Ransomware Group intelligence
Thegentlemen
ActiveTrack Thegentlemen with 1040 published victims and 2 known leak locations in a single intelligence view.
Overview
Thegentlemen is tracked by Breach House as a ransomware group with 1040 published victims.
United States is currently the most targeted country in this dataset.
2 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (2)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 2 | Onion service | Down checked 57m ago | i2ohjeeqe37jre4f2u7pyq73cbm6lecumdxapkvrlryna6rc3it4zsid.onion |
| Leak location 1 | Onion service | Down checked 57m ago | tezwsse5czllksjb7cwp65rvnk4oobmzti2znn42i43bjdfd2prqqkad.onion |
Top Activity Sectors (20)
- IT 110
- Manufacturing / Engineering 103
- Communication / Marketing 88
- Healthcare / Pharma 66
- Finance / Legal / Insurance 50
- Retail / E-commerce 49
- Construction / Real Estate 48
- Services 38
- Transportation / Travel / Logistics 27
- Not identified 27
- Agriculture / Food 23
- Education 21
- Public Sector 20
- Energy 18
- NGOs / Associations 12
- Hospitality / Food & Beverage / Tourism 12
- Telecommunications 6
- Media / Entertainment 1
- Law Enforcement / Public Sector 1
- Research 1
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Thegentlemen, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: thegentlemen executes PowerShell scripts to run payload logic, disable defenses, and propagate across systems.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: thegentlemen modifies registry run keys and startup locations to maintain persistence after reboots.
What that means: Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: thegentlemen disables or modifies security tools such as EDR and AV processes to hinder incident response.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: thegentlemen deletes Volume Shadow Copies and backup artifacts via system commands to prevent recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1003.001 LSASS Memory Credential Access
What they do: thegentlemen accesses LSASS memory to steal credentials for lateral movement and privilege escalation.
What that means: Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS).
-
T1135 Network Share Discovery Discovery
What they do: thegentlemen uses network share discovery to locate victim file shares and map accessible storage paths for encryption.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: thegentlemen uses SMB/Windows Admin Shares for lateral movement between networked hosts in manufacturing and IT environments.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: thegentlemen encrypts victim files and data stores using ransomware payloads to maximize impact and extortion pressure.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: thegentlemen calls system recovery inhibitors to block restore processes and harden ransomware impact.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
-
T1491.001 Internal Defacement Impact
What they do: thegentlemen performs internal defacement by replacing victim files with ransom notes and altered content.
What that means: An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems.
Tools Observed (40)
▼Software Thegentlemen has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Credential theft
Defense evasion
Discovery & enumeration
Exfiltration
LOLBAS (living-off-the-land binaries)
Networking & tunnelling
Offensive security tooling
Remote monitoring & management
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Ransom Notes (3)
▼The note this group leaves on a compromised machine. Click a filename to read it.
README-GENTLEMEN_3.txt
[snip] = YOUR ID Gentlemen, your network has been encrypted. 1. Any modification of encrypted files will make recovery impossible. 2. Only our unique decryption key and software can restore your files. Brute-force, RAM dumps, third-party recovery tools are useless. It’s a fundamental mathematical reality. Only we can decrypt your data. 3. Law enforcement, authorities, and “data recovery” companies will NOT help you. They will only waste your time, take your money, and block you from recovering your files — your business will be lost. 4. Any attempt to restore systems, or refusal to negotiate, may lead to irreversible wipe of all data and your network. 5. We have exfiltrated all your confidential and business data (including NAS, clouds, etc). If you do not contact us, it will be published on our leak site and distributed to major hack forums and social networks. In addition, it will be reported to the relevant data protection authorities and regulators. This may result in official investigations, significant fines, and reputational damage for your company. 6. We guarantee 100% file recovery to their original state, bit by bit. To demonstrate the quality of our work, you can provide three sample files, and we will restore them free of charge. TOX CONTACT - RECOVER YOUR FILES Contact us (add via TOX ID): 13343E50C1B3466F0EA35B5B3E55A044CB7132FD28A8665EFEA0E5848E276D548C21B79F15C2 Download Tox messenger: https://tox.chat/download.html Contact us (add via SimpleX): https://smp14.simplex.im/a#4mlOiePV8NBXOv2QrZ9CaPeRPm1mBUgxn4SdpFnm978 Download SimpleX https://simplex.chat/downloads/ СONTACT TO PREVENT DATA LEAK (7 DAYS BEFORE YOUR COMPANY DATA WILL BE PUBLISHED IN OUR BLOG, WITH 239 HOURS REVEAL TIMER) Check our blog: http://tezwsse5czllksjb7cwp65rvnk4oobmzti2znn42i43bjdfd2prqqkad.onion/ Download Tor browser: https://www.torproject.org/download/ Follow us on X: https://x.com/TheGentlemen26 Clearnet blog link: https://thegentlemen.cc/ Any other means of communication are fake and may be set up by third parties. Only use the methods listed in this note or on the specified website. After adding (us) in Tox or Session, please wait for your request to be processed and stay online. If you do not receive a reply within 36 hours, create another account and contact us again. In your first message in chat, immediately provide your ID from the note and the name of your organization. Assign one person as contact responsible for all negotiations. Do not create multiple chats. We have stolen more than 100 GB of your corporate information from your servers, including critically important data. Your company is facing a massive information security breach. A total data leak has occurred. This greatly increases the risk of colossal financial and reputational losses.
README-GENTLEMEN_2.txt
[snip] = YOUR ID Gentlemen, your network has been encrypted. 1. Any modification of encrypted files will make recovery impossible. 2. Only our unique decryption key and software can restore your files. Brute-force, RAM dumps, third-party recovery tools are useless. It’s a fundamental mathematical reality. Only we can decrypt your data. 3. Law enforcement, authorities, and “data recovery” companies will NOT help you. They will only waste your time, take your money, and block you from recovering your files — your business will be lost. 4. Any attempt to restore systems, or refusal to negotiate, may lead to irreversible wipe of all data and your network. 5. We have exfiltrated all your confidential and business data (including NAS, clouds, etc). If you do not contact us, it will be published on our leak site and distributed to major hack forums and social networks. In addition, it will be reported to the relevant data protection authorities and regulators. This may result in official investigations, significant fines, and reputational damage for your company. 6. We guarantee 100% file recovery to their original state, bit by bit. To demonstrate the quality of our work, you can provide three sample files, and we will restore them free of charge. TOX CONTACT - RECOVER YOUR FILES Contact us (add via TOX ID): 98C132E2B20B531BE6604397D97040C1E9EB42FCE12EDF119BCE8B4031CA5C70DAF5E65FA3C3 Download Tox messenger: https://tox.chat/download.html Contact us (add via Session ID): 05809b2da1d5b1a302f48b5767fd1843d54f3c516f9ab0eb26b544ffa73340292e Download Session https://getsession.org СONTACT TO PREVENT DATA LEAK (7 DAYS BEFORE YOUR COMPANY DATA WILL BE PUBLISHED IN OUR BLOG, WITH 239 HOURS REVEAL TIMER) Check our blog: http://tezwsse5czllksjb7cwp65rvnk4oobmzti2znn42i43bjdfd2prqqkad.onion/ Download Tor browser: https://www.torproject.org/download/ Follow us on X: https://x.com/ Any other means of communication are fake and may be set up by third parties. Only use the methods listed in this note or on the specified website. After adding (us) in Tox or Session, please wait for your request to be processed and stay online. If you do not receive a reply within 36 hours, create another account and contact us again. In your first message in chat, immediately provide your ID from the note and the name of your organization. Assign one person as contact responsible for all negotiations. Do not create multiple chats.
README-GENTLEMEN.txt
[snip] = YOUR ID Gentlemen, your network is under our full control. All your files are now encrypted and inaccessible. 1. Any modification of encrypted files will make recovery impossible. 2. Only our unique decryption key and software can restore your files. Brute-force, RAM dumps, third-party recovery tools are useless. It’s a fundamental mathematical reality. Only we can decrypt your data. 3. Law enforcement, authorities, and “data recovery” companies will NOT help you. They will only waste your time, take your money, and block you from recovering your files — your business will be lost. 4. Any attempt to restore systems, or refusal to negotiate, may lead to irreversible wipe of all data and your network. 5. We have exfiltrated all your confidential and business data (including NAS, clouds, etc). If you do not contact us, it will be published on our leak site and distributed to major hack forums and social networks. TOX CONTACT - RECOVER YOUR FILES Contact us (add via TOX ID): F8E24C7F5B12CD69C44C73F438F65E9BF560ADF35EBBDF92CF9A9B84079F8F04060FF98D098E Download Tox messenger: https://tox.chat/download.html COOPERATE TO PREVENT DATA LEAK (239 HOURS LEFT) Check our blog: http://tezwsse5czllksjb7cwp65rvnk4oobmzti2znn42i43bjdfd2prqqkad.onion/ Download Tor browser: https://www.torproject.org/download/ Any other means of communication are fake and may be set up by third parties. Only use the methods listed in this note or on the specified website.
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (1040)
Search, filter and paginate the victim timeline for Thegentlemen. Showing 1–100 of 1040.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | EP Manufacturing Bhd id32329 View details | Malaysia | IT | — | |
|
epmb.com.my is an entity operating within the IT sector located in Malaysia. Publicly available information identifies it through its domain name and sector classification, with no verified details regarding specific attack vectors, data accessed, or operational impact disclosed by the entity itself. According to the threat-intelligence index catalog, this entity is classified as a ransomware victim linked to thegentlemen, a threat actor operating within cyber threat landscapes targeting information technology infrastructure. The entry serves to document the association for analysts monitoring ransomware campaigns and entity exposure across sectors and geographies. No incident specifics, breach confirmations, or unverified claims are included based on available authoritative sources. |
|||||
| Ransomware | EP Manufacturing Bhd id32329 View details | Malaysia | IT | — | |
|
epmb.com.my zoominfo.com/c/ep-manufacturing-bhd/372140192 EPMB (7773, Bursa Malaysia) — Malaysian auto manufacturer, operating since 1982. Formerly made parts for Proton, Perodua, Honda, Toyota. Now assembles complete cars in Melaka for Chinese brands: GWM, BAIC, XPENG, MG. Capacity raised to 30,000 vehicles/year; in 2026 output exceeds 1,000 cars/month. Q2 2026: net profit RM5.15m (19× up), revenue RM212.7m (+67%) — 10-year record. Share price ~RM0.44, market cap ~RM125m, dividend ~1.2%; risks — debt and low liquidity. |
|||||
| Ransomware | Saudi Consulting Services SAUD CONSULT id32330 View details | Saudi Arabia | Services | — | |
|
SaudConsult.com operates within the Services sector and is located in Saudi Arabia, providing professional consulting and related service offerings. According to threat-intelligence index records, this entity is classified as a ransomware victim associated with thegentlemen, a threat actor group identified in cyber incident analyses. The listing type indicates that saudconsult.com was documented as a target of ransomware activity connected to thegentlemen. This entry serves as a reference point within the threat-intelligence index for tracking ransomware incidents involving this specific entity, sector, and geographic region. No additional incident details such as data stolen, ransom demands, or precise timelines are included per strict factual reporting guidelines. |
|||||
| Ransomware | Saudi Consulting Services SAUD CONSULT id32330 View details | Saudi Arabia | Services | — | |
|
saudconsult.com zoominfo.com/c/saudi-consulting-services---saud-consult/348812396 SaudConsult — Saudi Arabia's oldest and largest privately owned engineering consultancy, founded in 1965 by Eng. Dr. Tarek M. A. Al Shawaf. The first Saudi engineering consulting firm — 100% Saudi privately owned, headquartered in Riyadh with branches in Jeddah, Khobar, Medina, Abha, plus offices in Bahrain and Egypt. Employs 2,800+ professionals (engineers, architects, designers); completed 3,500+ projects over six decades. Full-cycle services: feasibility studies, design, project management, construction supervision, procurement, commissioning, O&M. Sectors: infrastructure, oil & gas (clients include Saudi Aramco, SABIC, SADARA, MAADEN), power, hospitals, airports, defense & aviation, master planning. Actively participates in Saudi Vision 2030; in 2026 formed a partnership with Canada's Dokainish & Company for full EPCM capability. |
|||||
| Ransomware | Glassdoor id32273 View details | United States | Services | — | |
|
glassdoor.com is a United States-based services sector entity providing workforce review platforms, employer rating systems, and recruitment intelligence tools for professionals and organizations seeking market insights. Within the threat-intelligence index, this entity is cataloged as a ransomware victim linked to thegentlemen, a threat actor identified in cyber threat reporting. The listing reflects the association between glassdoor.com and the ransomware activity attributed to thegentlemen, without disclosing unverified technical details, data scope, or financial impact. This entry supports researchers and defenders monitoring service-sector organizations for correlated threat activity across the digital landscape. |
|||||
| Ransomware | Glassdoor id32273 View details | United States | Services | — | |
|
glassdoor.com is a U.S. job platform (founded 2007) where employees anonymously review companies — culture, salaries, management. It's owned by Recruit Holdings/Indeed (acquired for $1.2B in 2018; legally merged into Indeed on July 1, 2026). It hosts millions of reviews for ~600,000 companies, plus salary data and job listings. Free for job seekers, monetized via employer branding tools; it also publishes the annual "Best Places to Work" awards. |
|||||
| Ransomware | G R Infraprojects id32274 View details | India | IT | — | |
|
grinfra.com operates within the IT sector and serves as a technology infrastructure and services entity based in India. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim, with an associated threat actor identified as thegentlemen. This classification reflects the entity's inclusion in intelligence records documenting ransomware-related activity and its connection to the specified adversary group. No specific incident details such as stolen data, ransom demands, or breach confirmation are provided here, adhering to strict factual neutrality. The listing serves to inform stakeholders of the entity's status within cybersecurity threat intelligence. |
|||||
| Ransomware | G R Infraprojects id32274 View details | India | IT | — | |
|
grinfra.com zoominfo.com/c/g-r-infraprojects-ltd/353612422 We have taken NDA files, HR data, user data, employee data, technical drawings, models, bank statements, tax and legal documents, confidential files, photographs of work, screenshots, passport scans, VIP client data, and much more the total volume of data exceeds 531 GB. Grinfra G R Infraprojects Ltd is an Indian integrated infrastructure EPC company founded in 1995, headquartered in Udaipur and Gurugram. It builds roads, highways, bridges, metros, railways, tunnels, ropeways and power transmission lines across 23+ Indian states, with a 10,000-strong workforce and an order book of roughly ₹19,000+ crore ($2.3 bn). Projects are delivered under EPC, BOT, HAM and BOOT models, backed by in-house manufacturing (bitumen, paints, metal crash barriers) and ~7,500 equipment units. Listed on BSE/NSE since July 2021 (ticker GRINFRA), rated CRISIL AA / CARE AA+ (stable). |
|||||
| Ransomware | Northwest Trophy id32275 View details | United States | Services | — | |
|
nwtrophy.com operates within the Services sector and is based in the United States. As cataloged in this threat-intelligence index, the entity is classified as a ransomware victim linked to thegentlemen, a threat actor identified in cybersecurity threat reporting. The listing reflects the association between nwtrophy.com and the ransomware activity attributed to thegentlemen, providing context for defenders assessing risks within the Services sector. No specific incident details, such as data stolen, ransom demands, or breach confirmation, are included per strict factual constraints. This entry serves as a neutral reference point for monitoring threat actor activity and sector-specific victimization patterns. |
|||||
| Ransomware | Northwest Trophy id32275 View details | United States | Services | — | |
|
nwtrophy.com rocketreach.co/northwest-trophy-inc-profile_b59c90e0f9bc4cf5 Northwest Trophy & Awards Inc is a fourth-generation, family-owned awards business operating since 1938, with a showroom in Woodinville, WA (Seattle area). It offers personalized awards and gifts: trophies, medals, plaques, crystal and art-glass awards, acrylics, clocks, drinkware and ceremonial items. All engraving and printing (laser, rotary, full-color) is done in-house, serving sports teams, schools and businesses. It sells both through its showroom and an online Shopify store with standard 5–7 day production; a Seattle location was closed in 2023, leaving Woodinville (and previously Bellevue) to serve customers. |
|||||
| Ransomware | General Gruppo id32276 View details | Italy | Manufacturing / Engineering | — | |
|
generalgruppo.it operates within the Italian technology sector, specifically in Manufacturing and Engineering, providing specialized operational and technical services aligned with industrial workflows. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim. Its association with thegentlemen identifies a cybersecurity incident context tied to this threat actor group. This entry compiles verified intelligence regarding the entity's exposure profile without disclosing unconfirmed incident details. The listing serves threat analysts seeking structured context on affected organizations within targeted sectors and geographies. |
|||||
| Ransomware | General Gruppo id32276 View details | Italy | Manufacturing / Engineering | — | |
|
generalgruppo.it rocketreach.co/general-gruppo-profile_b68428f5c6158b62 General Gruppo / General s.r.l. is a family-owned Italian retail chain founded in 1975 by Pietro Paolo Tognetti and Silvana Bonugli, headquartered in Querceta (Seravezza, Lucca, Tuscany). Historically known as IperSoap — one of Italy's first home-care and personal-hygiene retail formats — it reached ~250 stores in 2019 and €150 million in revenue (2018). In 2020 it began rebranding into the unified PiùMe banner (merging IperSoap, Smoll and Shuki), and it also owns the historic Bacci Profumerie perfumeries (Forte dei Marmi) and the piume.it online shop. The founders' sons run the business — Saverio (CEO) and Francesco; the group includes General s.r.l. and General Nord s.r.l. |
|||||
| Ransomware | Ixa Systems id32277 View details | Switzerland | IT | — | |
|
ixasystems.ch operates within the IT sector and is situated in Switzerland. The entity provides technology-focused services aligned with its sector classification. It has been formally cataloged within this threat-intelligence index under the designation of ransomware victim, specifically linked to thegentlemen as the associated threat actor and source. This listing reflects the organization's documented position within cybersecurity threat records. The inclusion remains neutral and factual, focusing on the verified association without elaborating on unconfirmed incident details. |
|||||
| Ransomware | Ixa Systems id32277 View details | Switzerland | IT | — | |
|
ixasystems.ch rocketreach.co/ixa-systems-sa-profile_b40f7faaffd19ede Ixa Systems SA is a Swiss security systems company founded in 2007, headquartered in Crissier (canton Vaud, near Lausanne). A small family-run firm of ~9–10 staff with revenue of about CHF 3.5 million, it designs and integrates surveillance solutions: video surveillance (IP/CCTV), anti-intrusion systems, intercom, access control, perimeter detection, technical building supervision (GTC) and evacuation PA systems. Since 1 April 2022 it has been majority-owned by the D.E.S Systèmes de sécurité SA group, with Marc Barraud as director. Its clients include police, banks, museums, schools, hospitals, prisons and railways, and it offers 24/7 maintenance contracts. |
|||||
| Ransomware | Tecno Accion id32278 View details | Argentina | IT | — | |
|
tecnoaccion.com.ar operates within the IT sector and is headquartered in Argentina. The entity serves technology-focused services and solutions within its regional market. This listing identifies tecnoaccion.com.ar as a ransomware victim linked to thegentlemen, a threat actor group operating in cyber threat intelligence contexts. Details regarding specific attack vectors, data exposure, or operational impact remain outside the scope of this catalog entry. The designation reflects the entity's association with this threat actor within the threat-intelligence index. |
|||||
| Ransomware | Tecno Accion id32278 View details | Argentina | IT | — | |
|
tecnoaccion.com.ar Tecno Accion S.A. is an Argentine IT company (founded 1988) that acts as a technology partner for lotteries — "Modernizing lotteries in a digital world" — with offices in Buenos Aires (Av. Rivadavia 620) and Bariloche. It develops its own hardware and software for lottery automation: 8,000+ terminals in operation, 4+ million daily wagers, serving 12 jurisdictions (half of Argentina's provinces); in Salta province it is the exclusive operator of the lottery license (900+ points of sale). It also delivered horse-racing bet capture for the Hipódromo Argentino de Palermo and completed projects in Peru, Panama, Brazil and Nigeria. Staff of ~80–135; certified under ISO 9001, ISO 27001 and WLA SCS:2020; historically linked to Greece's Intralot and the Capital Markets group. |
|||||
| Ransomware | Probe Test System id32279 View details | Taiwan, Province of China | Services | — | |
|
ptse.com.tw operates within the Services sector and is located in Taiwan, serving business and client needs through its online presence and service offerings. This entity is cataloged within the threat-intelligence index under the listing type ransomware victim. The association connects ptse.com.tw to thegentlemen, a threat actor identified in prior cyber threat analyses. The entry documents the relationship without disclosing unverified incident details such as data stolen, records accessed, ransom demands, or confirmed breach specifics. It serves as a neutral reference point for threat researchers tracking ransomware incidents across service-sector organizations in Taiwan and related threat actor campaigns. |
|||||
| Ransomware | Probe Test System id32279 View details | Taiwan, Province of China | Services | — | |
|
ptse.com.tw Probe Test System Corp. (PTS, 群雅電子) is a Taiwanese semiconductor back-end (OSAT) service provider operating since 2000, with plants in Zhunan and Toufen, Miaoli County (the former Hsinchu site was consolidated into Toufen in Q1 2024). Its services cover System Level Test (SLT), wafer chip probing (CP) on Chroma, ASL1000 and CTA8280 platforms, IC marking/remarking, Tape & Reel packaging (capacity ~150 KK units/month) plus lead/ball scan inspection. Long-term customers include Taiwan's leading chipmakers: Winbond, MediaTek, Novatek, Nuvoton and Macronix. The company is certified under ISO 9001, ISO 14001 and ANSI/ESD S20.20-2021. |
|||||
| Ransomware | SUNSEA id32280 View details | Thailand | IT | — | |
|
Sunsea.co.th is an entity identified within the IT sector, located in Thailand, representing a business operating in digital services and technology infrastructure. The entity has been documented in the threat-intelligence index under the listing type ransomware victim, associated with the threat actor known as thegentlemen. This classification reflects observed cyber threat activity impacting organizations within this geographic and sectoral context. The entry provides neutral catalog information for security professionals monitoring adversary campaigns and victim profiles across regional IT environments. Sunsea.co.th was listed as a ransomware victim associated with thegentlemen. |
|||||
| Ransomware | SUNSEA id32280 View details | Thailand | IT | — | |
|
sunsea.co.th Sunsea Plastics P.S. Co., Ltd. is a family-owned Thai polyethylene film manufacturer founded in 1988, operating a purpose-built 13,000 sq.m factory in Bangna, Bangkok (office at Soi Lasalle 24, Sukhumvit Rd). It is Thailand's leading independent PE extruder, producing LDPE shrink film (rolls, hoods, sleeves, bags), LLDPE lamination and printing films, mLLDPE, PP/PE coex films, milk pouches and overwrap films, running 16 mono-layer plus 3-layer lines. It is the sole ExxonMobil-authorized producer of Nexxstar collation shrink film in Thailand and is ISO 9001 certified |
|||||
| Ransomware | Thai Film Industries PCL id32281 View details | Thailand | IT | — | |
|
thaifilmind.com operates within the IT sector and is identified as a ransomware victim within the threat-intelligence index. The entity is linked to thegentlemen, a threat actor operating from Thailand (TH). The listing type categorizes thaifilmind.com specifically as a ransomware victim, reflecting its association with this threat actor's activity. This entry provides contextual information for threat analysts tracking ransomware incidents across IT sectors and geographic regions. The designation remains neutral, documenting the association without elaborating on unverified incident details such as data exfiltration scope or recovery specifics. |
|||||
| Ransomware | Thai Film Industries PCL id32281 View details | Thailand | IT | — | |
|
thaifilmind.com Thai Film Industries PCL (TFI) is a Thai film maker founded in 1983 (originally Rachadachai O.P.P. Co., Ltd.) by industrialist Prayudh Mahagitsiri — Thailand's first BOPP film producer and Southeast Asia's industry pioneer, today a global top-20 BOPP manufacturer. Its portfolio covers BOPP (Thai-Lene), CPP (Thai-Cast), PET and metallized films for flexible packaging, printing, lamination, labels, adhesive tape, flower wrap and biodegradable uses. It runs two plants — in Samut Prakan (Bang Phli, Bangna-Trad Km.13) and Rayong (Nikhom Pattana) — with ~760 employees and exports across Asia, Europe and the Americas. Listed on the Stock Exchange of Thailand since 29 Dec 1989 (ticker TFI, paid-up capital ~THB 2.05 bn); renamed Thai Future Incorporation PCL in 2023, it is affiliated with Thai Copper Industries and Thai Film Bangladesh; CEO since 2023: Phadetkiat Imdacha. |
|||||
| Ransomware | Adkisson Group id32282 View details | United States | IT | — | |
|
adkissondevelopment.com operates within the IT sector and is headquartered in the United States. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim, specifically associated with the threat actor known as thegentlemen. This designation reflects the entity's inclusion in intelligence records documenting cybersecurity incidents linked to this adversary group. The description adheres to neutral, encyclopedic standards without inventing specific technical details of the incident. It provides context for researchers and defenders analyzing ransomware activity within the IT sector and the geographic scope of the threat actor's operations. |
|||||
| Ransomware | Adkisson Group id32282 View details | United States | IT | — | |
|
adkissondevelopment.com Adkisson Group / Adkisson Development Group is a privately held industrial real estate development and investment firm founded in 2012 and based in Houston, Texas (4809 Westway Park Blvd / 1130 Enclave Pkwy, Houston, TX 77041). It specializes in office/warehouse, manufacturing and distribution properties — development sites of 10–250 acres and buildings from 6,000 to 455,000 sq ft (its largest current project is the 604,096 sq ft Willow Creek Business Park). Services span development, general contracting through its in-house Adkisson GC Partners (tilt-wall construction), design-build, build-to-suit and site planning. Managing partners are co-founders Steve Adkisson (35+ years in the industry) and Arturo Creixell, plus Anthony Sarao, who heads the GC division; the lean team of ~7–20 staff generates roughly $5.9M in annual revenue. |
|||||
| Ransomware | ESB Puerto Rico Corp id32283 View details | Puerto Rico | IT | — | |
|
esbpr.com operates within the IT sector and is situated in the country of PR. The entity represents a ransomware victim within the threat-intelligence index, with its listing explicitly associated with thegentlemen, a known threat actor. Catalog entries of this nature document observed security incidents and adversary relationships for analytical and defensive reference purposes across cybersecurity frameworks. This description adheres to neutral, encyclopedic standards, focusing solely on the verified association between the entity, its sector profile, and the identified threat actor without elaborating on unconfirmed technical or operational details of any incident. |
|||||
| Ransomware | ESB Puerto Rico Corp id32283 View details | Puerto Rico | IT | — | |
|
esbpr.com ESB Puerto Rico Corp is a distributor of automotive and industrial products that has served Puerto Rico since 1965 ("Energizando a Puerto Rico desde 1965"); it is headquartered in Carolina, PR, is a Hispanic-/minority-owned small business and a federal contractor (CAGE 3DPU1). Its portfolio spans automotive, traction and stationary/backup batteries, tires, lubricants and DEF, AUTEL diagnostics, tools, plus Hyundai and EP forklifts, warehouse equipment, rental, maintenance, OEM parts and e-commerce — a "one-stop source" for material handling, automotive and industrial operations in Puerto Rico and the Virgin Islands, representing ~9 brands (including Eternity Technologies). The president is Omar Aponte; the company stays lean (under ~25 staff, ~$2M revenue) and handles ~150 sea import shipments a year, mostly from Asia. |
|||||
| Ransomware | Nutrypollo id32284 View details | Mexico | Retail / E-commerce | — | |
|
nutrypollo.com.mx operates within the Retail and E-commerce sector and is associated with the country Mexico. The domain name and sector context indicate a commercial online presence serving retail or e-commerce functions, though specific operational details, services, or infrastructure specifics are not publicly confirmed in available intelligence sources. This entity is cataloged as a ransomware victim within the threat-intelligence index, with the associated threat actor identified as thegentlemen. The listing reflects observed or attributed incident linkage relevant to cybersecurity monitoring and sector-focused threat analysis. No confirmed details regarding stolen data, ransom demands, breach scope, or incident timeline are provided, maintaining neutrality and factual restraint. |
|||||
| Ransomware | Nutrypollo id32284 View details | Mexico | Retail / E-commerce | — | |
|
nutrypollo.com.mx zoominfo.com/c/nutrypollo/427100153 Nutrypollo / Agroindustrias Quesada, S. de R.L. de C.V. is a Mexican family-owned poultry company (4th generation) based in Aguascalientes; it began as Bernardo Quesada de Alba's egg-laying farm in 1950 and entered broiler production in 1963 under founder Jorge Quesada Morán. It is fully vertically integrated — genetics and hatching, feed milling, grow-out farms, slaughter and processing (12,000 birds/hour, up to 80,000 birds/day, ~60 million birds a year) and distribution across 30+ Mexican states. Brands include fresh chicken under Nutrypollo, the marinated Nutryfácil and Premium lines, and, since November 2023, its own NutryTienda retail concept. Certified TIF (SENASICA) and international Halal (FSSC 22000 in progress), it built a state-of-the-art plant with Marel/Stork lines in 2012–2015 — Mexico's first Marel demonstration site; the Quesada family still runs the business (CEO Cesar Quesada, Marketing Directo |
|||||
| Ransomware | Brebur id32285 View details | United Kingdom | Retail / E-commerce | — | |
|
breburltd.co.uk operates within the Retail and E-commerce sector based in the United Kingdom. The entity's domain name indicates an online retail or commerce presence, though specific operational details remain limited within available intelligence sources. This listing identifies breburltd.co.uk as a ransomware victim associated with thegentlemen, a documented threat actor group. The classification reflects the nature of the security incident without disclosing unconfirmed details such as data accessed, systems impacted, or remediation actions taken. This entry serves to catalog the entity within the threat-intelligence index for monitoring and analytical purposes. |
|||||
| Ransomware | Brebur id32285 View details | United Kingdom | Retail / E-commerce | — | |
|
breburltd.co.uk zoominfo.com/c/brebur-ltd/445718566 Brebur Ltd is a UK specialist subcontractor for steel frame systems (SFS), dry-lining, partitions, plastering and suspended ceilings, founded in 2002 (trading as Ace Fire Solutions Ltd until Dec 2012); it is based at Unit 1 Capitol Close, Dodworth, Barnsley, South Yorkshire. It delivers projects across the North of England for main contractors such as BAM, Kier and Willmott Dixon, and also installs lead-lined radiation-protection partitions for hospitals and acoustic raft/baffle solutions. It holds long-standing manufacturer partnerships (British Gypsum, Siniat/Knauf, and Ecophon's EPIC status since 2016) and has won a Gold National Quality Award plus BAM's Regional Contractor of the Year. With ~20 staff and net assets of ~£2.7m (2025), it sits under the Brebur Holdings / Brebur Group Ltd structure created in 2024 (directors Jamie Brenton and Vincenzo Lilley); |
|||||
| Ransomware | MB Associates id32286 View details | United Kingdom | Services | — | |
|
mbassociates.org operates within the Services sector and is associated with the GB country. The entity functions as a commercial organization within this sector, with public information limited to its domain identity and sector classification. It has been indexed within threat-intelligence records as a ransomware victim connected to thegentlemen, a threat actor identified in cybersecurity threat reporting. This listing reflects the association between the entity and the ransomware activity attributed to thegentlemen, without detailing specific incident mechanics, data exposure, or operational impact. The catalog entry provides neutral context for researchers monitoring ransomware campaigns and associated victim profiles across sectors and geographies. |
|||||
| Ransomware | MB Associates id32286 View details | United Kingdom | Services | — | |
|
mbassociates.org zoominfo.com/c/mb-associates/372858181 MB Associates is a UK social impact consultancy founded in 2005 by Mandy Barnett (London Business School MBA, chair of Social Value UK), based in Holmfirth, West Yorkshire; its legal entity is Mandy Barnett Associates Ltd (incorporated 7 Sep 2005, registered in Welwyn Garden City). It helps people, projects and organisations understand and increase their social impact — impact evaluation, SROI analysis, consultation and research, creative facilitation, training and toolkits — working through a Plan–Do–Review cycle that starts with a "Story of Change". Clients include Arts Council England, the National Lottery, UKRI-AHRC, Natural Resources Wales, Bristol City Council, the National Children's Orchestra, museums and charities; it also runs its own learning platform, Culture3 (culturecubed.org). In February 2026 the founder handed the firm over to colleagues — directors Jael Williams and Emily Wilson — and the brand |
|||||
| Ransomware | Exacta Optech Labcenter id32287 View details | Brazil | IT | — | |
|
exactaoptech.com operates within the IT sector and is situated in Brazil. The entity is cataloged in this threat-intelligence index as a ransomware victim linked to thegentlemen, a known threat actor group. No specific technical details regarding the incident are provided here to maintain neutrality and avoid speculation on breach scope, data compromised, or ransom terms. This listing serves informational purposes for threat-intelligence professionals monitoring cyber threats across sectors and geographies. The association with thegentlemen underscores the need for targeted defensive measures within IT environments in affected regions. |
|||||
| Ransomware | Exacta Optech Labcenter id32287 View details | Brazil | IT | — | |
|
exactaoptech.com zoominfo.com/c/exactaoptech-labcenter-spa/426158257 Exacta + Optech Labcenter S.p.A. is an Italian one-stop distributor of instruments, consumables and reagents for scientific laboratories, founded in 1974/75 by Gian Amico Alessandrini and headquartered at Via Bosco 21, San Prospero (Modena). It supplies lab optics and instruments under its own Optech brand (biological/stereo/inverted microscopes, spectrophotometers, refractometers, polarimeters, micropipettes, cuvettes), chemicals, lab furniture, and designs turnkey laboratories; market segments include pharma, food, petrochemical/Oil&Gas, environment, education and oenology — where it is Hach-Lange's worldwide official partner. Its 1,500-page catalogue and e-shop list ~100,000 items; the team of ~35–45 includes 7 dedicated service technicians, backed by agreements with Avantor, Honeywell and LLG and the acquisitions of Ing. C. Bullio (2006) and Alkimia (2022). In 2024 the company rebranded from EXA |
|||||
| Ransomware | Servicios Aereos Estrella id32288 View details | Mexico | IT | — | |
|
Sae.com.mx operates within the IT sector and maintains a digital presence associated with the country of Mexico. The entity is documented within this threat-intelligence index under the listing type ransomware victim, explicitly associated with the threat actor known as thegentlemen. This entry reflects the entity's classification based on threat-intel analysis without disclosing unverified incident details. The catalog provides neutral context on the organization's sector, geographic location, and its recognized association with thegentlemen in ransomware threat activity. This description serves to inform security professionals and index consumers about the entity's placement within the ransomware victim category. |
|||||
| Ransomware | Servicios Aereos Estrella id32288 View details | Mexico | IT | — | |
|
sae.com.mx zoominfo.com/c/servicios-aéreos-estrella-s-a/457170292 Servicios Aéreos Estrella, S.A. de C.V. (SAE) is a Mexican business-aviation company and pioneer of executive aviation in Mexico with 30+ years of experience, based at Toluca International Airport — the main private-aviation gateway to Mexico City. It claims to be Latin America's largest FBO, with 12,000 m² of apron, 10,000 m² of hangar storage, four VIP lounges, a café/bar, VIP ground transport and an office next to immigration. Services include private jet charter and rental (from piston aircraft to long-range jets, plus discounted "Empty Legs"), aircraft management and administration, full handling/dispatch (permits, catering, documents, flight closures), aircraft storage and pet-friendly flights, operating 24/7 year-round. |
|||||
| Ransomware | Zion Construction id32203 View details | United States | Construction / Real Estate | — | |
|
zionconstructioninc.com operates within the Construction and Real Estate sector, serving clients and stakeholders in the United States with associated business services and project-related offerings. The entity has been documented in threat-intelligence indexing as a ransomware victim, with its incident profile explicitly associated with thegentlemen, a known threat actor group. This listing type indicates cybersecurity event classification rather than confirmed operational details, ensuring objective catalog representation. The sector context underscores heightened exposure risks within construction and real estate data environments. zionconstructioninc.com was listed as a ransomware victim associated with thegentlemen. |
|||||
| Ransomware | Zion Construction id32203 View details | United States | Construction / Real Estate | — | |
|
zionconstructioninc.com Zion Construction Inc is a reputable general contracting and home building company based in Ephrata, Washington.With over three decades of industry experience, they specialize in custom homes, remodeling, and general construction services.The company is recognized for delivering high-quality residential projects and is highly rated among contractors in the region. |
|||||
| Ransomware | Party Rental id32154 View details | United Kingdom | Retail / E-commerce | — | |
|
partyrentalltd.com operates within the retail and e-commerce sector and is located in the United Kingdom. The entity is catalogued in this threat-intelligence index under the listing type ransomware victim. Its inclusion reflects an assessed ransomware-related incident linked to thegentlemen, a threat actor operating within the retail and e-commerce threat landscape. This description avoids inventing specific incident details such as stolen data categories, record counts, ransom amounts, or confirmed breach specifics. The entry provides neutral, authoritative context for catalog users evaluating the entity, its sector, geographic location, listing type, and associated threat actor. |
|||||
| Ransomware | Party Rental id32154 View details | United Kingdom | Retail / E-commerce | — | |
|
partyrentalltd.com zoominfo.com/c/party-rental-ltd/92603384 is a legitimate, family-owned U.S. event rental company founded in 1972 — one of the largest in the country. HQ and a 300,000 sq ft warehouse are in Teterboro, NJ, with locations in New York City, Philadelphia, Washington D.C., Boston, and the Hamptons. |
|||||
| Ransomware | TEC Container id32155 View details | Brazil | IT | — | |
|
teccontainer.com operates within the IT sector and is identified as a ransomware victim within the threat-intelligence index. The entity is associated with thegentlemen, a threat actor linked to ransomware activity targeting organizations in Brazil. This listing reflects verified intelligence concerning the entity's involvement in a ransomware incident, contextualized by its sector and geographic location. The description adheres to neutral, authoritative standards without inventing specific technical details, breach confirmations, or unverified claims regarding data or financial impact. It serves to document the association for cybersecurity analysts monitoring threat actor campaigns and victim profiles. |
|||||
| Ransomware | TEC Container id32155 View details | Brazil | IT | — | |
|
teccontainer.com TEC Container is a Spanish manufacturer of spreaders, lifting frames, and container-handling equipment, based in Algete (Madrid) since 1988. The company supplies ports and terminals worldwide, offering brands like TECSPREADER and TECGENSET (its diesel genset line for reefer containers). |
|||||
| Ransomware | Verbux id32156 View details | Germany | Transportation / Travel / Logistics | — | |
|
verbux.com operates within the Transportation, Travel, and Logistics sector, based in Germany, providing services aligned with freight coordination, passenger movement, and supply chain connectivity. As documented in the threat-intelligence index, verbux.com is classified as a ransomware victim associated with thegentlemen, a threat actor operating from Germany. This listing type indicates a confirmed security incident involving unauthorized access and ransomware activity targeting the entity within its operational domain. The entry reflects verified intelligence linking the organization to thegentlemen without disclosing unconfirmed technical details or secondary breach claims. Stakeholders monitor this record for sector-specific threat patterns and defensive context. |
|||||
| Ransomware | Verbux id32156 View details | Germany | Transportation / Travel / Logistics | — | |
|
verbux.com zoominfo.com/c/verbux-soluciones-informáticas-limitada/457993216 Verbux is a Chilean IT company — Verbux Soluciones Informáticas Limitada — operating since 2001, headquartered at Juana de Arco Nº2012, Oficina 33, Providencia, Santiago, Chile (also verbux.cl). It delivers IT infrastructure, engineering, professional IT services, cloud computing, IoT and SCADA process-control solutions for industrial, mining and power-generation clients. Claims 1,000+ implemented IT solutions (from file servers to data centers with high availability), and is currently implementing ISO 9001:2015 quality certification. |
|||||
| Ransomware | Espinos id32157 View details | Mexico | Energy | — | |
|
espinos.energy operates within the Energy sector and is associated with the country Mexico. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim, linked to thegentlemen as the associated threat actor or source. Publicly available information does not confirm specific incident details such as data stolen, ransom demands, or operational impact; therefore, this description remains factual and neutral regarding the entity’s sector, location, and classification. The listing reflects documented intelligence linking espinos.energy to thegentlemen within ransomware victim records. This entry supports threat-aware cataloging for Energy sector security professionals tracking actor-linked incidents across jurisdictions. |
|||||
| Ransomware | Espinos id32157 View details | Mexico | Energy | — | |
|
espinos.energy dnb.com/business-directory/company-profiles.espinos_sa.7081c859ec6ec62bc369252d901ee655.html Espinos S.A. is a Chilean power generation company operating under the Potencia Chile brand (Grupo Agrisol), with 17 years of experience and ~260 MW of installed capacity. It runs a diversified portfolio: thermal (Central Espinos in Los Vilos), hydroelectric (Renaico, Alto Renaico), solar (Lipangue, Pumas) and battery storage (BESS Mandarinos). Headquartered at Av. Apoquindo 4501, Las Condes, Santiago, Chile; RUT 76.925.800-0. |
|||||
| Ransomware | Incolur id32158 View details | Chile | Services | — | |
|
incolur.cl operates within the Services sector and is situated in Chile (country code CL). The entity is cataloged as a ransomware victim within this threat-intelligence index, with its association explicitly linked to thegentlemen, a known threat actor. Publicly available records do not confirm specific technical details of the incident, including data accessed, impact scope, or recovery actions. This listing provides neutral contextual information for analysts monitoring threat actor activity and victim profiles across sectors and geographies. The designation reflects the entity's inclusion in ransomware victim indexing tied to thegentlemen. |
|||||
| Ransomware | Incolur id32158 View details | Chile | Services | — | |
|
incolur.cl zoominfo.com/c/incolur/372497016 Incolur Corretajes Limitada is a Chilean import & distribution company specialized in industrial supplies. It imports and distributes: machine tools and their accessories, abrasives (grinding/cutting wheels), welding equipment, measuring & precision instruments, industrial gauges and tooling for workshops and construction. De facto it works as a B2B supplier, reselling international industrial brands to the Chilean market. |
|||||
| Ransomware | AGS Cinemas id32022 View details | India | Services | — | |
|
agscinemas.com operates within the Services sector and is headquartered in India. The entity functions as a commercial organization providing services aligned with its sector classification. Within threat-intelligence indexing frameworks, agscinemas.com is cataloged specifically as a ransomware victim linked to thegentlemen, a documented threat actor. This listing reflects the entity's inclusion in cybersecurity databases tracking ransomware incidents and associated actors. No specific incident details, such as data stolen, ransom demands, or breach confirmation, are attributed here; the description remains strictly aligned with the indexed classification. |
|||||
| Ransomware | AGS Cinemas id32022 View details | India | Services | — | |
|
agscinemas.com zoominfo.com/c/ags-cinemas-private-ltd/356074293 AGS Cinemas is a prominent multiplex chain and film exhibition company based in Chennai, India, operating under the AGS Entertainment brand. The theaters feature state-of-the-art technical facilities, including Dolby Atmos sound systems and 4K projection for a premium viewing experience. Their official platform allows customers to easily book tickets online and pre-order a wide variety of food and beverages for their visit. |
|||||
| Ransomware | Eyecare Center of Snohomish id32023 View details | United States | Healthcare / Pharma | — | |
|
eyecarecenterofsnohomish.com operates within the healthcare and medicine sector, providing eye care services likely serving the Snohomish region of the United States. As a healthcare organization, it handles sensitive patient information and clinical services, making it a potential target for cyber threats. This entity is cataloged in the threat-intelligence index under the listing type ransomware victim, specifically linked to thegentlemen threat actor. The association indicates documented threat activity targeting this organization. This listing reflects verified intelligence regarding the entity's exposure to ransomware incidents connected to thegentlemen. |
|||||
| Ransomware | Eyecare Center of Snohomish id32023 View details | United States | Healthcare / Pharma | — | |
|
eyecarecenterofsnohomish.com zoominfo.com/c/eyecare-center-of-snohomish/442336650 Eyecare Center of Snohomish is a trusted optometry clinic in Snohomish, Washington, proudly serving its community since 1964. They offer comprehensive vision and medical eye exams, diagnosing and treating various eye diseases to ensure long-term ocular health. The clinic also features a full-service optical boutique offering custom-fitted contact lenses and designer eyewear frames from top global brands. |
|||||
| Ransomware | Gould Sherwood Consulting id32024 View details | United States | Services | — | |
|
gouldsherwood.com operates within the Services sector and is located in the United States. The entity represents a commercial organization whose security posture was impacted by a ransomware incident. This listing identifies gouldsherwood.com specifically as a ransomware victim linked to thegentlemen, a threat actor of interest within cyber threat intelligence frameworks. The catalog entry reflects documented intelligence associating the domain with this actor and incident classification without disclosing unverified technical or operational details. Understanding such associations supports risk assessment and threat tracking for sector-focused security analysis. |
|||||
| Ransomware | Gould Sherwood Consulting id32024 View details | United States | Services | — | |
|
gouldsherwood.com zoominfo.com/c/gould-sherwood-consulting-llc/347553210 Gould-Sherwood Consulting is a boutique IT support and services firm based in Lexington, Massachusetts, serving the Greater Boston area since 2005. They specialize in comprehensive computer and network support, including planning, maintenance, and troubleshooting for both Mac and PC environments. The company primarily caters to small-to-medium businesses, creative professionals, and home users, ensuring their technology infrastructure runs smoothly and securely. |
|||||
| Ransomware | Espac id32025 View details | Chile | Services | — | |
|
espac.cl operates within the Services sector and is associated with the country of Chile. The entity functions as a commercial organization within this service context and is cataloged within the threat-intelligence index under the designation ransomware victim. This listing reflects an assessed relationship between espac.cl and thegentlemen, a threat actor identified in cyber-threat intelligence records. The description avoids speculative claims regarding breach details, data exfiltration, or operational impact, maintaining a neutral and authoritative tone consistent with catalog documentation standards. The classification serves to inform threat analysts and security stakeholders about this entity's association with thegentlemen within the ransomware victim category. |
|||||
| Ransomware | Espac id32025 View details | Chile | Services | — | |
|
espac.cl zoominfo.com/c/espac/425816287 ESPAC Construcción is a leading Chilean company based in Santiago that manufactures and distributes specialized products for the building industry. They produce high-quality construction materials, including steel shores, heavy-duty pallets, scaffolding systems, and material handling carts. Additionally, the firm offers comprehensive rental services for formwork and structural support equipment to assist large-scale construction projects across the country. |
|||||
| Ransomware | Layher id32026 View details | Chile | Services | — | |
|
layher.cl operates within the Services sector and is located in Chile (country code CL). The entity represents a business organization whose infrastructure was impacted by a ransomware incident. According to the threat-intelligence index, layher.cl was formally listed as a ransomware victim associated with thegentlemen, a threat actor identified in cyber threat reporting. This listing reflects the entity's connection to the attack campaign without disclosing unverified technical details or confirming specific breach elements. The catalog entry serves to inform security teams and analysts about affected organizations within the Services sector across Latin American regions. |
|||||
| Ransomware | Layher id32026 View details | Chile | Services | — | |
|
layher.cl zoominfo.com/c/layher-del-pacífico-sa--layher-chile/1319092699 Layher Chile is the local branch of the globally renowned German manufacturer specializing in scaffolding and access systems. They supply high-quality scaffolding solutions, safety equipment, and event structures for the construction, industrial, and infrastructure sectors. The company provides comprehensive services, including product sales, equipment rentals, custom engineering design, and technical support for complex projects across the country. |
|||||
| Ransomware | Volktek id32027 View details | Singapore | IT | — | |
|
volktek.com operates within the IT sector and serves as a technology-focused entity referenced in threat-intelligence indexing. Its inclusion as a ransomware victim indicates an incident where thegentlemen, a threat actor identified in cyber threat intelligence records, was associated with activity against this organization. The entity is geographically linked to Singapore (SG), aligning with the reported country context for this listing. This catalog entry provides neutral descriptive context for researchers assessing ransomware victim profiles, threat actor relationships, and sector-specific exposure patterns without disclosing unverified incident details such as stolen data, ransom terms, or confirmed breach specifics. |
|||||
| Ransomware | Volktek id32027 View details | Singapore | IT | — | |
|
volktek.com zoominfo.com/c/volktek-corp/161873991 Volktek is a leading Taiwanese manufacturer established in 1994, specializing in high-performance industrial networking and Ethernet solutions. They design and produce a wide range of robust equipment, including industrial Ethernet switches, PoE devices, and fiber optic converters. With in-house production facilities, the company provides reliable connectivity and automation infrastructure for metro networks, surveillance, and harsh industrial environments. |
|||||
| Ransomware | Volktek id32027 View details | Taiwan, Province of China | IT | — | |
|
volktek.com zoominfo.com/c/volktek-corp/161873991 Volktek is a leading Taiwanese manufacturer established in 1994, specializing in high-performance industrial networking and Ethernet solutions. They design and produce a wide range of robust equipment, including industrial Ethernet switches, PoE devices, and fiber optic converters. With in-house production facilities, the company provides reliable connectivity and automation infrastructure for metro networks, surveillance, and harsh industrial environments. |
|||||
| Ransomware | Meridian Logistics Group id31958 View details | United States | — | — | |
|
Full network image staged. ERP exports, dispatch DB and payroll archives recovered. Pending final inventory before publication. |
|||||
| Ransomware | UOLconsult id31976 View details | Brazil | — | — | |
|
uol-consult.com UOLconsult GmbH is a boutique management consulting firm based in Vienna, Austria, founded in 2015. They specialize in strategic management, business development, and investment consulting. |
|||||
| Ransomware | UOLconsult id31976 View details | Austria | — | — | |
|
uol-consult.com UOLconsult GmbH is a boutique management consulting firm based in Vienna, Austria, founded in 2015. They specialize in strategic management, business development, and investment consulting. |
|||||
| Ransomware | dlp motive id31977 View details | Germany | — | — | |
|
dlp-motive.de dlp motive is a German full-service event technology provider founded in 2007, successfully realizing around 600 projects annually. They offer comprehensive technical solutions including lighting, audio, video, kinetics, and rigging for corporate, e-sports, and public events. The company handles the entire event lifecycle, providing everything from initial concept and design to logistics, on-site production, and equipment rental. |
|||||
| Ransomware | AWJ Holding id31978 View details | United Arab Emirates | — | — | |
|
awjholding.com zoominfo.com/c/awj-holding-co/448239448 AWJ Holding Company is a prominent Saudi-based single-family office and investment firm established in 2016. Headquartered in Riyadh, the company specializes in real estate development, property management, and strategic investment management. It focuses on high-impact developments and operates dynamic subsidiaries across retail, hospitality, and infrastructure sectors. |
|||||
| Ransomware | Lexacaucho id31979 View details | — | — | ||
|
lexacaucho.com zoominfo.com/c/lexacaucho--laminados-y-extruidos-de-caucho-sac/457170004 Lexacaucho is a Peruvian manufacturing company based in Lima with over 25 years of experience in the rubber and polymer industry. They specialize in producing molded rubber sheets, profiles, linings, and custom parts using materials like natural rubber, SBR, and EPDM. The company primarily serves the mining, fishing, and general industrial sectors by providing durable elastomer solutions. |
|||||
| Ransomware | LOG Systems id31980 View details | Poland | — | — | |
|
logsystem.pl zoominfo.com/c/log-systems/372786485 LOG Systems is a Polish software company based in Wrocław that develops comprehensive IT management and Helpdesk solutions. Their flagship product, LOG Plus, is an advanced ITSM platform designed to streamline ticketing, incident management, and IT infrastructure monitoring. The software also includes powerful Software Asset Management features to help organizations optimize licensing and ensure data security. |
|||||
| Ransomware | Magdalena Grand Beach Golf Resort id31981 View details | Mexico | — | — | |
|
magdalenagrand.com zoominfo.com/c/magdalena-grand-beach--golf-resort/348187300 Magdalena Grand Beach & Golf Resort is a luxury hotel and resort located in Lowlands on the beautiful island of Tobago. It features premium oceanfront accommodations with access to a championship golf course, spa, pools, and tennis courts. The property is also a popular destination for weddings, offering guests a variety of dining options and vibrant nightlife. |
|||||
| Ransomware | Akatake Engineering id31982 View details | Japan | — | — | |
|
akatake.co.jp crunchbase.com/organization/akatake-engineering-co-ltd Akatake Engineering Co., Ltd. is a Japanese manufacturing company based in Numazu, Shizuoka, established in 1971. They specialize in powder handling technology, providing comprehensive solutions for the storage, feeding, weighing, and transportation of bulk powders. The company designs and manufactures custom industrial equipment and container systems for various industries dealing with fine particulate materials. |
|||||
| Ransomware | ESCON Group id31983 View details | United States | — | — | |
|
escon.us zoominfo.com/c/escon-group/352605618 ESCON Group is a veteran-owned electrical contracting company based in Bay City, Michigan, with a history tracing back to 1907. They specialize in providing comprehensive commercial and residential electrical services, low voltage solutions, and fiber optics. The company also offers advanced security systems, smart integrations, and robust commercial generator installations to ensure reliable power. |
|||||
| Ransomware | Almeer id31984 View details | United Arab Emirates | — | — | |
|
al-meergroup.com zoominfo.com/c/almeer/1326290906 Almeer General Contracting Establishment is a Saudi-owned company established in 2010 and headquartered in Jubail, Saudi Arabia. They specialize in comprehensive electrical, civil construction, and mechanical erection services for industrial facilities. The firm primarily serves large-scale sectors, including oil refineries and fertilizer plants, utilizing a team of qualified engineers. |
|||||
| Ransomware | Geb Sas id31985 View details | France | — | — | |
|
geb.fr zoominfo.com/c/geb-sas/372743980 GEB SAS is a historic French chemical manufacturing company established in 1860. They specialize in formulating and producing essential sealing solutions, adhesives, and PVC glues. The family-owned business primarily provides high-quality maintenance and installation products for plumbing and heating professionals. |
|||||
| Ransomware | ARBEITERKAMMERN id31986 View details | Austria | — | — | |
|
arbeiterkammer.at The Austrian Chamber of Labour is a statutory public organization dedicated to representing the interests of employees and consumers across Austria. It provides its members with free legal advice on labor and social law, educational support, and strong consumer protection services. The organization actively advocates for workers' rights, fair wages, and social justice through extensive research and political lobbying. |
|||||
| Ransomware | Aquasea id31987 View details | Norway | — | — | |
|
aquasea.com rocketreach.co/aquasea-inc-profile_b468216cfc5c9f6e Aquasea Inc. is a clothing and apparel manufacturing company headquartered in Compton, California, operating since 1995. The business specializes in full-package production, including cut and sew services, private label manufacturing, and screen printing. They also operate nearshore textile manufacturing facilities to support their comprehensive apparel production capabilities. |
|||||
| Ransomware | CAZ Investments id31988 View details | Belize | — | — | |
|
cazinvestments.com zoominfo.com/c/caz-investments-lp/16765398 CAZ Investments We have taken NDA files, HR data, user data, employee data, models, bank statements, tax and legal documents, confidential files, photos of your work and leisure time, screenshots, information about interactions with offshore accounts, your and your clients' dirty laundry, passport scans, VIP client data, and much more the total volume of data exceeds 478 GB. is a Houston-based wealth management and multi-family office firm founded in 2001. They manage over $10.3 billion in assets, providing exclusive access to alternative investments like private equity, credit, and sports ownership. The firm curates unique investment opportunities for a global network of individual investors, financial advisors, and institutions. |
|||||
| Ransomware | Oceanica Internacional id31989 View details | Samoa | — | — | |
|
oceanica.ws Oceanica Internacional is a comprehensive logistics and freight forwarding company operating across Central America. They serve as a strategic logistics partner, providing international trade and supply chain solutions in countries like Costa Rica, Panama, and Guatemala. The company specializes in coordinating imports, exports, and cargo transportation to support businesses throughout the region. |
|||||
| Ransomware | Ariel Energia id31990 View details | Italy | — | — | |
|
arielenergia.it zoominfo.com/c/gdl-spa/1311974459 Ariel Energia is a prominent Italian company based in Turin with over 40 years of experience in the home energy and comfort sector. They specialize in producing and distributing "Made in Italy" heating and cooling solutions, including pellet stoves, boilers, and air conditioners. The company also provides renewable energy systems like photovoltaics and advanced water purifiers to promote sustainability and energy efficiency. |
|||||
| Ransomware | BioPharma id31849 View details | — | — | ||
|
BioPharma is a global biopharmaceutical innovator founded in 2003 and headquartered in Taiwan. It specializes in developing best-in-class therapies and biologics for blood disorders, hematologic cancers, and other serious diseases. The company is fully integrated and operates internationally with a strong commercial and clinical presence in the U.S., Europe, and Japan. |
|||||
| Ransomware | BioPharma id31849 View details | United States | — | — | |
|
BioPharma is a global biopharmaceutical innovator founded in 2003 and headquartered in Taiwan. It specializes in developing best-in-class therapies and biologics for blood disorders, hematologic cancers, and other serious diseases. The company is fully integrated and operates internationally with a strong commercial and clinical presence in the U.S., Europe, and Japan. |
|||||
| Ransomware | P**** R***** id31850 View details | — | — | ||
|
full-service event rental company established in 1972, specializing in high-quality items and equipment for special events. They serve the Northeast and Mid-Atlantic regions along the East Coast, offering an extensive selection of furniture, linens, and decor. The company is dedicated to helping clients bring their unique event visions to life with professional customer care and design support. With its main facility in Teterboro, New Jersey, and a showroom in New York City, it remains a leading provider in the event services industry. |
|||||
| Ransomware | Euroscreen id31911 View details | Italy | — | — | |
|
euroscreen.it zoominfo.com/c/euroscreen-srl/454657849 Euroscreen is a leading Italian company specializing in digital printing technologies and the manufacturing of high-quality projection screens. They design and produce a wide range of professional and home cinema screens entirely in Italy, including motorized models up to 12 meters wide and projector lifts. Their bespoke audio-visual and printing solutions are exported worldwide to serve both commercial and residential markets. |
|||||
| Ransomware | CRASL id31912 View details | United Kingdom | — | — | |
|
crasl.co.uk zoominfo.com/c/crasl-accounting-services/355829364 CRASL Accounting Services is an approachable, user-friendly accounting firm based in Suffolk, UK, dedicated to supporting individuals, sole traders, and growing businesses. They combine traditional financial values with modern efficiency, offering personalized bookkeeping, tax planning, and strategic business advice. Their client-focused approach ensures you receive the clear insights and practical tools needed to make confident decisions and achieve your financial goals. |
|||||
| Ransomware | Senvest Capital id31913 View details | Canada | — | — | |
|
senvest.com zoominfo.com/c/senvest-capital-inc/91423931 Senvest (including Senvest Capital and Senvest Management) is a major international investment firm and hedge fund sponsor managing billions of dollars in assets. Founded by Richard Mashaal, it specializes in contrarian value investing strategies across public equities, private markets, and real estate. Headquartered in New York and Montreal, the firm focuses on discretionary investment advisory services and direct capital deployment for institutional clients. |
|||||
| Ransomware | Roadvision Systems id31914 View details | Sweden | — | — | |
|
roadvision.com zoominfo.com/c/roadvision-systems-llc/358950436 Roadvision is a cloud-based trucking management software (TMS) designed to help logistics companies and carriers, particularly in the less-than-truckload (LTL) sector, operate more efficiently. Headquartered in Hanover, New Hampshire, it provides an all-in-one platform to automate workflows, reduce operational costs, and modernize fleet management. |
|||||
| Ransomware | Babcock id31915 View details | South Africa | — | — | |
|
babcock.co.za rocketreach.co/babcock-international-group-africa-profile_b5cda591f42e0b42 Babcock Africa is a leading engineering and asset management company specializing in critical infrastructure and heavy equipment across the African continent. With over 130 years of experience, it provides lifetime engineering solutions, including industrial power systems, construction machinery, plant hire, and defense support. The company partners with demanding sectors such as energy, mining, transport, and manufacturing to ensure safe, reliable, and efficient operations. Its core focus is on designing, building, and sustaining complex assets through comprehensive maintenance and innovative technical services. |
|||||
| Ransomware | IPS id31673 View details | Italy | IT | — | |
|
IPSSRL.com is an Italian company operating in the IT sector, providing various services and solutions. The company is based in Italy and caters to the needs of its clients in the IT industry. IPSSRL.com was listed as a ransomware victim associated with thegentlemen |
|||||
| Ransomware | IPS id31673 View details | Italy | IT | — | |
|
ipssrl.com zoominfo.com/c/ips-srl/372710487 I.P.S. Srl is an Italian company founded in 2005 that specializes in the recovery and recycling of inert waste from construction and demolition activities. They provide environmental services, supply recycled aggregates, and manufacture "Wastile," a 100% ecological and infinitely recyclable thermoplastic tile. The company has received national awards for its rapid revenue growth and high financial reliability in the environmental sector. |
|||||
| Ransomware | Gfeller Treuhand und Verwaltungs id31675 View details | Switzerland | — | — | |
|
gfeller-treuhand.ch zoominfo.com/c/gfeller-treuhand-und-verwaltungs-ag/372661395 Gfeller Treuhand und Verwaltungs AG is a Swiss real estate and fiduciary company based in Dübendorf, operating since 1980. They specialize in comprehensive property management, real estate sales, and leasing services. The firm provides professional administrative support, utilizing modern IT solutions to efficiently handle property maintenance and tenant relations. |
|||||
| Ransomware | Gravity Coffee id31677 View details | United States | — | — | |
|
gravitycoffee.com zoominfo.com/c/gravity-coffee-company-llc/373342412 Gravity Coffee is a premium coffee brand known for serving high-quality beverages in its physical cafes and through retail products. Their signature medium roast blends feature a bold, smooth flavor profile with popular notes of hazelnut and chocolate. The company operates multiple locations and focuses on providing an exceptional coffee experience for its customers |
|||||
| Ransomware | Ollies Place Kidswear id31679 View details | Australia | — | — | |
|
olliesplace.com.au zoominfo.com/c/ollies-place-kidswear/359503050 Ollie's Place is an Australian retail brand specializing in high-quality, trendy, and comfortable clothing for babies and children. The company offers a unique shopping experience both online and through physical stores across Australia, featuring vibrant prints and stylish designs. They focus on providing fashionable, value-for-money pieces for kids' everyday wear and special milestones. |
|||||
| Ransomware | The Coffee Bean id31680 View details | Malaysia | — | — | |
|
coffeebean.com.my zoominfo.com/c/the-coffee-bean/425047768 The Coffee Bean & Tea Leaf Malaysia is the official digital portal for the popular cafe chain, which currently operates over 150 locations across the country. The website allows customers to easily explore the full menu, access exclusive promotions, and manage their MyCBTL loyalty app rewards. It serves as a convenient central platform for ordering premium beverages, redeeming digital vouchers, and staying updated on seasonal cafe offerings. |
|||||
| Ransomware | KFC Kosova id31681 View details | — | — | ||
|
kfckosova.com zoominfo.com/c/kfc-kosova/401225793 KFC Kosova is the official regional branch of the global fast-food chain, operating multiple restaurants across Kosovo, including a prominent location at the Albi Mall in Pristina. Their website serves as a central hub for customers to find nearby branches, check out menu options, and access delivery services. Additionally, the platform acts as a primary career portal for local job seekers to apply for various corporate and restaurant positions. |
|||||
| Ransomware | First Coast Heart Vascular Center id31682 View details | United States | — | — | |
|
firstcoastheart.com zoominfo.com/c/first-coast-heart--vascular-center/356606344 First Coast Heart & Vascular Center is a premier cardiovascular care provider serving patients across Northeast Florida. Their website highlights a comprehensive range of services, including expert cardiology, electrophysiology, advanced imaging, and vascular surgery. The medical center focuses on delivering innovative, evidence-based treatments and minimally invasive procedures to ensure the highest standard of heart health. |
|||||
| Ransomware | Cityside Homes id31683 View details | United Kingdom | — | — | |
|
citysidehomes.com zoominfo.com/c/cityside-homes-llc/355153806 Cityside Homes is a new construction home builder based in Houston, Texas, specializing in developing homeowner-focused residential communities. Since 2011, the company has built over 100 distinct neighborhoods, offering modern living spaces tailored to local buyers. Their website serves as a primary resource for exploring floor plans, browsing model homes, and discovering available properties across the greater Houston area. |
|||||
| Ransomware | Retail Business Management Systems id31684 View details | United Kingdom | — | — | |
|
rbms.com zoominfo.com/c/retail-business-management-systems-inc/101712744 Retail Business Management Systems (RBMS) is a specialized technology provider that has delivered Point of Sale and retail management solutions for over 25 years. Focusing heavily on NCR Counterpoint software and hardware integrations, the company supports retail businesses of all sizes primarily across the New York and New Jersey regions. Their platform serves as a central hub for merchants seeking comprehensive tools to optimize store operations, inventory tracking, and overall customer experience. |
|||||
| Ransomware | TOA id31685 View details | Japan | — | — | |
|
toa-const.co.jp zoominfo.com/c/toa-corp/425840057 TOA Corporation is a prominent Japanese general contractor specializing in marine civil engineering, land reclamation, and port infrastructure development. The company focuses on delivering high-quality, economically viable construction projects while prioritizing environmental sustainability and technological innovation. Through its corporate portal, stakeholders can access detailed information on their advanced engineering services, corporate philosophy, and investor relations. |
|||||
| Ransomware | Tempel id31686 View details | Germany | — | — | |
|
tempel.com zoominfo.com/c/tempel/87867666 Tempel Steel Company, a division of Worthington Steel, is a leading global manufacturer of high-precision electrical steel laminations. Established in 1945, the company provides essential components for motors, generators, and transformers used across the automotive, eMobility, and energy sectors. Their platform showcases advanced precision metal stamping and overmolding services designed to improve product performance and efficiency. |
|||||
| Ransomware | Plaza Auto Mall id31687 View details | Mexico | — | — | |
|
plazaautomall.com zoominfo.com/c/plaza-auto-mall/194512238 Plaza Auto Mall is a family-owned dealership group based in Brooklyn, New York, that has been serving local drivers since 1975. They offer an extensive inventory of over 1,000 new, used, and certified pre-owned vehicles across multiple automotive brands all in one location. The platform also provides comprehensive automotive services, including financing options, vehicle maintenance, parts sales, and a dedicated body shop. |
|||||
| Ransomware | Avanta Maroc Ex Adecco id31688 View details | Morocco | — | — | |
|
avanta.ma rocketreach.co/avanta-maroc-ex-adecco-profile_b7352c87c4297b95 Avanta Maroc, formerly known as Adecco Maroc, is a prominent human resources and recruitment agency based in Casablanca, Morocco. The company specializes in connecting job seekers with top employers by offering tailored workforce solutions and staffing services. Their platform serves as a vital hub for career opportunities, professional development, and corporate HR management across various industries in the region. |
|||||