-moving, adaptable, and relentlessly effective.
## Background: The Qilin Split and Rise to Prominence
The Gentlemen's origins trace to a contentious business dispute—one that underscores how ransomware operates as a genuine (if criminal) enterprise with organizational hierarchies, affiliate relationships, and contractual disputes.
The group was founded by operators who previously worked as affiliates of Qilin, one of the world's most prolific ransomware operations. These founders, operating under the moniker ArmCorp, initiated the split in July 2025 after accusing Qilin's leadership of withholding approximately $48,000 in unpaid commissions. Rather than accept the loss, ArmCorp spun off to create their own RaaS platform—and it proved to be a shrewdly timed move.
The growth trajectory has been startling. In the first half of 2026 alone, The Gentlemen claimed more than 300 victims—accounting for roughly one in ten of all ransomware incidents globally during that period. This placed them second only to Qilin itself, their former parent organization. For a splinter group barely one year old, this represents an unprecedented market capture in the ransomware ecosystem.
## Global Reach and Industry Targeting
The Gentlemen's impact is genuinely worldwide. Victims span more than 60 countries across every continent, with operations cutting across over 20 distinct industry sectors:
Geographically, the group shows an unusual concentration pattern. Thailand is the single most-targeted country, followed by the USA, France, and Brazil. This geographic preference may indicate specific targeting strategies, language capabilities, or particular affiliates within their network operating in those regions.
## How The Gentlemen Break In: Attack Vectors
The Gentlemen don't rely on zero-day exploits or advanced persistence techniques. Instead, they leverage well-understood, unsexy vulnerabilities that organizations have struggled to remediate for years:
Primary attack vectors include:
| Vector | Details |
|--------|---------|
| Exposed edge devices | Unpatched Fortinet and Cisco appliances exposed to the internet |
| Unpatched VPNs | Remote access solutions with known vulnerabilities left unfixed |
| Internet-facing RDP | Remote Desktop Protocol exposed without proper segmentation or MFA |
| Remote management tools | Insecure remote support and monitoring platforms |
| Credential harvesting | Login credentials stolen by info-stealing malware or purchased from Initial Access Brokers (IABs) |
Once credentials are obtained—whether through malware like Emotet or purchased from underground forums—The Gentlemen leverage them for straightforward credential-based access. This approach is remarkably effective because it bypasses the need for vulnerability discovery and exploitation; the attackers simply log in using valid usernames and passwords, making their presence blend seamlessly with legitimate administrative activity.
## Technical Capabilities: Cross-Platform Devastation
What distinguishes The Gentlemen's malware from many competitors is its aggressive cross-platform architecture and self-propagating design.
The ransomware targets:
This breadth is significant because most ransomware variants focus primarily on Windows. By attacking Linux servers, ESXi hypervisors, and NAS devices, The Gentlemen can compromise not just workstations and file servers, but the underlying infrastructure itself—including virtualized environments and backup systems.
Once deployed, the malware self-propagates aggressively across networks, attempting to compromise as much infrastructure as possible before detection. The goal is speed: maximize encrypted assets before the target organization can interrupt the attack, activate incident response, or isolate affected segments.
Visual indicators of compromise include:
## The Double-Extortion Model and Leaked Negotiations
Like most modern ransomware operations, The Gentlemen employ the double-extortion model: they encrypt victim data and demand ransom for decryption keys, while simultaneously threatening to publish stolen data publicly if payment is refused.
But in May 2026, the group's operational discipline failed spectacularly. Internal chats between The Gentlemen operators were leaked, exposing their negotiation playbooks and revealing tactics that went beyond standard extortion. Most troublingly, the leaked conversations showed the group weaponizing stolen data strategically:
The group had stolen data from a UK software consultancy, and rather than simply threatening to publish it, they used it to attack one of the consultancy's clients in Turkey. They then offered the Turkish company "proof" that the breach originated with the UK firm and encouraged legal action against them—effectively turning victims against each other while multiplying the pressure for payment. This sophisticated social engineering demonstrates that The Gentlemen operates with strategic calculation, not just crude criminality.
## Implications for Organizations
The scale and sophistication of The Gentlemen threat creates urgent imperatives across multiple domains:
Operational Risk: With 300+ victims in six months, most organizations in targeted industries have a statistically significant probability of being on this group's radar—whether through active reconnaissance, purchasing stolen credentials from IABs, or targeting by affiliates within The Gentlemen's network.
Infrastructure Vulnerability: The focus on unpatched edge devices, VPNs, and management tools highlights a persistent gap between security best practices and organizational execution. Most targeted organizations *know* these systems are critical; the failure is in remediation discipline.
Supply Chain Exploitation: The incident involving UK consultancy clients in Turkey demonstrates that The Gentlemen will exploit business relationships to multiply leverage and damage—a pattern that makes supply chain risk assessment increasingly critical.
## Defense and Mitigation Strategies
While no single technical fix eliminates ransomware risk, organizations can dramatically reduce exposure by addressing fundamentals that The Gentlemen exploits:
Immediate priorities:
1. Patch management: Identify and remediate all exposed edge devices (Fortinet, Cisco, VPN appliances). This is not a future project—it's urgent.
2. Credential security: Implement multi-factor authentication (MFA) on all remote access points, including VPN and RDP.
3. Network segmentation: Isolate critical infrastructure (backup systems, hypervisors, domain controllers) from general network traffic.
4. Backup strategy: Maintain offline, immutable backups that cannot be accessed by ransomware or attackers who gain network access.
5. Monitoring and detection: Deploy behavioral analysis tools to detect lateral movement, privilege escalation, and encryption activities.
6. Incident response planning: Ensure your organization can detect and respond to compromise before encryption spreads. Active response speed is critical when facing fast-propagating malware.
---
## HackWire Analysis
The Gentlemen represent a critical inflection point in ransomware evolution. Unlike previous splinter operations that struggled to gain traction, The Gentlemen achieved market dominance in months—and they did so by executing flawlessly against well-known defensive gaps, not by inventing new attack techniques.
The deeper lesson is uncomfortable: most organizations are compromised not because defenses are impenetrable, but because fundamental hygiene remains incomplete. Exposed VPNs, missing MFA, unpatched edge devices, and inadequate network segmentation are not exotic vulnerabilities discovered by research teams. They're operational failures that every major incident response firm encounters constantly.
What makes The Gentlemen dangerous is not innovation—it's industrialization. They've built a RaaS platform that lets hundreds of affiliates execute the same playbook simultaneously across dozens of industries and continents. They have operational discipline (until the May chat leak), clear processes, and financial incentives that keep the machine running. The $48,000 dispute that spawned them was not a crisis; it was a business negotiation that created a competitor.
The threat to Indra, a NATO contractor, also signals escalation. Whether The Gentlemen will follow through on the threat or use it for leverage, the fact that they are targeting defense contractors suggests either growing confidence, pressure from nation-state actors seeking access, or both.
For defenders, the implication is clear: you cannot assume that your organization's security gaps are too well-known to matter, or that you're too small to target. The Gentlemen operate at scale and don't discriminate. They find credential brokers with access to thousands of organizations, purchase the cheapest valid credentials, and deploy malware across the board. You might be victim #127 or victim #301, but if you match the profile, you're in scope.
Defend the fundamentals relentlessly. Patch. Segment. Monitor. Backup. MFA. These are not optional. — *HackWire Editorial*
---
## Related Coverage