Ransomware Group intelligence
Thegentlemen
ActiveTrack Thegentlemen with 1040 published victims and 2 known leak locations in a single intelligence view.
Overview
Thegentlemen is tracked by Breach House as a ransomware group with 1040 published victims.
United States is currently the most targeted country in this dataset.
2 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (2)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 2 | Onion service | Down checked 2h ago | i2ohjeeqe37jre4f2u7pyq73cbm6lecumdxapkvrlryna6rc3it4zsid.onion |
| Leak location 1 | Onion service | Down checked 2h ago | tezwsse5czllksjb7cwp65rvnk4oobmzti2znn42i43bjdfd2prqqkad.onion |
Top Activity Sectors (20)
- IT 110
- Manufacturing / Engineering 103
- Communication / Marketing 88
- Healthcare / Pharma 66
- Finance / Legal / Insurance 50
- Retail / E-commerce 49
- Construction / Real Estate 48
- Services 38
- Transportation / Travel / Logistics 27
- Not identified 27
- Agriculture / Food 23
- Education 21
- Public Sector 20
- Energy 18
- NGOs / Associations 12
- Hospitality / Food & Beverage / Tourism 12
- Telecommunications 6
- Media / Entertainment 1
- Law Enforcement / Public Sector 1
- Research 1
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Thegentlemen, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: thegentlemen executes PowerShell scripts to run payload logic, disable defenses, and propagate across systems.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: thegentlemen modifies registry run keys and startup locations to maintain persistence after reboots.
What that means: Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: thegentlemen disables or modifies security tools such as EDR and AV processes to hinder incident response.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: thegentlemen deletes Volume Shadow Copies and backup artifacts via system commands to prevent recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1003.001 LSASS Memory Credential Access
What they do: thegentlemen accesses LSASS memory to steal credentials for lateral movement and privilege escalation.
What that means: Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS).
-
T1135 Network Share Discovery Discovery
What they do: thegentlemen uses network share discovery to locate victim file shares and map accessible storage paths for encryption.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: thegentlemen uses SMB/Windows Admin Shares for lateral movement between networked hosts in manufacturing and IT environments.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: thegentlemen encrypts victim files and data stores using ransomware payloads to maximize impact and extortion pressure.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: thegentlemen calls system recovery inhibitors to block restore processes and harden ransomware impact.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
-
T1491.001 Internal Defacement Impact
What they do: thegentlemen performs internal defacement by replacing victim files with ransom notes and altered content.
What that means: An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems.
Tools Observed (40)
▼Software Thegentlemen has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Credential theft
Defense evasion
Discovery & enumeration
Exfiltration
LOLBAS (living-off-the-land binaries)
Networking & tunnelling
Offensive security tooling
Remote monitoring & management
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Ransom Notes (3)
▼The note this group leaves on a compromised machine. Click a filename to read it.
README-GENTLEMEN_3.txt
[snip] = YOUR ID Gentlemen, your network has been encrypted. 1. Any modification of encrypted files will make recovery impossible. 2. Only our unique decryption key and software can restore your files. Brute-force, RAM dumps, third-party recovery tools are useless. It’s a fundamental mathematical reality. Only we can decrypt your data. 3. Law enforcement, authorities, and “data recovery” companies will NOT help you. They will only waste your time, take your money, and block you from recovering your files — your business will be lost. 4. Any attempt to restore systems, or refusal to negotiate, may lead to irreversible wipe of all data and your network. 5. We have exfiltrated all your confidential and business data (including NAS, clouds, etc). If you do not contact us, it will be published on our leak site and distributed to major hack forums and social networks. In addition, it will be reported to the relevant data protection authorities and regulators. This may result in official investigations, significant fines, and reputational damage for your company. 6. We guarantee 100% file recovery to their original state, bit by bit. To demonstrate the quality of our work, you can provide three sample files, and we will restore them free of charge. TOX CONTACT - RECOVER YOUR FILES Contact us (add via TOX ID): 13343E50C1B3466F0EA35B5B3E55A044CB7132FD28A8665EFEA0E5848E276D548C21B79F15C2 Download Tox messenger: https://tox.chat/download.html Contact us (add via SimpleX): https://smp14.simplex.im/a#4mlOiePV8NBXOv2QrZ9CaPeRPm1mBUgxn4SdpFnm978 Download SimpleX https://simplex.chat/downloads/ СONTACT TO PREVENT DATA LEAK (7 DAYS BEFORE YOUR COMPANY DATA WILL BE PUBLISHED IN OUR BLOG, WITH 239 HOURS REVEAL TIMER) Check our blog: http://tezwsse5czllksjb7cwp65rvnk4oobmzti2znn42i43bjdfd2prqqkad.onion/ Download Tor browser: https://www.torproject.org/download/ Follow us on X: https://x.com/TheGentlemen26 Clearnet blog link: https://thegentlemen.cc/ Any other means of communication are fake and may be set up by third parties. Only use the methods listed in this note or on the specified website. After adding (us) in Tox or Session, please wait for your request to be processed and stay online. If you do not receive a reply within 36 hours, create another account and contact us again. In your first message in chat, immediately provide your ID from the note and the name of your organization. Assign one person as contact responsible for all negotiations. Do not create multiple chats. We have stolen more than 100 GB of your corporate information from your servers, including critically important data. Your company is facing a massive information security breach. A total data leak has occurred. This greatly increases the risk of colossal financial and reputational losses.
README-GENTLEMEN_2.txt
[snip] = YOUR ID Gentlemen, your network has been encrypted. 1. Any modification of encrypted files will make recovery impossible. 2. Only our unique decryption key and software can restore your files. Brute-force, RAM dumps, third-party recovery tools are useless. It’s a fundamental mathematical reality. Only we can decrypt your data. 3. Law enforcement, authorities, and “data recovery” companies will NOT help you. They will only waste your time, take your money, and block you from recovering your files — your business will be lost. 4. Any attempt to restore systems, or refusal to negotiate, may lead to irreversible wipe of all data and your network. 5. We have exfiltrated all your confidential and business data (including NAS, clouds, etc). If you do not contact us, it will be published on our leak site and distributed to major hack forums and social networks. In addition, it will be reported to the relevant data protection authorities and regulators. This may result in official investigations, significant fines, and reputational damage for your company. 6. We guarantee 100% file recovery to their original state, bit by bit. To demonstrate the quality of our work, you can provide three sample files, and we will restore them free of charge. TOX CONTACT - RECOVER YOUR FILES Contact us (add via TOX ID): 98C132E2B20B531BE6604397D97040C1E9EB42FCE12EDF119BCE8B4031CA5C70DAF5E65FA3C3 Download Tox messenger: https://tox.chat/download.html Contact us (add via Session ID): 05809b2da1d5b1a302f48b5767fd1843d54f3c516f9ab0eb26b544ffa73340292e Download Session https://getsession.org СONTACT TO PREVENT DATA LEAK (7 DAYS BEFORE YOUR COMPANY DATA WILL BE PUBLISHED IN OUR BLOG, WITH 239 HOURS REVEAL TIMER) Check our blog: http://tezwsse5czllksjb7cwp65rvnk4oobmzti2znn42i43bjdfd2prqqkad.onion/ Download Tor browser: https://www.torproject.org/download/ Follow us on X: https://x.com/ Any other means of communication are fake and may be set up by third parties. Only use the methods listed in this note or on the specified website. After adding (us) in Tox or Session, please wait for your request to be processed and stay online. If you do not receive a reply within 36 hours, create another account and contact us again. In your first message in chat, immediately provide your ID from the note and the name of your organization. Assign one person as contact responsible for all negotiations. Do not create multiple chats.
README-GENTLEMEN.txt
[snip] = YOUR ID Gentlemen, your network is under our full control. All your files are now encrypted and inaccessible. 1. Any modification of encrypted files will make recovery impossible. 2. Only our unique decryption key and software can restore your files. Brute-force, RAM dumps, third-party recovery tools are useless. It’s a fundamental mathematical reality. Only we can decrypt your data. 3. Law enforcement, authorities, and “data recovery” companies will NOT help you. They will only waste your time, take your money, and block you from recovering your files — your business will be lost. 4. Any attempt to restore systems, or refusal to negotiate, may lead to irreversible wipe of all data and your network. 5. We have exfiltrated all your confidential and business data (including NAS, clouds, etc). If you do not contact us, it will be published on our leak site and distributed to major hack forums and social networks. TOX CONTACT - RECOVER YOUR FILES Contact us (add via TOX ID): F8E24C7F5B12CD69C44C73F438F65E9BF560ADF35EBBDF92CF9A9B84079F8F04060FF98D098E Download Tox messenger: https://tox.chat/download.html COOPERATE TO PREVENT DATA LEAK (239 HOURS LEFT) Check our blog: http://tezwsse5czllksjb7cwp65rvnk4oobmzti2znn42i43bjdfd2prqqkad.onion/ Download Tor browser: https://www.torproject.org/download/ Any other means of communication are fake and may be set up by third parties. Only use the methods listed in this note or on the specified website.
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (1040)
Search, filter and paginate the victim timeline for Thegentlemen. Showing 401–500 of 1040.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Lopes Law id30490 View details | United States | Finance / Legal / Insurance | — | |
|
***.com zoominfo.com/c/lopes-law-llc/449811320 Lopes Law LLC is a Philadelphia-based law firm founded by Anthony Lopes that specializes in franchise law, representing both franchisees and franchisors nationwide. The firm provides comprehensive legal services including Franchise Disclosure Document (FDD) reviews, franchise agreement negotiations, and dispute resolution using transparent flat-fee pricing. In addition to franchise expertise, the practice acts as fractional general counsel for businesses and offers specialized tax law services to help companies navigate complex legal landscapes |
|||||
| Ransomware | Carita id30491 View details | France | Retail / E-commerce | — | |
|
Carita.com operates in the retail and e-commerce sector, offering various products to customers in France. As an e-commerce company, carita.com provides online shopping experiences, leveraging digital platforms to reach its customer base. Carita.com was listed as a ransomware victim associated with thegentlemen |
|||||
| Ransomware | Carita id30491 View details | France | Retail / E-commerce | — | |
|
***.com zoominfo.com/c/carita/358348689 Carita is a prestigious French luxury skincare brand founded in 1945, renowned for its professional-grade beauty treatments and high-end cosmetics. Now part of L'Oréal's Luxury Division following its acquisition from Shiseido in 2022, the brand operates globally with a focus on exceptional skincare rituals and personalized beauty experiences. Available in over 130 countries, Carita combines innovative formulations with artisanal expertise, generating annual revenue in the range of $9-10 million for its core operations |
|||||
| Ransomware | BDO Greece id30492 View details | Greece | Finance / Legal / Insurance | — | |
|
BDO Greece is a financial and legal services provider based in Greece, offering audit, tax, and advisory services to clients. As a member of the global BDO network, the firm operates in the finance, legal, and insurance sectors. BDO Greece was listed as a ransomware victim associated with thegentlemen |
|||||
| Ransomware | BDO Greece id30492 View details | Greece | Finance / Legal / Insurance | — | |
|
***.gr zoominfo.com/c/bdo-certified-public-accountants-sa/372555588 BDO Greece is a leading Athens-based accounting, tax, and advisory firm that operates as a member of the global BDO network. The company provides comprehensive audit, assurance, and business consulting services to a diverse range of industries, including real estate, hospitality, and the public sector. Employing between 50 and 200 professionals, the firm generates an estimated annual revenue of over $23 million while helping clients navigate complex financial and regulatory landscapes |
|||||
| Ransomware | Dash Door Glass id30493 View details | United States | IT | — | |
|
Dashdoor.com is an IT company based in the United States, providing various services within the IT sector. As a US-based entity, dashdoor.com operates in a highly competitive market, offering solutions to its clients. Dashdoor.com was listed as a ransomware victim associated with thegentlemen |
|||||
| Ransomware | Dash Door Glass id30493 View details | United States | IT | — | |
|
***.com Dash Door & Glass is a prominent commercial contractor and facility support specialist headquartered in Doral, Florida, with a rich history dating back to 1955. The company specializes in the supply, installation, and maintenance of commercial doors, glass, and architectural hardware for large-scale construction projects across South Florida. Operating with a dedicated team of professionals, the firm has established itself as a major industry player, generating an impressive annual revenue of approximately $113.3 million |
|||||
| Ransomware | Shamrock Holdings Inc. id30327 View details | United States | IT | — | |
|
Zoominfo is a leading provider of go-to-market intelligence, offering a platform that delivers contact and company data to businesses. Based in the US, the company operates in the IT sector, helping organizations with sales, marketing, and recruiting efforts. Zoominfo was listed as a ransomware victim associated with thegentlemen |
|||||
| Ransomware | Shamrock Holdings Inc. id30327 View details | United States | IT | — | |
|
https://en.wikipedia.org/wiki/Shamrock_Holdings https://www.***.com/c/shamrock-holdings-inc/102187761 https://www.***.com/c/shamrock-capital-advisors-llc/80380310 https://www.shamrock.com/ Shamrock Holdings, Inc. is an investment firm founded by Roy E. Disney in 1978, primarily serving the investment needs of the Disney Family. The company emphasizes integrity, responsibility, and transparency in its operations. In addition to its investment activities, Shamrock manages various real estate investment programs through a subsidiary. Its intended clients include members of the Roy E. Disney Family and other potential investors in real estate. Assets Under Management: The firm manages over $6.6B in assets across entertainment IP, media rights, and private equity . Included 2021-2026 Stanley Gold inbox(80778) and sent(21617) |
|||||
| Ransomware | Medic Rescue id30328 View details | United States | NGOs / Associations | — | |
|
Medic Rescue is a US-based non-governmental organization operating in the healthcare sector, providing medical rescue services. The organization is part of the NGOs and associations sector, offering various services to the community. Medic Rescue was listed as a ransomware victim associated with thegentlemen |
|||||
| Ransomware | Medic Rescue id30328 View details | United States | NGOs / Associations | — | |
|
https://www.***.org/ https://www.zoominfo.com/c/medic-rescue/47367866 Medic Rescue Services has been providing trusted emergency medical services to Beaver County since 1978. They offer a range of services including on-site emergency care, non-emergency transports, stretcher van trips, and wheelchair van services, all available 24/7. Their dedicated team and extensive fleet ensure swift and effective responses to medical needs. Medic Rescue aims to prioritize health and safety while fostering community trust through their reliable service |
|||||
| Ransomware | LogiQuip id30329 View details | United Kingdom | Manufacturing / Engineering | — | |
|
Logiquip.com is a company operating in the manufacturing and engineering sector, based in the United Kingdom. The company likely provides equipment or services related to its sector. Logiquip.com was listed as a ransomware victim associated with thegentlemen |
|||||
| Ransomware | LogiQuip id30329 View details | United Kingdom | Manufacturing / Engineering | — | |
|
***.com zoominfo.com/c/logiquip/146752157 LogiQuip, founded in 1992, is a specialized manufacturer providing inventory management and storage solutions exclusively for the healthcare industry.They design innovative systems, such as ParWire shelving, to solve complex supply chain and distribution issues in hospitals.Ultimately, their products help medical professionals save valuable time on inventory tasks so they can focus on patient care |
|||||
| Ransomware | Virginia Historical Society id30330 View details | United States | NGOs / Associations | — | |
|
Virginiahistory.org is a non-profit organization based in the United States, operating in the NGOs and associations sector. The organization is dedicated to collecting, preserving, and interpreting the state's history. Virginiahistory.org offers various resources, including historical publications, educational programs, and exhibitions. It was listed as a ransomware victim associated with thegentlemen |
|||||
| Ransomware | Virginia Historical Society id30330 View details | United States | NGOs / Associations | — | |
|
***.org zoominfo.com/c/virginia-historical-society/184942664 is the digital platform for the Virginia Museum of History & Culture, owned and operated by the Virginia Historical Society, a private non-profit established in 1831.It is uniquely positioned as the only museum that presents all of Virginia's history under one roof, covering all centuries, regions, and topics.The organization connects people to America's past through its exhibitions, educational programs, and extensive research collections, inspiring future generations |
|||||
| Ransomware | Quanterm Logistics Sdn Bhd id30331 View details | Malaysia | IT | — | |
|
Quanterm.com is an IT company based in Malaysia, providing various IT services. The company operates in the IT sector, offering its services to clients. Quanterm.com was listed as a ransomware victim associated with thegentlemen |
|||||
| Ransomware | Quanterm Logistics Sdn Bhd id30331 View details | Malaysia | IT | — | |
|
***.com zoominfo.com/c/quanterm-logistics-sdn-bhd/346750206 Quanterm Logistics, founded in 1992 and headquartered in Malaysia, is a leading freight forwarding and total logistics provider in the Asia Pacific region.Starting as an international LCL consolidator, the company has expanded to offer comprehensive supply chain solutions including warehousing, distribution, and fleet management.Today, the organization serves both domestic and international markets through a wide network of offices across Malaysia, Vietnam, Australia, and other countries |
|||||
| Ransomware | Spedidam id30332 View details | France | Services | — | |
|
Spedidam.fr is a French company operating in the services sector. The company is based in France and provides various services to its clients. Spedidam.fr was listed as a ransomware victim associated with thegentlemen |
|||||
| Ransomware | Spedidam id30332 View details | France | Services | — | |
|
***.fr Spedidam, founded in 1959 by five musical performers, is a French collective management organization that protects performers' neighboring rights.The organization manages the collection and distribution of royalties for performing artists while supporting artistic and cultural initiatives.Based in Paris, it serves as one of France's key institutions for managing intellectual property rights in music and dance |
|||||
| Ransomware | hiddeenn id30333 View details | Other | — | ||
|
Hiddeenn operates in the other sector, providing unspecified offerings. The entity's location and specific services are not well-documented. Hiddeenn was listed as a ransomware victim associated with thegentlemen |
|||||
| Ransomware | hiddeenn id30333 View details | Other | — | ||
|
hidddenn |
|||||
| Ransomware | Arabia Falcon Insurance Company SAOG id30334 View details | Oman | Finance / Legal / Insurance | — | |
|
Afic.om is an entity operating in the finance, legal, and insurance sector in Oman, providing various services to its clients. The company's specific offerings and operations are not publicly disclosed, but it is known to be part of the country's financial and legal infrastructure. Afic.om was listed as a ransomware victim associated with thegentlemen |
|||||
| Ransomware | Arabia Falcon Insurance Company SAOG id30334 View details | Oman | Finance / Legal / Insurance | — | |
|
***.om zoominfo.com/c/arabia-falcon-insurance-company-saog/447137751 Arabia Falcon Insurance Company (AFIC), is a leading insurance provider in Oman formed by the historic merger of two successful local insurers.The company underwrites a comprehensive range of general, motor, medical, and life insurance products for individuals and businesses.Headquartered in Muscat, AFIC has firmly established itself as a trusted and prominent name in the Sultanate's insurance sector |
|||||
| Ransomware | Ce Ratp Comite D entreprise Ratp id30335 View details | France | Other | — | |
|
Ceratp.fr is a French entity operating in the other sector, providing various offerings to its clients. Located in France, ceratp.fr serves its customers with a range of services. Ceratp.fr was listed as a ransomware victim associated with thegentlemen |
|||||
| Ransomware | Ce Ratp Comite D entreprise Ratp id30335 View details | France | Other | — | |
|
***.fr zoominfo.com/c/ce-ratp-comité-dentreprise-ratp/1315531566 digital platform of the RATP Works Council, dedicated exclusively to employees of the Paris public transport operator and their beneficiaries.It provides comprehensive services for social and cultural activities, allowing members to book vacations, register for summer camps, and access exclusive leisure events.Based in Fontenay-sous-Bois, the platform serves as a central hub for managing employee benefits and corporate perks |
|||||
| Ransomware | Keifert id30336 View details | Germany | Manufacturing / Engineering | — | |
|
Keifert.de is a company based in Germany, operating in the manufacturing and engineering sector. The company likely provides various products and services related to its sector. Keifert.de was listed as a ransomware victim associated with thegentlemen |
|||||
| Ransomware | Keifert id30336 View details | Germany | Manufacturing / Engineering | — | |
|
***.de zoominfo.com/c/keifert-gmbh/429980133 Keifert GmbH master-certified building cleaning company based in Schallstadt, Germany, with over 35 years of industry experience.They offer a comprehensive range of professional services, including office, industrial, and specialized cleaning, as well as janitorial services across the Southern Baden region.As a quality-focused enterprise, the company is certified according to DIN EN ISO 9001 and 14001 standards, ensuring reliable and environmentally conscious solutions for their clients |
|||||
| Ransomware | Kosmos id30337 View details | Germany | IT | — | |
|
Kosmos.de is an IT company based in Germany, providing various IT services. The company operates in the IT sector, offering its services to clients in DE. Kosmos.de was listed as a ransomware victim associated with thegentlemen |
|||||
| Ransomware | Kosmos id30337 View details | Germany | IT | — | |
|
***.de zoominfo.com/c/kosmos/470278755 Franckh-Kosmos Verlags-GmbH & Co. KG, a prominent media publishing house based in Stuttgart, Germany.Founded in 1822 by Johann Friedrich Franckh, the company is one of the leading publishers of guidebooks, children's books, board games, and educational experiment kits.It successfully combines long-standing tradition with modern trends to offer engaging products for children, families, and hobbyists |
|||||
| Ransomware | EBNY Development id30338 View details | Egypt | Retail / E-commerce | — | |
|
Ebny.com.eg is an e-commerce platform based in Egypt, operating in the retail sector and offering various products to customers. As an online shopping destination, it provides a range of goods and services to the Egyptian market. Ebny.com.eg was listed as a ransomware victim associated with thegentlemen. |
|||||
| Ransomware | EBNY Development id30338 View details | Egypt | Retail / E-commerce | — | |
|
***.com.eg Founded in 2012, EBNY Development is a pioneering real estate company focused on redefining the property market in Egypt and beyond. They create innovative and functional projects that combine elegant designs with thoughtful planning to elevate daily living and lifestyles. Ultimately, the company is dedicated to delivering long-lasting value and building a brighter, sustainable future for its clients |
|||||
| Ransomware | Tonnies Group id30339 View details | Germany | Agriculture / Food | — | |
|
Toennies.de is a German company operating in the agriculture and food sector, offering various products and services. The company is based in Germany and is involved in the production and distribution of food products. Toennies.de was listed as a ransomware victim associated with thegentlemen |
|||||
| Ransomware | Tonnies Group id30339 View details | Germany | Agriculture / Food | — | |
|
***.de zoominfo.com/c/tönnies-group/427095219 Founded in 1971 as a family-owned business, the Tönnies Group is a leading German meat processing company headquartered in Rheda-Wiedenbrück.As a major global player in the food industry, it specializes in the slaughtering, butchering, and processing of pork and beef, generating around 5 billion euros in annual turnover with over 8,000 employees.Notably, the holding company is rebranding to "Premium Food Group" starting in 2025 to emphasize its focus on sustainable food solutions |
|||||
| Ransomware | Automovil Supply S.A id30340 View details | Paraguay | Retail / E-commerce | — | |
|
Supply.com.py operates in the retail and e-commerce sector in Paraguay, providing various products and services to customers. As an e-commerce platform, it likely offers a range of goods and services online. Supply.com.py was listed as a ransomware victim associated with thegentlemen |
|||||
| Ransomware | Automovil Supply S.A id30340 View details | Paraguay | Retail / E-commerce | — | |
|
***.com.py zoominfo.com/c/automóvil-supply/405948730 Automovil Supply S.A., accessible via ***.com.py, is a prominent Paraguayan chain of auto parts stores founded on August 10, 1955.With over 70 years of experience in the automotive industry, the company employs between 200 and 500 staff members and operates multiple retail branches across Paraguay.Known for its slogan "Over 70 years moving the country," it serves as a major importer and distributor of motor vehicle parts in the region |
|||||
| Ransomware | Excel Cell Electronic id30341 View details | Taiwan, Province of China | Manufacturing / Engineering | — | |
|
Ece.com.tw is a company based in Taiwan, operating in the manufacturing and engineering sector. The company likely provides various products and services related to engineering and manufacturing to its clients. Ece.com.tw was listed as a ransomware victim associated with thegentlemen |
|||||
| Ransomware | Excel Cell Electronic id30341 View details | Taiwan, Province of China | Manufacturing / Engineering | — | |
|
***.com.tw zoominfo.com/c/excel-cell-electronic-co-ltd/372144382 Excel Cell Electronic Co., Ltd. (ECE), founded in 1981 and headquartered in Taichung, Taiwan, is a prominent manufacturer of electronic components.The publicly traded company specializes in producing DIP switches, micro switches, relays, terminal blocks, connectors, and resettable fuses for global markets.ECE focuses heavily on product innovation and process integration to serve as a reliable strategic partner in the fast-paced electronics industry |
|||||
| Ransomware | Mercado Libre id30342 View details | Argentina | Retail / E-commerce | — | |
|
Mercadolibre.com.ar is a prominent e-commerce website operating in Argentina, offering a wide range of products and services to its customers in the retail sector. As a leading online marketplace, it provides a platform for buyers and sellers to interact and conduct transactions. Mercadolibre.com.ar was listed as a ransomware victim associated with thegentlemen |
|||||
| Ransomware | Mercado Libre id30342 View details | Argentina | Retail / E-commerce | — | |
|
***.com.ar zoominfo.com/c/mercadolibre-srl/425378760 Argentine platform of MercadoLibre, the undisputed leader in Latin American e-commerce and fintech, founded in 1999 by Marcos Galperin. It operates a massive online marketplace integrated with a powerful ecosystem of services, including Mercado Pago for digital payments and Mercado Envíos for logistics. As a cornerstone of Argentina's digital economy, it connects millions of buyers and sellers, driving both retail innovation and financial inclusion across the nation |
|||||
| Ransomware | CSIR Structural Engineering Research Centre id30343 View details | India | Research | — | |
|
Serc.res.in is a research entity based in India, operating in the research sector. The organization provides various research-related offerings. Serc.res.in was listed as a ransomware victim associated with thegentlemen |
|||||
| Ransomware | CSIR Structural Engineering Research Centre id30343 View details | India | Research | — | |
|
***.res.in zoominfo.com/c/csir-structural-engineering-research-centre/372543677 CSIR-Structural Engineering Research Centre (CSIR-SERC), a premier national laboratory established in 1965 and located in Chennai, India.Operating under the Council of Scientific and Industrial Research, the institute is dedicated to advanced research in structural engineering, materials science, and structural health monitoring.The center plays a crucial role in developing innovative construction technologies and providing specialized testing services to support India's infrastructure development |
|||||
| Ransomware | Jump Solutions Inc id30344 View details | Philippines | IT | — | |
|
Jumpsolutions.ph is an IT company based in the Philippines, providing various IT services. The company operates in the IT sector, offering solutions to clients in the country. Jumpsolutions.ph was listed as a ransomware victim associated with thegentlemen |
|||||
| Ransomware | Jump Solutions Inc id30344 View details | Philippines | IT | — | |
|
***.ph zoominfo.com/c/jump-solutions-inc/450178976 Filipino-owned IT solutions provider and system integrator based in Makati City, Metro Manila.The company specializes in delivering comprehensive, end-to-end IT solutions, including network infrastructure assessments, IT consultancy, and risk management.As a trusted technology partner, they focus on providing future-ready and secure technologies that empower businesses across various industries |
|||||
| Ransomware | MBT Energy id30345 View details | Germany | Energy | — | |
|
mbt-energy.com is an energy sector company based in Germany, providing various energy-related services. The company operates in the energy sector, catering to the needs of its customers in Germany. mbt-energy.com was listed as a ransomware victim associated with thegentlemen |
|||||
| Ransomware | MBT Energy id30345 View details | Germany | Energy | — | |
|
***.com zoominfo.com/c/mibet-energy/357309481 Xiamen Mibet New Energy Co., Ltd., is a high-tech enterprise based in China that specializes in one-stop solar mounting solutions and PV racking systems.The company manufactures a comprehensive range of structures for ground, rooftop, floating, tracking, carport, and agricultural solar applications. Holding over 200 global patents and an annual production capacity of 20GW+, Mibet exports its internationally certified products to more than 100 countries worldwide |
|||||
| Ransomware | Pro-Tech Technology id30347 View details | Singapore | Energy | — | |
|
ptt-asia.com is a company based in Singapore, operating in the energy sector. The company's activities and offerings are focused on this domain. ptt-asia.com was listed as a ransomware victim associated with thegentlemen |
|||||
| Ransomware | Pro-Tech Technology id30347 View details | Singapore | Energy | — | |
|
***.com Pro-Tech Technology (Asia) Limited,leading IT solutions provider established in 2004 with offices in Hong Kong.Operating in the Information Technology & Services industry, the company focuses on delivering secure, effective, and cost-effective IT solutions and services to its clients .With a workforce of up to 200 employees, PTT strives to provide stable technological infrastructure and support across the Asian marke |
|||||
| Ransomware | Pro-Tech Technology id30347 View details | Hong Kong | Energy | — | |
|
***.com Pro-Tech Technology (Asia) Limited,leading IT solutions provider established in 2004 with offices in Hong Kong.Operating in the Information Technology & Services industry, the company focuses on delivering secure, effective, and cost-effective IT solutions and services to its clients .With a workforce of up to 200 employees, PTT strives to provide stable technological infrastructure and support across the Asian marke |
|||||
| Ransomware | Technical Solutions Group id30348 View details | United States | IT | — | |
|
Tsgpc.com operates in the IT sector, providing services in the United States. As a company in the IT industry, tsgpc.com likely offers a range of technology-related services. Tsgpc.com was listed as a ransomware victim associated with thegentlemen |
|||||
| Ransomware | Technical Solutions Group id30348 View details | United States | IT | — | |
|
***.com zoominfo.com/c/medical-data-rx/346985484 Technical Solutions Group, LLC, an IT services company headquartered in Gladwin, Michigan, which also operates the specialized division Medical Data Rx.The organization provides comprehensive technology solutions, including networking, data backup, and hardware services, assisting both small businesses and medical professionals across the United States and Canada.As a diversified technology services provider, the company focuses on delivering reliable technical support and tailored IT management to its clients |
|||||
| Ransomware | Keywest Projects id30178 View details | Canada | Construction / Real Estate | — | |
|
Keywestprojects.ca is a Canadian company operating in the construction and real estate sector, providing services related to these fields in Canada. The company's specific offerings may include construction management, real estate development, and related services. Keywestprojects.ca was listed as a ransomware victim associated with thegentlemen |
|||||
| Ransomware | Keywest Projects id30178 View details | Canada | Construction / Real Estate | — | |
|
***.ca zoominfo.com/c/keywest-projects-ltd/354074136 KeyWest Projects Ltd. is a Canadian EPCM (Engineering, Procurement, Construction Management) company headquartered in Calgary, Alberta. It specializes in full-cycle project delivery for the energy sector — including oil and gas facilities, pipelines, and industrial infrastructure — primarily across Western Canada. The firm is recognized for its integrated, client-driven approach that emphasizes safety, efficiency, and technical reliability on complex energy projects |
|||||
| Ransomware | International Freight Services id30179 View details | United States | IT | — | |
|
ifs-sfo.com is an IT company based in the United States, operating in the information technology sector. The company likely provides various IT services, although specific details about its offerings are not readily available. ifs-sfo.com was listed as a ransomware victim associated with thegentlemen |
|||||
| Ransomware | International Freight Services id30179 View details | United States | IT | — | |
|
***.com zoominfo.com/c/ifs-sfocom/348198952 IFS (International Freight Services, Inc.) is a logistics company headquartered at San Francisco International Airport (SFO). It provides international air and ocean freight forwarding, customs brokerage, warehousing, and end-to-end supply chain solutions. With decades of experience, IFS specializes in time-critical and high-touch cargo, serving industries from technology and life sciences to automotive and retail |
|||||
| Ransomware | Royal Thai Navy Housing Cooperative id30180 View details | Thailand | Other | — | |
|
Kehanavycoop.com is an entity based in Thailand, operating in the other sector. The company's specific offerings are not well-documented, but it is known to be a part of the diverse Thai business landscape. Kehanavycoop.com was listed as a ransomware victim associated with thegentlemen |
|||||
| Ransomware | Royal Thai Navy Housing Cooperative id30180 View details | Thailand | Other | — | |
|
***.com Royal Thai Navy Housing Cooperative Limited, a service organization based in Bangkok, Thailand.It primarily manages housing projects like "Navy Place," offering residential units for sale and rent to naval personnel and members.Additionally, the cooperative provides financial services such as member shares, loans, and deposits, alongside educational scholarships for members children |
|||||
| Ransomware | CTM India Limited motherson INDIA id30181 View details | India | Finance / Legal / Insurance | — | |
|
Dun & Bradstreet, or dnb.com, is a leading global provider of business decisioning data and analytics, operating in the finance, legal, and insurance sectors, with operations in India. The company offers a range of services, including data and analytics, as well as business intelligence solutions. dnb.com was listed as a ransomware victim associated with thegentlemen |
|||||
| Ransomware | CTM India Limited motherson INDIA id30181 View details | India | Finance / Legal / Insurance | — | |
|
***.com/business-directory/company-profiles.ctm_india_limited.c67e34c4f71f7ed11aaf1dc39e0e10a6.html CTM India Limited is located in New Delhi, Delhi, India and is part of the Metalworking Machinery Manufacturing industry. CTM India Limited is associated with the global Motherson Group, focusing on producing specialized equipment and forms essential for industrial manufacturing processes. The company is led by key principal Bimal Dhar and operates within the broader machinery manufacturing sector |
|||||
| Ransomware | Hooke Laboratories id30182 View details | United States | IT | — | |
|
Hookelabs.com is an IT company based in the United States, providing various services within the IT sector. As a US-based entity, hookelabs.com operates in a highly competitive market, offering its expertise to clients. Hookelabs.com was listed as a ransomware victim associated with thegentlemen |
|||||
| Ransomware | Hooke Laboratories id30182 View details | United States | IT | — | |
|
***.com zoominfo.com/c/hooke-laboratories-inc/345976723 Hooke Laboratories is a biotechnology company based in Lawrence, Massachusetts, specializing in biological products for medical and pharmaceutical research.They are best known for their "Hooke Kits™," which are ready-to-use emulsions used to induce animal models of autoimmune diseases, such as EAE, in laboratory rodents.The company operates strictly as a preclinical research supplier, working only with rodents and in vitro, and does not offer any products for human clinical use |
|||||
| Ransomware | GIA Partners id30183 View details | United States | IT | — | |
|
Giallc.com is an IT company based in the United States, providing various IT services. The company operates in the IT sector, offering services to its clients. Giallc.com was listed as a ransomware victim associated with thegentlemen |
|||||
| Ransomware | GIA Partners id30183 View details | United States | IT | — | |
|
***.com zoominfo.com/c/gia-partners-llc/347817491 GIA Partners, LLC is a New York-based registered investment advisor specializing in fixed income strategies and credit analysis .The firm focuses on diversified portfolios, including core fixed income, high yield, and emerging market debt, leveraging the extensive experience of its investment team.With over $1 billion in assets under management, GIA emphasizes that credit risk is well-compensated and diversifiable to generate excess returns for its clients |
|||||
| Ransomware | Rowley Properties id30184 View details | United Kingdom | Construction / Real Estate | — | |
|
Rowleyproperties.com is a company operating in the construction and real estate sector, based in the United Kingdom. The company likely provides services related to property development, management, and sales. Rowleyproperties.com was listed as a ransomware victim associated with thegentlemen. |
|||||
| Ransomware | Rowley Properties id30184 View details | United Kingdom | Construction / Real Estate | — | |
|
***.com zoominfo.com/c/rowley-properties/1117416022 Rowley Properties is a multi-generational, family-owned real estate company based in Issaquah, Washington, founded in 1954. The firm specializes in owning, developing, and managing approximately 80 acres of commercial and residential properties, including office spaces, apartments, and storage facilities in downtown Issaquah. They are deeply committed to local community development, focusing on long-term projects that help businesses succeed and families thrive |
|||||
| Ransomware | Canada Wide Media id30185 View details | Canada | Finance / Legal / Insurance | — | |
|
Canadawide.com operates within the finance, legal, and insurance sector in Canada, providing various services to its clients. The company's presence in the Canadian market is notable, given its focus on financial and legal services. Canadawide.com was listed as a ransomware victim associated with thegentlemen |
|||||
| Ransomware | Canada Wide Media id30185 View details | Canada | Finance / Legal / Insurance | — | |
|
***.com zoominfo.com/c/canada-wide-media-ltd/24612070 Canada Wide Media is Western Canada's leading independent publishing and custom content creation company, headquartered in Burnaby, British Columbia.They produce over 48 premium print and digital publications, such as BC Business and TV Week, reaching an audience of over 6 million readers.The firm specializes in audience engagement, custom publishing, and prestige media solutions tailored for various industries |
|||||
| Ransomware | ErgoMed id30186 View details | United Kingdom | Healthcare / Pharma | — | |
|
Ergomed.net is a UK-based company operating in the healthcare and pharmaceutical sector, providing services and offerings to clients. As a healthcare and pharma company, ergomed.net is involved in various aspects of the industry, including research and development. It was listed as a ransomware victim associated with thegentlemen |
|||||
| Ransomware | ErgoMed id30186 View details | United Kingdom | Healthcare / Pharma | — | |
|
***.net ErgoMed Work Systems is a US-based occupational health and employment testing company that has been providing loss control programs since 1992.They specialize in physical demand simulation testing, musculoskeletal evaluations, and post-offer employment screening to help businesses and HR managers reduce workplace injuries |
|||||
| Ransomware | MBO GmbH id30187 View details | Germany | Manufacturing / Engineering | — | |
|
MBO GmbH is a company based in Germany, operating in the manufacturing and engineering sector. The company likely provides various products and services related to these fields. MBO GmbH was listed as a ransomware victim associated with thegentlemen |
|||||
| Ransomware | MBO GmbH id30187 View details | Germany | Manufacturing / Engineering | — | |
|
***.com MBO GmbH is a German surface technology company based in Roding, serving as the in-house surface treatment unit for the Mühlbauer Parts & Systems Group.With over 40 years of experience, they specialize in various advanced coating processes, including electroplating, powder coating, and painting.The company provides comprehensive technical advice and surface finishing solutions that are directly integrated with their parent company's production lines |
|||||
| Ransomware | Meccanica Gn id30188 View details | Italy | Manufacturing / Engineering | — | |
|
Meccanicagn.com is an Italian company operating in the manufacturing and engineering sector, providing various services and products to its clients. The company is based in Italy and focuses on delivering high-quality solutions to its customers. Meccanicagn.com was listed as a ransomware victim associated with thegentlemen |
|||||
| Ransomware | Meccanica Gn id30188 View details | Italy | Manufacturing / Engineering | — | |
|
***.com zoominfo.com/c/meccanica-gn/368731563 Meccanica GN is an Italian precision manufacturing company based in Carpi, specializing in high-accuracy machining like milling, turning, and grinding.With over two decades of experience, they produce critical components for demanding sectors, including Formula 1 motorsport, aerospace, automotive, and biomedical.The company is recognized for its advanced technology, strict quality assurance, and commitment to maximum performance |
|||||
| Ransomware | Al Dhow Group id30189 View details | United Arab Emirates | Transportation / Travel / Logistics | — | |
|
Al-dhow.com is a company operating in the transportation, travel, and logistics sector in the United Arab Emirates. The company likely provides services related to shipping, cargo, and travel arrangements, given its name and sector. Al-dhow.com was listed as a ransomware victim associated with thegentlemen |
|||||
| Ransomware | Al Dhow Group id30189 View details | United Arab Emirates | Transportation / Travel / Logistics | — | |
|
***.com zoominfo.com/c/al-dhow/345585723 Dhow International Holding is a diversified group of companies with a portfolio spanning high-growth and high-impact industries across the GCC region.Their extensive operations encompass a wide range of sectors, including engineering, architectural solutions, hospitality, food & beverage, logistics, healthcare, and venture capital. The group is committed to delivering integrated, end-to-end services while fostering long-term sustainable growth across all its businesses |
|||||
| Ransomware | Beran Concrete id30190 View details | Czechia | Construction / Real Estate | — | |
|
Beranconcrete.com operates in the construction and real estate sector in the Czech Republic, providing various services related to concrete and construction projects. The company's offerings likely include concrete production, construction materials, and related services. Beranconcrete.com was listed as a ransomware victim associated with thegentlemen |
|||||
| Ransomware | Beran Concrete id30190 View details | Czechia | Construction / Real Estate | — | |
|
***.com zoominfo.com/c/beran-concrete-inc/4424481 Beran Concrete is a premier concrete construction and ready-mix supplier serving commercial and residential projects across Wichita, Kansas, and the broader Midwest.Founded in 1980, the company is driven by a deep pride in quality workmanship and a proven ability to consistently meet strict client deadlines.To support its continued growth and better serve local communities, the business actively expands its regional footprint by integrating additional ready-mix plants |
|||||
| Ransomware | BDS CZ id30191 View details | Czechia | Finance / Legal / Insurance | — | |
|
BDS CZ operates in the finance, legal, and insurance sector in the Czech Republic, providing various services to clients. The company is based in the Czech Republic and serves the local market with its financial and legal expertise. It was listed as a ransomware victim associated with thegentlemen |
|||||
| Ransomware | BDS CZ id30191 View details | Czechia | Finance / Legal / Insurance | — | |
|
***.cz BDS CZ is a Prague-based real estate agency that offers comprehensive property services, including Airbnb management, interior renovations, and investment consulting.The company's name originates from the Vietnamese abbreviation for real estate, indicating its strong focus on serving the local Vietnamese community and investors.Operating from its headquarters in Prague's historic Old Town, the agency assists clients in maximizing their property value and managing real estate portfolios |
|||||
| Ransomware | Stadttheater Giessen id30192 View details | Germany | Hospitality / Food & Beverage / Tourism | — | |
|
Stadttheater Giessen is a theater located in Giessen, Germany, offering various performances and events in the hospitality and tourism sector. As a cultural institution, it provides entertainment and recreational activities to the local community. Stadttheater Giessen was listed as a ransomware victim associated with thegentlemen |
|||||
| Ransomware | Stadttheater Giessen id30192 View details | Germany | Hospitality / Food & Beverage / Tourism | — | |
|
***.de rocketreach.co/stadttheater-giessen-gmbh-profile_b40b4590ff936dde Stadttheater Gießen is a prominent multi-genre municipal theatre in Germany, renowned for its striking Art Nouveau (Jugendstil) building constructed in 1907. As the cultural heart of the Mittelhessen region, it offers a diverse repertoire encompassing opera, musicals, drama, and classical concerts. The theatre is celebrated for its high-quality productions, blending traditional classics with innovative contemporary works for audiences of all ages |
|||||
| Ransomware | Gegenbauer Elektrotechnik id30193 View details | Austria | IT | — | |
|
Gegenbauer-it.at is an Austrian company operating in the IT sector, providing various services. The company is based in Austria and offers IT solutions. Gegenbauer-it.at was listed as a ransomware victim associated with thegentlemen |
|||||
| Ransomware | Gegenbauer Elektrotechnik id30193 View details | Austria | IT | — | |
|
***.at Gegenbauer Elektrotechnik & IT GmbH is a Vienna-based service provider specializing in comprehensive electrical engineering and IT solutions for businesses.Evolving from a sole proprietorship with over 30 years of experience, the company was officially established in 2015 to offer end-to-end planning and implementation.They focus on delivering customized technical infrastructures, professional support, and employee training to meet the diverse needs of their clients |
|||||
| Ransomware | Bell Hardware id30194 View details | United States | Retail / E-commerce | — | |
|
Bellhardware.com operates in the retail and e-commerce sector in the United States, offering various products and services to its customers. As an online retailer, the company provides a platform for customers to purchase hardware and other related items. Bellhardware.com was listed as a ransomware victim associated with thegentlemen |
|||||
| Ransomware | Bell Hardware id30194 View details | United States | Retail / E-commerce | — | |
|
***.com zoominfo.com/c/bell-hardware/353995383 Bell Hardware is a premier supplier of premium commercial doors, frames, and architectural hardware, operating out of seven locations across Oregon and Northern California.They act as a comprehensive one-stop shop for contractors, providing high-quality building products alongside expert on-site installation and modification services.Furthermore, the company partners with design and construction teams during the early planning stages to evaluate project elements and streamline the building process |
|||||
| Ransomware | CHIFENG GOLD SEPON id30195 View details | Lao People's Democratic Republic | IT | — | |
|
lxml.la is an entity operating in the IT sector in LA, providing unspecified services. The entity's name suggests a connection to the IT sector, but specific details about its offerings are not available. lxml.la was listed as a ransomware victim associated with thegentlemen |
|||||
| Ransomware | CHIFENG GOLD SEPON id30195 View details | Lao People's Democratic Republic | IT | — | |
|
***.la zoominfo.com/c/lane-xang-minerals-ltd/1311794256 which operates the major Sepon open-pit and underground gold and copper mine in Savannakhet Province, Laos.As a significant regional employer, the company heavily invests in local workforce development, with 95% of its staff being Lao nationals WILL BE UPDATED! |
|||||
| Ransomware | Natren id30196 View details | United States | Healthcare / Pharma | — | |
|
Natren.com is a US-based company operating in the healthcare and pharmaceutical sector, offering various products and services. The company is involved in the development and distribution of probiotics and other health-related products. Natren.com was listed as a ransomware victim associated with thegentlemen. |
|||||
| Ransomware | Natren id30196 View details | United States | Healthcare / Pharma | — | |
|
***.com zoominfo.com/c/natren-inc/26870087 Natren is a leading manufacturer of premium probiotic supplements with over 30 years of experience, dedicated to improving gut health and overall well-being.Based in California, the company offers a comprehensive range of natural, non-GMO formulas tailored for men, women, children, and even pets.They are highly regarded for their flagship "Healthy Trinity" 3-in-1 system and their strict cold-chain shipping process, which guarantees 100% potency through the expiration date |
|||||
| Ransomware | Au Vieux Campeur id30197 View details | France | Retail / E-commerce | — | |
|
Auvieuxcampeur.fr is a French e-commerce company operating in the retail sector, offering various products to customers in France. As an online retailer, auvieuxcampeur.fr provides a range of goods and services to its customers. Auvieuxcampeur.fr was listed as a ransomware victim associated with thegentlemen |
|||||
| Ransomware | Au Vieux Campeur id30197 View details | France | Retail / E-commerce | — | |
|
***.fr Au Vieux Campeur is a premier French retailer and the leading independent outdoor and sports equipment company in Europe.Founded in Paris in 1941, the brand has expanded from a single historic boutique in the Latin Quarter to nearly 50 stores across France and a robust e-commerce platform.They offer an extensive selection of over 1,500 premium brands, providing specialized clothing and gear for a wide variety of activities including mountaineering, diving, skiing, and trail running |
|||||
| Ransomware | Ayres Carr & Sullivan, P.C. id30198 View details | United States | IT | — | |
|
LinkedIn is a professional networking platform based in the US, operating in the IT sector, offering services for job seekers, recruiters, and businesses to connect and share information. As a leading online platform, LinkedIn provides various tools and features for its users. It was listed as a ransomware victim associated with thegentlemen |
|||||
| Ransomware | Ayres Carr & Sullivan, P.C. id30198 View details | United States | IT | — | |
|
Ayres Carr & Sullivan, P.C. is a longstanding, general civil practice and trial law firm based in Indianapolis, Indiana. Tracing its roots back to 1914, the firm serves clients across the state with a focus on civil litigation, trial practice, and specialized matters including probate, bankruptcy, and corporation law. Primary Location: 251 E. Ohio St., Suite 500, Indianapolis, IN 46204 Primary Practice Areas: Civil Litigation, Trial Practice, Personal Injury, Corporation Law, Probate, and Bankruptcy Key Attorneys: William S. Ayres, John R. Carr III, and Bret Clement https://www.***.com/company/ayres-carr-&-sullivan-pc |
|||||
| Ransomware | Immling id30199 View details | Germany | Retail / E-commerce | — | |
|
Immling.de operates in the retail and e-commerce sector in Germany, offering various products and services to its customers. As an online retailer, immling.de provides a platform for customers to purchase goods and services. Immling.de was listed as a ransomware victim associated with thegentlemen |
|||||
| Ransomware | Immling id30199 View details | Germany | Retail / E-commerce | — | |
|
***.de is the official website for the Immling Festival, a renowned classical music and opera event held annually at Gut Immling in Halfing, Germany. Running primarily from June to August since 1997, it features high-quality opera productions and symphony concerts in a picturesque setting. In 2026, the festival celebrates its 30th anniversary, remaining a major cultural highlight in the Chiemgau region |
|||||
| Ransomware | DHC Corporation id30200 View details | Japan | Retail / E-commerce | — | |
|
DHC Corporation, operating as dhc.co.jp, is a Japanese company primarily engaged in the retail and e-commerce sector, offering various products and services to its customers in Japan. The company's operations include online shopping platforms, providing a range of goods to the Japanese market. DHC Corporation was listed as a ransomware victim associated with thegentlemen |
|||||
| Ransomware | DHC Corporation id30200 View details | Japan | Retail / E-commerce | — | |
|
***.co.jp zoominfo.com/c/dhc-corp/372590440 DHC Corporation, a major Japanese health and beauty company renowned for its dietary supplements, skincare, and cosmetics. The brand is especially famous for its olive oil-based beauty products and high-quality, affordable nutritional supplements. The site serves as a primary hub for consumers to purchase their popular health, wellness, and beauty essentials |
|||||
| Ransomware | Steegaa Interior id30201 View details | United Arab Emirates | Other | — | |
|
Steegaa.com is a company based in the United Arab Emirates, operating in the other sector. The company likely provides various services, although specific details about its offerings are not readily available. Steegaa.com was listed as a ransomware victim associated with thegentlemen. |
|||||
| Ransomware | Steegaa Interior id30201 View details | United Arab Emirates | Other | — | |
|
***.com zoominfo.com/c/steegaa/408684474 Steegaa Interior, a Dutch company based in Helmond specializing in high-end custom interior design and construction.Established in 2000, the firm focuses on designing, manufacturing, and installing bespoke interiors for both private and commercial clients.They are highly regarded for their exceptional craftsmanship, attention to detail, and ability to deliver complete, turnkey interior solutions.Additionally, the company operates as a recognized training center, offering apprenticeships to foster the next generation of skilled interior builders |
|||||
| Ransomware | Indra Group id30202 View details | Spain | IT | — | |
|
Indracompany.com is a company operating in the IT sector, based in Spain. The company provides various IT services and solutions to its clients. Indracompany.com was listed as a ransomware victim associated with thegentlemen. |
|||||
| Ransomware | Indra Group id30202 View details | Spain | IT | — | |
|
***.com zoominfo.com/c/indra-sistemas-sa/136495916 Indra, a leading Spanish multinational technology and consulting company. It specializes in innovative solutions for defense, aerospace, air traffic management, smart mobility, and digital transformation (via its Minsait brand). The company serves as a strategic technological partner for governments and major corporations worldwide, driving modernization and security across critical sectors |
|||||