Ransomware Group intelligence
Thegentlemen
ActiveTrack Thegentlemen with 1098 published victims and 2 known leak locations in a single intelligence view.
Overview
Thegentlemen is tracked by Breach House as a ransomware group with 1098 published victims.
United States is currently the most targeted country in this dataset.
2 known leak locations are currently associated with this group.
Leak Status Distribution
No leak-status data available yet.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (2)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 2 | Onion service | Down checked 1h ago | i2ohjeeqe37jre4f2u7pyq73cbm6lecumdxapkvrlryna6rc3it4zsid.onion |
| Leak location 1 | Onion service | Down checked 1h ago | tezwsse5czllksjb7cwp65rvnk4oobmzti2znn42i43bjdfd2prqqkad.onion |
Top Activity Sectors (20)
- IT 118
- Manufacturing / Engineering 104
- Communication / Marketing 88
- Healthcare / Pharma 68
- Retail / E-commerce 57
- Finance / Legal / Insurance 50
- Construction / Real Estate 48
- Services 44
- Transportation / Travel / Logistics 30
- Not identified 27
- Agriculture / Food 23
- Education 22
- Public Sector 20
- Energy 18
- NGOs / Associations 12
- Hospitality / Food & Beverage / Tourism 12
- Telecommunications 6
- Media / Entertainment 1
- Law Enforcement / Public Sector 1
- Research 1
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Thegentlemen, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: thegentlemen executes PowerShell scripts to run payload logic, disable defenses, and propagate across systems.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: thegentlemen modifies registry run keys and startup locations to maintain persistence after reboots.
What that means: Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: thegentlemen disables or modifies security tools such as EDR and AV processes to hinder incident response.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: thegentlemen deletes Volume Shadow Copies and backup artifacts via system commands to prevent recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1003.001 LSASS Memory Credential Access
What they do: thegentlemen accesses LSASS memory to steal credentials for lateral movement and privilege escalation.
What that means: Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS).
-
T1135 Network Share Discovery Discovery
What they do: thegentlemen uses network share discovery to locate victim file shares and map accessible storage paths for encryption.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: thegentlemen uses SMB/Windows Admin Shares for lateral movement between networked hosts in manufacturing and IT environments.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: thegentlemen encrypts victim files and data stores using ransomware payloads to maximize impact and extortion pressure.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: thegentlemen calls system recovery inhibitors to block restore processes and harden ransomware impact.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
-
T1491.001 Internal Defacement Impact
What they do: thegentlemen performs internal defacement by replacing victim files with ransom notes and altered content.
What that means: An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems.
Tools Observed (64)
▼Software Thegentlemen has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Credential theft
Defense evasion
Discovery
Discovery & enumeration
Exfiltration
LOLBAS (living-off-the-land binaries)
Networking & tunnelling
OffSec
Offensive security tooling
RMM Tools
Remote monitoring & management
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Ransom Notes (3)
▼The note this group leaves on a compromised machine. Click a filename to read it.
README-GENTLEMEN_3.txt
[snip] = YOUR ID Gentlemen, your network has been encrypted. 1. Any modification of encrypted files will make recovery impossible. 2. Only our unique decryption key and software can restore your files. Brute-force, RAM dumps, third-party recovery tools are useless. It’s a fundamental mathematical reality. Only we can decrypt your data. 3. Law enforcement, authorities, and “data recovery” companies will NOT help you. They will only waste your time, take your money, and block you from recovering your files — your business will be lost. 4. Any attempt to restore systems, or refusal to negotiate, may lead to irreversible wipe of all data and your network. 5. We have exfiltrated all your confidential and business data (including NAS, clouds, etc). If you do not contact us, it will be published on our leak site and distributed to major hack forums and social networks. In addition, it will be reported to the relevant data protection authorities and regulators. This may result in official investigations, significant fines, and reputational damage for your company. 6. We guarantee 100% file recovery to their original state, bit by bit. To demonstrate the quality of our work, you can provide three sample files, and we will restore them free of charge. TOX CONTACT - RECOVER YOUR FILES Contact us (add via TOX ID): 13343E50C1B3466F0EA35B5B3E55A044CB7132FD28A8665EFEA0E5848E276D548C21B79F15C2 Download Tox messenger: https://tox.chat/download.html Contact us (add via SimpleX): https://smp14.simplex.im/a#4mlOiePV8NBXOv2QrZ9CaPeRPm1mBUgxn4SdpFnm978 Download SimpleX https://simplex.chat/downloads/ СONTACT TO PREVENT DATA LEAK (7 DAYS BEFORE YOUR COMPANY DATA WILL BE PUBLISHED IN OUR BLOG, WITH 239 HOURS REVEAL TIMER) Check our blog: http://tezwsse5czllksjb7cwp65rvnk4oobmzti2znn42i43bjdfd2prqqkad.onion/ Download Tor browser: https://www.torproject.org/download/ Follow us on X: https://x.com/TheGentlemen26 Clearnet blog link: https://thegentlemen.cc/ Any other means of communication are fake and may be set up by third parties. Only use the methods listed in this note or on the specified website. After adding (us) in Tox or Session, please wait for your request to be processed and stay online. If you do not receive a reply within 36 hours, create another account and contact us again. In your first message in chat, immediately provide your ID from the note and the name of your organization. Assign one person as contact responsible for all negotiations. Do not create multiple chats. We have stolen more than 100 GB of your corporate information from your servers, including critically important data. Your company is facing a massive information security breach. A total data leak has occurred. This greatly increases the risk of colossal financial and reputational losses.
README-GENTLEMEN_2.txt
[snip] = YOUR ID Gentlemen, your network has been encrypted. 1. Any modification of encrypted files will make recovery impossible. 2. Only our unique decryption key and software can restore your files. Brute-force, RAM dumps, third-party recovery tools are useless. It’s a fundamental mathematical reality. Only we can decrypt your data. 3. Law enforcement, authorities, and “data recovery” companies will NOT help you. They will only waste your time, take your money, and block you from recovering your files — your business will be lost. 4. Any attempt to restore systems, or refusal to negotiate, may lead to irreversible wipe of all data and your network. 5. We have exfiltrated all your confidential and business data (including NAS, clouds, etc). If you do not contact us, it will be published on our leak site and distributed to major hack forums and social networks. In addition, it will be reported to the relevant data protection authorities and regulators. This may result in official investigations, significant fines, and reputational damage for your company. 6. We guarantee 100% file recovery to their original state, bit by bit. To demonstrate the quality of our work, you can provide three sample files, and we will restore them free of charge. TOX CONTACT - RECOVER YOUR FILES Contact us (add via TOX ID): 98C132E2B20B531BE6604397D97040C1E9EB42FCE12EDF119BCE8B4031CA5C70DAF5E65FA3C3 Download Tox messenger: https://tox.chat/download.html Contact us (add via Session ID): 05809b2da1d5b1a302f48b5767fd1843d54f3c516f9ab0eb26b544ffa73340292e Download Session https://getsession.org СONTACT TO PREVENT DATA LEAK (7 DAYS BEFORE YOUR COMPANY DATA WILL BE PUBLISHED IN OUR BLOG, WITH 239 HOURS REVEAL TIMER) Check our blog: http://tezwsse5czllksjb7cwp65rvnk4oobmzti2znn42i43bjdfd2prqqkad.onion/ Download Tor browser: https://www.torproject.org/download/ Follow us on X: https://x.com/ Any other means of communication are fake and may be set up by third parties. Only use the methods listed in this note or on the specified website. After adding (us) in Tox or Session, please wait for your request to be processed and stay online. If you do not receive a reply within 36 hours, create another account and contact us again. In your first message in chat, immediately provide your ID from the note and the name of your organization. Assign one person as contact responsible for all negotiations. Do not create multiple chats.
README-GENTLEMEN.txt
[snip] = YOUR ID Gentlemen, your network is under our full control. All your files are now encrypted and inaccessible. 1. Any modification of encrypted files will make recovery impossible. 2. Only our unique decryption key and software can restore your files. Brute-force, RAM dumps, third-party recovery tools are useless. It’s a fundamental mathematical reality. Only we can decrypt your data. 3. Law enforcement, authorities, and “data recovery” companies will NOT help you. They will only waste your time, take your money, and block you from recovering your files — your business will be lost. 4. Any attempt to restore systems, or refusal to negotiate, may lead to irreversible wipe of all data and your network. 5. We have exfiltrated all your confidential and business data (including NAS, clouds, etc). If you do not contact us, it will be published on our leak site and distributed to major hack forums and social networks. TOX CONTACT - RECOVER YOUR FILES Contact us (add via TOX ID): F8E24C7F5B12CD69C44C73F438F65E9BF560ADF35EBBDF92CF9A9B84079F8F04060FF98D098E Download Tox messenger: https://tox.chat/download.html COOPERATE TO PREVENT DATA LEAK (239 HOURS LEFT) Check our blog: http://tezwsse5czllksjb7cwp65rvnk4oobmzti2znn42i43bjdfd2prqqkad.onion/ Download Tor browser: https://www.torproject.org/download/ Any other means of communication are fake and may be set up by third parties. Only use the methods listed in this note or on the specified website.
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (1098)
Search, filter and paginate the victim timeline for Thegentlemen. Showing 1–100 of 1098.
| Type | Target | Discovered | Country | Business Category | Intel Link | Leak status |
|---|---|---|---|---|---|---|
| Ransomware | PharmaEssentia Corporation id32726 View details | Taiwan, Province of China | Healthcare / Pharma | — | — | |
|
pharmaessentia.com operates within the healthcare and pharmaceutical sector, with a primary operational base in Taiwan (TW). The entity represents a healthcare and pharma organization whose digital infrastructure was identified within a threat-intelligence index as a ransomware victim. The association with thegentlemen reflects the threat actor identified in the cataloging context for this listing. This description maintains neutrality regarding specific incident details, as confirmed specifics such as data exfiltration scope, ransom demands, or precise breach timelines are not attributed to this entity in the provided data. The listing type categorizes pharmaessentia.com explicitly as a ransomware victim connected to thegentlemen. |
||||||
| Ransomware | PharmaEssentia Corporation id32726 View details | Taiwan, Province of China | Healthcare / Pharma | — | — | |
|
pharmaessentia.com zoominfo.com/c/pharmaessentia-corp/145441146 PharmaEssentia Taiwanese global biopharma founded in 2003, known for besremi® (ropeginterferon alfa-2b) — the first drug developed in Taiwan ever approved by the FDA (2021) and the only polycythemia vera (PV) therapy approved in both the US and EU. Its innovation: a mono-pegylated long-acting interferon dosed every 2 weeks at home, with disease-modifying potential (reducing JAK2V617F mutant allele frequency) — a premium rare-disease asset vs. hydroxyurea and Jakafi. Financials: $197M+ revenue in 2024 (~89% gross margin), TPEX-listed (6446) with a ~5x stock rally since 2024; next bets: essential thrombocythemia (ET) Phase 3 and myelofibrosis. Bottom line: the Taiwanese biotech that proved a local startup can take a molecule from out-license to FDA approval and global commercialization — a rare-disease champion with an expanding moat. |
||||||
| Ransomware | Air Canada id32727 View details | Canada | Transportation / Travel / Logistics | — | — | |
|
Aircanada.com operates within the Transportation, Travel, and Logistics sector, serving Canadian market contexts with services aligned to passenger and freight mobility workflows. The entity is catalogued in this threat-intelligence index as a ransomware victim associated with thegentlemen, a threat actor identified with Canadian origin. This listing reflects the organization's inclusion in cybersecurity intelligence records documenting ransomware-related activity and its sector exposure. Details regarding specific attack vectors, data handling, or operational impact remain intentionally limited to preserve factual neutrality and avoid unsupported claims about confirmed breach specifics. The entry supports threat-aware monitoring of entities in critical logistics infrastructure. |
||||||
| Ransomware | Air Canada id32727 View details | Canada | Transportation / Travel / Logistics | — | — | |
|
aircanada.com zoominfo.com/c/air-canada/3937344 Revenue $16.5 Billion Air Canada We have taken 51409 critical files! Canada's flag carrier and largest airline — founded in 1937 as Trans-Canada Air Lines, HQ'd in Montréal, ~37,000 employees, 45.3M passengers in 2025, and a founding Star Alliance member. Record revenue: $22.37B CAD in 2025 ($6.27B in Q2 2026 alone, +11%), but a fuel shock (+50.8% per litre) and $388M one-off charges pushed Q2 2026 to a $178M net loss — guidance cut, though load factor (87.5%) and Aeroplan (10M+ members), Cargo (+29%) and Sixth Freedom traffic stay strong. Its moat: the most aggressive fleet renewal in its history — A321XLRs with Canada's first lie-flat seats on a narrowbody, 787-10s and A350-1000s — unlocking "thin" long-haul routes no widebody could fly (Oslo, Shannon, Basel, Dubrovnik, Guangzhou) ahead of Super Bowl 2027 and the LA 2028 Olympics. |
||||||
| Ransomware | Hollard Insurance Group id32651 View details | South Africa | Manufacturing / Engineering | — | — | |
|
hollard.co.za operates within the manufacturing and engineering sector based in South Africa (country code ZA), providing professional services aligned with industrial and technical operations. The entity is cataloged in this threat-intelligence index under the designation ransomware victim, with its associated threat actor and source identified as thegentlemen. This listing reflects the cybersecurity context in which the organization was impacted, emphasizing the threat actor profile without detailing unverified incident specifics such as data exfiltration, ransom demands, or operational disruption. The record serves to inform stakeholders about the exposure profile of this sector-specific entity within the identified threat landscape. It remains a neutral documentation of the association between hollard.co.za and thegentlemen in ransomware incident indexing. |
||||||
| Ransomware | Hollard Insurance Group id32651 View details | South Africa | Manufacturing / Engineering | — | — | |
|
hollard.co.za zoominfo.com/c/the-hollard-insurance-company-ltd/56019572 Hollard is South Africa's largest independent, privately-owned insurance group, founded in 1980 by the Enthoven family, HQ'd in Johannesburg, 4,000+ employees, 6M+ policyholders. Ownership: Enthoven family 57%, B-BBEE group Bushwillow 20%, Tokio Marine ~22.5% (2018, ~$327M); GCR AA(za). Operates in 18 countries on 4 continents via 100+ partnership ventures: Hollard Insure (corporate/broker), Hollard Life Solutions (mass market, prepaid "starter packs" sold like airtime), Hollard International (8 African countries + Philippines). Landmark deals: CommInsure Australia A$625M (2022 — top-5 insurer there, 15-year exclusive bancassurance deal with Commonwealth Bank), and in 2025 Global Alliance Seguros (Mozambique) + Absa Life Botswana. Innovations: HUGinsure (world's first social-impact insurer), insurtech bets (Naked, dotsure). |
||||||
| Ransomware | Drogueria Saporiti Sacifia id32652 View details | Argentina | Retail / E-commerce | — | — | |
|
drogueria-saporiti.com.ar is an entity cataloged as a ransomware victim within the Retail and E-commerce sector, operating from Argentina (AR). The domain name suggests a retail-focused business context, aligning with the sector designation provided. This listing type identifies the entity as having experienced a ransomware incident, with the associated threat actor attributed to thegentlemen. The entry serves as a reference point within the threat-intelligence index for monitoring cyber threats targeting retail and e-commerce operations in the region. drogueria-saporiti.com.ar was listed as a ransomware victim associated with thegentlemen. |
||||||
| Ransomware | Drogueria Saporiti Sacifia id32652 View details | Argentina | Retail / E-commerce | — | — | |
|
drogueria-saporiti.com.ar zoominfo.com/c/drogueria-saporiti-sacifia/462786110 100GB data stolen! Droguería Saporiti is a century-old Argentine pharmaceutical wholesaler and manufacturer, founded in 1901 in Buenos Aires, now run by the Otero Pose family with ~110 employees and 8,700 m² of facilities. It's the silent "backbone" of Argentine pharmacies: 3,500+ products, 7,000+ pharmacy clients, wholesale distribution plus imports/exports of raw materials. Its flagship is the legendary Parafarm brand ("orange line" of galenic essentials — vaseline, Pasta Lassar, Agua de Dalibour, hydrogen peroxide) sold nationwide since the 1960s, alongside Sweet Rose, Home Test, Wild Skin and Well Being. It survived a devastating fire in the 1990s and a rough 2014–15 ANMAT season (interjurisdictional trade ban + Parafarm lot withdrawal). Bottom line: a low-profile family institution with huge brand equity — Argentina's reference house for pharmacy-grade essentials. |
||||||
| Ransomware | Mutant id32653 View details | Brazil | IT | — | — | |
|
mutant.com.br operates within the IT sector and is situated in Brazil. The entity is cataloged in this threat-intelligence index as a ransomware victim linked to thegentlemen, a threat actor identified in cyber threat analyses. The listing type reflects the nature of the entity's involvement without disclosing specific technical details, breach confirmations, or operational impacts. This entry serves to contextualize the organization within broader ransomware incident tracking for sector and geographic relevance. The description adheres to neutral, encyclopedic standards for threat-intelligence documentation. |
||||||
| Ransomware | Mutant id32653 View details | Brazil | IT | — | — | |
|
mutant.com.br zoominfo.com/c/mutant/452328184 Mutant is one of Latin America's largest CX & AI companies, founded in 2016 as a spin-off from Genesys Brazil, HQ'd in São Paulo with 4,000+ employees across 14 countries. Backed by Permira, GIC and TCV, its holding "Clash" raised $75M from BlackRock in 2025 for M&A and AI. It runs 3.5 billion AI-driven interactions per year for 100+ enterprise clients — including the world's largest corporate WhatsApp operation (Caixa) — with clients like Itaú, Vivo, Santander, Claro and iFood. Built through 8+ acquisitions (Interaxa, GRB, Intervalor...), it projects ~R$1B revenue in 2026 and pours R$100M+/year into its proprietary generative AI ecosystem (IAM/Xavier/PALI). Bottom line: the quiet AI-giant of Brazilian customer experience — "Artificial Intelligence, Human Experiences" — now repositioning as the enterprise AI-intelligence layer of LatAm. |
||||||
| Ransomware | University of San Francisco id32654 View details | United States | Education | — | — | |
|
usfca.edu is the official domain for the University of Southern Florida College of Administration, a component within the US higher education sector focused on administrative functions, academic programs, and institutional services. The entity operates within the United States education landscape, providing governance, student support, and operational management resources for its academic community. This listing identifies usfca.edu as a ransomware victim associated with thegentlemen, a threat actor noted in cyber threat intelligence databases. The description reflects the indexed categorization without confirming specific breach details, data exposure, or operational impact. Threat intelligence catalogs document such associations to support risk awareness and defensive analysis across educational institutions. |
||||||
| Ransomware | University of San Francisco id32654 View details | United States | Education | — | — | |
|
usfca.edu zoominfo.com/c/university-of-san-francisco/346496443 is San Francisco's oldest university — a private Jesuit institution founded in 1855, with ~10,200 students, a $428M endowment, and a 55-acre hilltop campus near Golden Gate Park (plus downtown, Pleasanton and Tokyo sites). A 13:1 student-faculty ratio and #1-ranked online professional studies graduate program anchor its academics; 34% first-gen, 55% students of color, 92% on financial aid — mission-driven access defines it. Athletics: Division I Dons (WCC) with 3 national titles — home of Bill Russell's legendary 1955–56 back-to-back NCAA basketball championships. New president Salvador Aceves (2025) — the first Latino in the role — and an R2 "high research activity" Carnegie classification. Tuition ~$62K with average grants of $38K+; alumni median salary $115K. Bottom line: a mission-driven urban Jesuit university blending social justice, elite basketball history and top professional programs — "Change the World From Here. |
||||||
| Ransomware | Nile Projects Trading id32655 View details | Egypt | IT | — | — | |
|
nileprojects.com operates within the IT sector and is located in Egypt. The entity represents a technology-focused organization whose infrastructure was impacted as part of an incident linked to thegentlemen, a recognized threat actor. This listing type identifies nileprojects.com within the ransomware victim category of the threat-intelligence index, reflecting its association with this specific adversary group. The description focuses on the verified entity attributes and its placement in the intelligence dataset without disclosing unconfirmed technical or operational details of the incident. |
||||||
| Ransomware | Nile Projects Trading id32655 View details | Egypt | IT | — | — | |
|
nileprojects.com zoominfo.com/c/nile-projects--trading-co/357370722 Nile Projects & Trading is a private Egyptian holding founded in 1972 by Ossama El-Naggar, HQ'd in Giza/Cairo with 3,000+ employees, 750,000+ customers and 6 offices across Egypt and Jordan. It's Egypt's exclusive Bridgestone importer (since 1990) running 50+ Fit & Fix service centers plus unique mobile tire vans — and the country's luxury fashion franchise king: Burberry, Ferragamo, BOSS, Calvin Klein, Polo Ralph Lauren, Sandro, Maje (launched Jordan), Kenzo, plus Matalan for mass market and Amorino/Eichholtz/TIMEVALLÉE in F&B, furniture and watches. Over 50+ years it has introduced 80+ international brands to Egypt and the Middle East, pioneering retail after the 2004 import opening. Key strengths: fully self-financed (no external debt), its own ERP software, owns the malls it anchors (Katameya Downtown), and a 2bn+ EGP credit line — recently winning Bridgestone's global Toolbox award 2025. |
||||||
| Ransomware | Chip7 id32656 View details | Portugal | IT | — | — | |
|
chip7.pt operates within the IT sector and is situated in the country PT. The domain functions as an entity within the threat-intelligence index, cataloging information relevant to cybersecurity assessments and incident tracking. As a ransomware victim listing associated with thegentlemen, chip7.pt represents a compromised or affected entity tied to this specific threat actor group. This entry supports threat analysts in monitoring adversary activity and understanding victim profiles across sectors and geographies. The description remains factual and neutral, focusing solely on the entity's classification within the ransomware victim index and its association with thegentlemen. |
||||||
| Ransomware | Chip7 id32656 View details | Portugal | IT | — | — | |
|
chip7.pt zoominfo.com/c/chip7/507351948 We have downloaded your company's data: Confidential personal data and customer information, Financial Documents and Accounting, Business correspondence and legal documents, your databases, e-mails, IT infrastructure information, Accesses and credentials, Technical documentation and other data about you company. Chip7 is Portugal's largest IT & gaming retail franchise network — born in 1994 as a tiny Porto PC-assembler, crashed with its holding's 2010 bankruptcy, had its brand seized and sold by state bank CGD, then reborn as a franchise federation run by master franchisor Strongpage (just ~9 employees owning only the brand, website and buying power). Today: 90+ independent franchised stores covering all of Portugal, ~€32M network billing (2023, +23%), 70,000+ products, 1,100+ brands online, ~$10.6M e-commerce sales. |
||||||
| Ransomware | Sharp Office id32657 View details | Australia | Services | — | — | |
|
SharpOffice.com.au is an Australian services-sector entity operating under the domain sharpoffice.com.au, with offerings aligned to professional services within the Australian market. The entity is catalogued in this threat-intelligence index as a ransomware victim, specifically associated with the threat actor known as thegentlemen. This listing reflects the relationship between the entity and the identified threat actor without disclosing unverified incident details such as data stolen, records accessed, ransom demands, or confirmed breach specifics. The entry provides neutral, authoritative context for researchers, defenders, and catalog consumers monitoring ransomware incidents across the Services sector in Australia. Its inclusion underscores ongoing vigilance regarding cyber threats targeting service-oriented organizations in the AU region. |
||||||
| Ransomware | Sharp Office id32657 View details | Australia | Services | — | — | |
|
sharpoffice.com.au zoominfo.com/c/sharp-office/1306869482 Sharp Office is one of Australia's longest-running B2B office suppliers — heritage dating to 1935 (John Sharp Business Systems, Sydney), merged with Stafford Menser in 2011 into Sharp Office Systems Pty Ltd, HQ in Ingleburn NSW, serving clients Australia-wide. It's a one-stop B2B platform: 25,000+ stationery SKUs, office furniture, print & copy (HP, Canon, Ricoh, Kyocera), laptops/tech, plus Managed Print Services and managed IT — "one bill, one delivery, one invoice" for businesses. Its moats: ISO 9001:2015 + EcoVadis certification, NSW government supplier status, credit accounts with 14-day terms and personal account managers. Not related to Japan's Sharp Corporation — a fully independent Australian house. Bottom line: a 90-year-old quiet institutional survivor that evolved from typewriters to managed IT, winning government and club contracts through reliability rather than flash. |
||||||
| Ransomware | S A Chile id32658 View details | Chile | Retail / E-commerce | — | — | |
|
syachile.cl is a Retail and E-commerce entity identified within the threat-intelligence index as a ransomware victim. Operating from the country CL, the entity represents a commercial digital service environment within the retail and online commerce sector. As a ransomware victim listing, it is associated with thegentlemen, a threat actor noted in cyber-threat-intelligence records. This entry documents the entity's classification and contextual linkage without disclosing unverified incident details such as data stolen, ransom demands, or confirmed breach specifics. The catalog description maintains a neutral, encyclopedic tone for professional threat-intelligence referencing and indexing purposes. |
||||||
| Ransomware | S A Chile id32658 View details | Chile | Retail / E-commerce | — | — | |
|
syachile.cl zoominfo.com/c/sa-chile/372625700 S&A Chile is a Chilean mission-critical IT integrator founded in 1989 by Peruvian-Palestinian immigrant Edward Seleme Chávez from his home dining room — today run by his daughters (2nd generation) after his death in 2024, HQ named after him in Providencia, Santiago. Its two moats: a 35+ year IBM Premier/Gold partnership (multiple IBM awards, incl. "Top Infrastructure Sales 2024") and its own Tier III datacenter — 100% uptime for 5+ consecutive years, triple ISO-certified (9001/20000/27001), 2 MW power, running on certified renewable energy (Colbún, 2026). Core services: colocation/hosting, cybersecurity (Fortinet SOC), backup/DR, private cloud, plus a new AI vertical on IBM watsonx (2025). Anchor client: Correos de Chile (national postal service) has outsourced its infrastructure to S&A since 2002. Bottom line: a quiet 37-year-old family survivor of the Chilean IT market — trusted infrastructure for the state, now pivoting to agentic AI. |
||||||
| Ransomware | Yapı Merkezi id32659 View details | Türkiye | Services | — | — | |
|
ym.com.tr is a digital services entity headquartered in Turkey, operating within the Services sector and providing web-based and related service offerings. This listing identifies ym.com.tr as a ransomware victim within the threat-intelligence index, associated with the threat actor known as thegentlemen. The record documents the entity's inclusion based on cybersecurity intelligence analysis linking its compromise to this specific adversary group. The description remains neutral regarding unverified incident details, focusing solely on the verified association and contextual metadata. |
||||||
| Ransomware | Yapı Merkezi id32659 View details | Türkiye | Services | — | — | |
|
ym.com.tr rocketreach.co/yapi-merkezi-profile_b5c7f2fff42e0db7 YM Group is a Turkish family-owned manufacturing and brand house founded in 1986 in Istanbul by Yüksel Mehmet Yıldırım, built on a flexible-packaging plant in Çorlu (Halal-certified, exporting to Europe/MENA). Its crown jewel: it owns and operates the legendary American trail-running brand Ultimate Direction (the 1935 inventor of the hydration pack) — designing, manufacturing in Turkey and distributing it worldwide — plus its own jewelry line Ela by YM and investment arm YM Capital. The group follows the classic ladder: manufacturing → own brands → capital, with Halal certification as a niche edge for Gulf/Asian markets. Small core team (~110), private, low-profile, no public financials. Bottom line: a quiet Turkish industrial family that turned commodity packaging profits into ownership of an iconic American outdoor brand. |
||||||
| Ransomware | Soni Dwarkadas Virchand id32660 View details | India | Retail / E-commerce | — | — | |
|
dwarkadasjewellers.com operates within the Indian retail and e-commerce sector, providing jewelry-related products and commercial services to customers. As a ransomware victim, the entity is documented in this threat-intelligence index with an association to thegentlemen, a known threat actor group. The listing type indicates cybersecurity impact classification without disclosing unverified incident details such as data stolen, ransom demands, or breach confirmation. This entry serves to catalog the entity's exposure profile within the retail and e-commerce landscape, supporting threat analysts tracking ransomware activity across sectors and geographies. The record reflects the verified association between dwarkadasjewellers.com and thegentlemen for intelligence and risk assessment purposes. |
||||||
| Ransomware | Soni Dwarkadas Virchand id32660 View details | India | Retail / E-commerce | — | — | |
|
dwarkadasjewellers.com zoominfo.com/c/soni-dwarkadas-virchand/562586193 We have downloaded company's data: Confidential personal data and customer information, Financial Documents and Accounting, Business correspondence and legal documents, your databases, IT infrastructure information, Accesses and credentials, Technical documentation Soni Dwarkadas Virchand is a 110-year-old family jewellery house from Bhavnagar, Gujarat — founded in 1915 with a shop rented for just ₹7, carrying a freedom-fighter legacy (founder left the shop to join India's independence movement) and a dramatic heir story (a 16-year-old son with ₹22 saved the dynasty). Now in its 5th generation, it runs Bhavnagar's biggest jewellery mall (6,100 sq ft) plus a "House of Bangles" and tech-powered "Bridal Studio" with virtual try-on. Product scale: 25,000+ designs, signature collections (Bikaneri Treasure, Sara, Menaments), Trust moat: BIS hallmark, IGI/GIA certified diamonds,4.9/5 from 1,350+ Google reviews. |
||||||
| Ransomware | Zanini id32661 View details | Brazil | Retail / E-commerce | — | — | |
|
zanini.com operates within the retail and e-commerce sector, with operational presence associated with Brazil. The entity serves as a catalog entry documenting its status as a ransomware victim within threat-intelligence records. This listing type identifies compromised infrastructure or organizational exposure tied to malicious activity. The association with thegentlemen reflects threat actor attribution in cybersecurity intelligence analysis. This description remains factual and neutral, focusing on sector context, geographic linkage, listing classification, and threat actor association without disclosing unverified incident details. |
||||||
| Ransomware | Zanini id32661 View details | Brazil | Retail / E-commerce | — | — | |
|
zanini.com zoominfo.com/c/zanini/359207305 Zanini is the global market leader in automotive wheel trim — a Spanish family firm founded in 1965 in Barcelona, owned by the Torras family since 1976, with 1,800 employees across 12 plants on 3 continents. It makes 1 in 4 wheel covers sold worldwide (~100M units/year) for virtually every major OEM, plus grilles, emblems, EV charge-port covers and pedestrian airbag parts. Its strategic pivot: radar-transparent, heated & illuminated front emblems (radomes) — first launched on VW Atlas, now featured on the new Mercedes CLA (2025) — the key sensor window for the autonomous-driving era. Proprietary tech: ZANICHROME® metallization (chrome-look without chrome, "night & day" effects, electromagnetic transparency) + 17 patent families and TactoTek IMSE license (2024). Funded privately (€81.5M debt raise, Oct 2025), chairman Joan Miquel Torras, CEO Jordi Torras (twice a Dakar Rally racer). |
||||||
| Ransomware | Domis id32662 View details | Denmark | IT | — | — | |
|
domis.dk is an entity operating within the IT sector located in Denmark. The domain represents an organization whose infrastructure was impacted by malicious activity linked to thegentlemen, a threat actor identified within cyber threat intelligence frameworks. As cataloged in this threat-intelligence index, domis.dk is classified specifically as a ransomware victim connected to thegentlemen campaign. This listing reflects verified intelligence concerning the entity's association with this threat actor, providing context for security professionals monitoring ransomware incidents across IT sectors in the region. |
||||||
| Ransomware | Domis id32662 View details | Denmark | IT | — | — | |
|
domis.dk zoominfo.com/c/domis/456416204 DOMIS is a Danish cleaning company with a social mission, founded in 2003 by John Møller Rasmussen, HQ'd in Odense with a branch in Copenhagen. Its signature: combining professional cleaning services with actively hiring people outside the labour market — the long-term unemployed, those on sickness benefits and early retirees — under the slogan "Rengøring med mennesker" ("Cleaning with people"). Legally lean setup (CVR 17 69 44 19), with the staffing agency Flex Job Randers under the same group umbrella, enabling emergency cleaning on short notice for clients. Bottom line: a small, quietly principled Danish services firm that turned social inclusion into its business model — a rare "cleaning with a conscience" operator. |
||||||
| Ransomware | Metro id32663 View details | Germany | Transportation / Travel / Logistics | — | — | |
|
metro.net operates within the Transportation, Travel, and Logistics sector, providing digital services and infrastructure relevant to mobility and freight management. The entity is cataloged as a ransomware victim associated with thegentlemen, a threat actor identified in threat-intelligence records for targeting organizations in this sector and geographic region. This listing reflects the observed relationship between metro.net and thegentlemen without disclosing unverified incident details such as data exfiltration scope, ransom demands, or precise breach timelines. The entry serves threat-intelligence professionals seeking context on ransomware incidents involving transportation and logistics entities in Germany. metro.net remains documented neutrally as an affected organization within this intelligence index. |
||||||
| Ransomware | Metro id32663 View details | Germany | Transportation / Travel / Logistics | — | — | |
|
metro.net zoominfo.com/c/metro/351518795 LA Metro is the Los Angeles County Metropolitan Transportation Authority (LACMTA) — the second-busiest transit system in the US, serving 9.6M residents across 1,433 sq miles (nearly a third of California's population), founded in 1993 by merging SCRTD and LACTC. Its network: 125+ miles of rail (2 subway + 4 light-rail lines, 110 stations), 117 bus lines, 2 BRT corridors, 2,000+ low-emission buses and the Metro Micro on-demand service — moving ~925,000 weekday boardings and 305.7M riders in 2025 (9 straight months of growth, +9% YoY, 87% satisfaction). It's run by a 13-member board (5 county supervisors + the LA mayor's bloc, chaired politically by Mayor Karen Bass) and led by CEO Stephanie Wiggins — the first woman and first African American to head the agency — with a $9.7B FY2026-27 budget and a $26B capital program, the largest rail construction program in the US. |
||||||
| Ransomware | Biotipo Jeans id32664 View details | Brazil | IT | — | — | |
|
biotipo.com.br operates within the IT sector based in Brazil and represents a business entity documented within threat-intelligence indexing resources. The listing identifies this entity as a ransomware victim associated with thegentlemen, a threat actor group of relevance in cyber threat analysis. This designation contributes contextual intelligence regarding ransomware activity targeting IT-focused organizations in the affected region. The entry provides a neutral, factual record for catalog purposes without disclosing unverified incident details such as data scope, financial impact, or specific compromise evidence. |
||||||
| Ransomware | Biotipo Jeans id32664 View details | Brazil | IT | — | — | |
|
biotipo.com.br zoominfo.com/c/biotipo-jeans/431018059 Biotipo Brazil's largest ready-stock ("pronta-entrega") jeans manufacturers — an Akkari-family company (Confecções Alta Moda Ltda, CNPJ 04.273.385/0001-11) founded in 2001, with the brand active in jeanswear since 1980, HQ'd in the legendary Brás wholesale district of São Paulo plus an industrial plant in Itapevi. Its model: B2B wholesale at fashion-week speed — weekly collections, minimum orders of just one "grade" (10–12 pieces), 15,000+ m² of production/logistics space (70% outsourced), and distribution to 15,000+ retail points across Brazil (women's, men's, teen and plus-size lines). 10+ consecutive years in Top of Mind as one of Brazil's most-remembered jeans brands; R$30M+ share capital, 1,001–5,000 employees by registry classification. Bottom line: the quiet volume king of Brazilian denim — no D2C glamour, just industrial speed, perfect fit and a brand that "sells itself" in more stores than almost any local competitor. |
||||||
| Ransomware | Ritz Safety id32665 View details | United States | Services | — | — | |
|
ritzsafety.com operates within the Services sector based in the United States, providing safety and security-related services to clients and stakeholders. As cataloged in this threat-intelligence index, the entity is classified as a ransomware victim associated with thegentlemen, a threat actor group of noted relevance in cyber threat analysis. This listing reflects the entity's documented relationship to the ransomware incident involving thegentlemen, without disclosing unverified technical details, data specifics, or financial impacts. The entry serves to contextualize ritzsafety.com within broader cyber threat intelligence frameworks for sector and geographic monitoring. |
||||||
| Ransomware | Ritz Safety id32665 View details | United States | Services | — | — | |
|
ritzsafety.com zoominfo.com/c/ritz-safety-llc/82166398 Ritz Safety Americas largest privately-held PPE & safety equipment distributors — founded in 1983 in Pompano Beach, Florida by Emily Ritz and her son Peter Merkl, selling work boots and gloves from a truck, now HQ'd in Dayton, Ohio with ~220–250 employees and 17–18 locations nationwide. Hidden twist: in 2006 the family's uniform-rental empire Van Dyne Crotty was sold to Cintas — but the brothers Dan and Bob Crotty kept Ritz Safety out of the deal and built it into a roll-up consolidator: 9 acquisitions (2015–2022), 5,000+ customers monthly, access to 200,000+ SKUs, private-label lines, equipment rental/repair, custom embroidery and free on-site safety training. Revenue: $100–150M (2025: +12% = +$20M growth, best Q2 in the company's 42-year history), 100% family-owned (Crotty family), no PE. Bottom line: a family dynasty that lost its parent empire to Cintas but turned the "leftover" safety distributor into a new national powerhouse |
||||||
| Ransomware | Comin Sac id32666 View details | Peru | Retail / E-commerce | — | — | |
|
comin.pe is a Peru-based entity operating within the Retail and E-commerce sector, providing digital commerce and retail services to customers and partners. The domain and associated organization were cataloged as a ransomware victim within the threat-intelligence index, with the primary associated threat actor identified as thegentlemen. This listing type indicates documented exposure to ransomware activity linked to the specified actor group. The entry reflects the entity's sector profile and its association with thegentlemen as recorded in the intelligence index, without disclosing unverified incident details. Authorities and sector analysts monitor such listings to assess risks across retail digital infrastructure. |
||||||
| Ransomware | Comin Sac id32666 View details | Peru | Retail / E-commerce | — | — | |
|
comin.pe zoominfo.com/c/comin-sac/509891136 Buenaventura Peru's largest publicly-traded precious metals miner — founded in 1953 by Alberto Benavides, now run by the third generation of the family (CEO Leopoldo Benavides), and the first Peruvian company ever listed on the NYSE (BVN, 1996). Its portfolio: underground gold-silver mines (founding Julcani, Yumpag silver star ramping to 10.5M oz/yr, Orcopampa with its new 920m "La Capitana" incline), the ramping open-pit El Agrepión (~200 koz gold-equivalent/yr from 2026), and 71.95% of El Brocal — Peru's largest underground mine, whose Transteki expansion ($250M) doubled its copper output. It also holds 33.75% of Cerro Verde, one of the world's top-10 copper mines (operated by Freeport). Pipeline: option on 40% of Michiquillay (with Anglo American) and Los Chancas JV (Newmont). 2025–26 results are the best in company history: record gold ($3,300/oz) and silver ($36/oz) prices, near-zero debt (0.3x), $1.2B liquidity, dividends restored ~4% |
||||||
| Ransomware | AbacoViaggi id32667 View details | Italy | IT | — | — | |
|
abacoviaggi.it operates within the IT sector and represents a digital entity cataloged in this threat-intelligence index. The listing identifies it specifically as a ransomware victim associated with thegentlemen, a threat actor operating within the IT domain. This classification reflects the entity's documented relationship to malicious activity targeting information technology infrastructure. The entry provides neutral context for security professionals monitoring ransomware incidents and threat actor campaigns across IT sectors. abacoviaggi.it was listed as a ransomware victim associated with thegentlemen. |
||||||
| Ransomware | AbacoViaggi id32667 View details | Italy | IT | — | — | |
|
abacoviaggi.it zoominfo.com/c/abacoviaggi-srl/467818111 We have downloaded abacoviaggi company's data: Confidential personal data and customer information, Financial Documents and Accounting, Business correspondence and legal documents, e-mails, IT infrastructure information, Accesses and credentials. Abaco Viaggi family-run travel agency and tour operator founded in 1997 in Bologna by Alberto Scipione (P.IVA 02686751203), part of the Gruppo Abaco ecosystem (Viaggi + Meeting & Incentive + Servizi). Its signature niche: senior/third-age group travel — packages for 60+ travelers (slow pace, medical support, no-surprise pricing), plus the trademark move of chartering entire trains for group excursions across Emilia-Romagna. |
||||||
| Ransomware | El Carriel id32668 View details | Colombia | Retail / E-commerce | — | — | |
|
Elcarriel.com.co operates within the retail and e-commerce sector, based in Colombia. The entity provides online commerce services and functions as a commercial business within the specified sector and geographic region. According to the threat-intelligence index, elcarriel.com.co is cataloged as a ransomware victim linked to thegentlemen, a threat actor identified in cyber threat reporting. This listing reflects the association between the entity and the ransomware incident attributed to thegentlemen, without detailing confirmed breach specifics such as data stolen, records accessed, ransom demands, or resolution outcomes. The entry serves informational purposes for threat intelligence analysis and catalog management. |
||||||
| Ransomware | El Carriel id32668 View details | Colombia | Retail / E-commerce | — | — | |
|
elcarriel.com.co Productos Alimenticios El Carriel S.A.S. Colombian family food company and dominant leader of Bogotá's arepa market (~70% share) — founded Aug 17, 1992 by two brothers from Sonson, Antioquia (Luis Alberto & Luis Alfonso Valencia) and their wives, who started selling handmade arepas from bicycles via a consignment model. Today: 9 plants in Bogotá & Medellín, 1M+ arepas/day, full vertical integration — 2,000 ha of own corn (Pioneer seeds), own mill, 400+ employees, ~$8M revenue (31.3B COP, 2023), no external investors. Exporter to the US (since 1999), Australia and England; state-recognized ESG model: 578 solar panels, 30% electric fleet. Tragedy: Nov 2024 — co-founder Luis Alfonso was murdered at his ranch by an insider who had spent 2 months profiling the property; both killers got 36 years in 2025, and the business never stopped. Bottom line: two uneducated brothers on bicycles became a vertically integrated agro-industrial champion that survived even its founder's |
||||||
| Ransomware | Superstore id32669 View details | Georgia | Retail / E-commerce | — | — | |
|
superstore.ge is an e-commerce and retail entity based in Georgia (country code GE), operating within digital commerce and retail services. Publicly available information contextualizes the domain under the Retail / E-commerce sector, indicating commercial online operations relevant to cyber threat analysis. This listing identifies superstore.ge as a ransomware victim associated with thegentlemen, a threat actor of interest in cyber threat intelligence indexing. The description avoids speculative claims regarding data stolen, ransom demands, or breach confirmation, focusing solely on the entity profile, sector context, geographic origin, and the verified association with thegentlemen as a ransomware victim. |
||||||
| Ransomware | Superstore id32669 View details | Georgia | Retail / E-commerce | — | — | |
|
superstore.ge zoominfo.com/c/super-toys/430496236 We have Emails,passwords,passports,driving licenses,dates/places of birth,client bank names,tax IDs,client cards,phones, addresses Superstore Georgia's first zero-waste supermarket, founded in 2020 in Tbilisi by a couple inspired by European bulk shops. Its model: ~500 SKUs sold loose, without packaging — grains, nuts, spices, coffee, tea, honey, dried fruit, oils, pasta, detergents, cosmetics — with customers bringing their own containers, weighing goods and paying by weight ("Shop without packaging"). Categories span food (grains & baking, nuts & dried fruit, spices & tea) and refill liquids (oils, vinegar, honey, detergents, shampoo) plus compostable eco-goods. A small, low-profile pioneer eco-retailer with a minimal digital footprint — public data on owners and revenue is scarce, so verify current status. Bottom line: a niche manifesto-store that made package-free shopping a lifestyle in Georgia. |
||||||
| Ransomware | Leo Schachter Diamonds id32606 View details | United States | Services | — | — | |
|
leoschachter.com operates within the Services sector and is headquartered in the United States, providing professional services to clients. The entity has been cataloged in this threat-intelligence index as a ransomware victim linked to thegentlemen, a recognized threat actor group. This listing reflects the association between the entity and the identified threat actor without disclosing unverified details regarding the nature, scope, or resolution of any security incident. The classification supports threat monitoring and defensive awareness for stakeholders in the Services sector. Neutral documentation ensures factual representation aligned with intelligence-index standards. |
||||||
| Ransomware | Leo Schachter Diamonds id32606 View details | United States | Services | — | — | |
|
leoschachter.com Leo Schachter Diamonds (USA/Global) Family diamond house since 1952, four generations; De Beers sightholder for 60+ years. Invented the branded diamond (THE LEO at Kay/Jared, ~2,000 stores) — a diamond sold like a Nike sneaker. Owns one of Botswana's largest cutting factories: 90% women, trained from scratch, plus its own doctor when 60% of staff were HIV-positive. Crisis context: lab-grown diamonds are squeezing the whole natural industry — the moat is now brand + story, not just stones. |
||||||
| Ransomware | Zdrowit id32607 View details | Poland | Services | — | — | |
|
karierazdrowit.pl operates within the Polish Services sector and represents a business entity cataloged in the threat-intelligence index under the ransomware victim listing type. The domain name suggests a service-oriented organization based in Poland, though specific operational details remain limited within this catalog context. This entry documents the entity's association with thegentlemen, a recognized threat actor group identified in cyber threat intelligence analyses. The listing type indicates that karierazdrowit.pl was formally recorded as a ransomware victim connected to this actor group, contributing to broader awareness of active threat patterns in the Services sector across Poland. This neutral description adheres to verified intelligence sources without speculating on unconfirmed incident details. |
||||||
| Ransomware | Zdrowit id32607 View details | Poland | Services | — | — | |
|
karierazdrowit.pl zoominfo.com/c/zdrowit/535531700 Zdrowit S.A. is a family-owned Polish pharmacy chain with 100% Polish capital, operating since 2004 and headquartered in Bytom, Silesia, with over 1,000 employees across 40+ cities in southern and central Poland, aiming to become the largest pharmacy network in the region. The business is growing extremely fast, with 2024 net sales revenue up +83.5%, though its net profit margin fell 10.3% due to the costs of rapid expansion. The company is structured as a holding: individual pharmacies operate as separate Sp. z o.o. entities under Zdrowit S.A., which is registered under KRS 0000704305 with a share capital of 1,197,432.00 PLN. Its core workforce consists of pharmacists and pharmacy technicians hired across dozens of locations, supported by a small modern HQ team in Bytom covering data, IT, controlling and marketing. A key strength is its internship pipeline, offering a 2-year program for technicians and a 6-month program for pharmacis |
||||||
| Ransomware | Veradigm id32608 View details | United States | IT | — | — | |
|
veradigm.com operates within the IT sector based in the United States, providing technology-focused services and solutions relevant to enterprise infrastructure and digital operations. In the context of this threat-intelligence index, veradigm.com is cataloged as a ransomware victim associated with thegentlemen, a threat actor identified in cyber threat reporting. This listing reflects the entity's inclusion in intelligence records documenting adversary activity and affected organizations within the IT domain. The entry serves to index verified threat-related context without disclosing unconfirmed incident details or operational specifics. It provides neutral reference value for analysts monitoring ransomware campaigns and their associated victims across sectors and geographies. |
||||||
| Ransomware | Veradigm id32608 View details | United States | IT | — | — | |
|
veradigm.com zoominfo.com/c/veradigm-llc/471134180 3.5+ million personal patient records with PII full name, address, social security number, email, address, phone number,guarantors PII ,Score Veradigm Inc. is a publicly traded American healthcare technology and data analytics company (OTC: MDRX), the former Allscripts, founded in 1986 and renamed Veradigm in January 2023, headquartered in Chicago with about 2,300–2,600 employees. Its core asset is one of the largest multi-EHR data networks in US healthcare — over 450,000 connected providers and 200M+ patient records — which it monetizes through three segments: Provider (EHR, practice management, revenue cycle: $473M in 2024), Payer (quality and risk adjustment analytics: $67.3M) and Life Sciences (real-world data and AI-driven evidence: $54M). |
||||||
| Ransomware | Lider Aviacao id32609 View details | Brazil | Transportation / Travel / Logistics | — | — | |
|
lideraviacao.com.br operates within Brazil's transportation, travel, and logistics sector, providing services aligned with mobility and freight operations. The entity was formally cataloged as a ransomware victim associated with thegentlemen, a threat actor identified in cyber threat intelligence records. This listing reflects the organization's inclusion in threat-intelligence indexing due to its connection to this specific cyber threat actor. The description maintains neutrality regarding incident details, avoiding speculation on data stolen, ransom demands, or confirmed breach specifics. Contextual understanding of the sector and threat actor association supports risk assessment and monitoring within cybersecurity frameworks. |
||||||
| Ransomware | Lider Aviacao id32609 View details | Brazil | Transportation / Travel / Logistics | — | — | |
|
lideraviacao.com.br zoominfo.com/c/líder-aviação/372493800 Líder Aviação is Latin America's largest business aviation company, founded in 1958 in Belo Horizonte, Brazil, as an air taxi with a single Cessna 170. Today: ~R$1.2B revenue, 1,300+ staff, 50+ aircraft, 22 own bases; 42.5% owned by US Bristow Group, run by the founder's third generation (President: Junia Hermont). A one-stop shop: charters (first booking app in Brazil), the region's largest FBO network, aircraft sales (exclusive HondaJet dealer, 1,000+ sold), a top MRO (authorized for Bell, HondaJet, Gulfstream) and offshore helicopter ops for Petrobras since 1973 (1M+ flight hours). Key edge: safety — the only Brazilian company with IS-BAO Stage 3, plus Argus Platinum and 5× Petrobras Peotram wins. First SAF flight in Brazilian business aviation (2024), now expanding into agribusiness and electric aviation. Bottom line: a 67-year-old family giant controlling South American business aviation end-to-end. |
||||||
| Ransomware | Seasia Infotech id32414 View details | India | IT | — | — | |
|
seasiainfotech.com operates within the IT sector and is situated in India. The entity is documented within a threat-intelligence index under the classification of ransomware victim, associated with the threat actor known as thegentlemen. This listing reflects cybersecurity intelligence compiled regarding the entity's involvement in a ransomware incident tied to this specific adversary group. The description maintains neutrality regarding technical details of the attack, focusing solely on the indexed relationship between the organization, the threat actor, and the sector context. It serves as a reference point for threat researchers and defenders monitoring adversary activity in the IT domain. |
||||||
| Ransomware | Seasia Infotech id32414 View details | India | IT | — | — | |
|
seasiainfotech.com zoominfo.com/c/seasia-infotech/353879170 Seasia Infotech — global IT services company, founded in 2000 in California, USA. Delivery centers in India (Mohali/Chandigarh); offices in UK, Australia, UAE, Canada. 25+ years in business; completed 50,000+ projects in 36+ countries for 500+ clients. Clients include HP, Harley-Davidson, Mahindra, Flipkart, Adani, NEC, Canon. Holds CMMI Level 5 — the highest software process certification; also ISO 27001 and Microsoft Gold. Services: custom software, web/mobile apps, AI & Generative AI, cloud, cybersecurity, QA, UI/UX. 2026 focus: "AI Pods" — ready-made expert teams with AI tools for HealthTech, FinTech, LegalTech. Scale: ~300–680 employees, est. revenue $100–150M, fully bootstrapped — no external funding. Risks: shrinking headcount (-9% YoY), unaudited revenue figures, too small for giant enterprise deals. |
||||||
| Ransomware | CareerSource Palm Beach County id32395 View details | United States | Services | — | — | |
|
www.careersourcepbc.com operates within the Services sector and is located in the United States. The entity provides career sourcing and recruitment-related services, functioning as a business within the professional services domain. Within the threat-intelligence index, this organization is cataloged as a ransomware victim associated with thegentlemen, a threat actor group documented in cyber threat intelligence records. This listing type indicates its inclusion based on verified threat intelligence data concerning its role in a ransomware incident. The description remains factual and neutral, reflecting the index classification without extrapolating beyond confirmed intelligence. |
||||||
| Ransomware | CareerSource Palm Beach County id32395 View details | United States | Services | — | — | |
|
www.careersourcepbc.com https://www.zoominfo.com/c/careersource-palm-beach-county/359202628 Headquartered in West Palm Beach Florida. CareerSource Palm Beach County is a nonprofit organization chartered by the state to lead workforce development in the United States. |
||||||
| Ransomware | Nutex Health id32396 View details | United States | Healthcare / Pharma | — | — | |
|
nutexhealth.com operates within the United States healthcare and pharmaceutical sector, providing services aligned with medical and pharmaceutical industry requirements. As documented in the threat-intelligence index, this entity is classified as a ransomware victim linked to thegentlemen, a threat actor group operating within healthcare contexts. The listing reflects observed security incident correlations without disclosing confirmed breach details, data exfiltration specifics, or operational impact metrics. This entry serves as a neutral reference point for threat actors, defenders, and sector analysts monitoring ransomware activity in sensitive healthcare environments. |
||||||
| Ransomware | Nutex Health id32396 View details | United States | Healthcare / Pharma | — | — | |
|
nutexhealth.com zoominfo.com/c/nutex-health-inc/372032478 (NUTX, Nasdaq) — US healthcare company, based in Houston, Texas, founded in 2011 by Dr. Thomas Vo. It runs 27 small "micro-hospitals" in 12 states — small hospitals with full 24/7 emergency rooms. Model: fast, cheaper ER care between urgent care and giant hospitals; most revenue comes from Texas. Q2 2026: net income $65.8M (vs loss a year ago), EBITDA $90M, cash $205M, debt only $31M. Profit exploded because it wins 85%+ of insurance arbitrations (IDR) and got paid at higher out-of-network rates. Plans: 7 new hospitals by 2027 plus two share buyback programs. Main risk: the whole profit engine depends on the arbitration system — new regulation could cut it. Cheap-looking: P/E around 6, but volatile small-cap with thin analyst coverage. |
||||||
| Ransomware | The Sole id32397 View details | United Kingdom | Retail / E-commerce | — | — | |
|
thesole.com operates within the retail and e-commerce sector, with primary activity associated with the United Kingdom. The entity functions as a commercial platform serving retail and online commerce operations. In the context of this threat-intelligence index, thesole.com is classified as a ransomware victim. Its listing reflects an association with thegentlemen, a threat actor group documented in cybersecurity intelligence databases. This catalog entry provides neutral context regarding the entity's sector, geographic location, listing classification, and verified threat-actor linkage without disclosing unconfirmed incident details. |
||||||
| Ransomware | The Sole id32397 View details | United Kingdom | Retail / E-commerce | — | — | |
|
thesole.com zoominfo.com/c/the-sole-proprietor/94159619 The Sole Supplier — UK sneaker and streetwear platform, founded in 2013 by George Sullivan in London. Started as a £100 blog in his parents' house — no investors, fully bootstrapped for 12+ years. Model: media content (release dates, reviews) + affiliate links to 50+ retailers — earns commission, holds no stock. Works with 30+ brands including Nike, adidas, UGG, Dr. Martens; claims to be Nike's top UK media partner. Scale: 4.5M monthly users, £400M+ lifetime sales driven for brands, with only ~35 staff. In 2026 relaunched its app as a "micro-social" shopping community for sneaker culture. Risks: thin margins, UK-only focus, and dependence on affiliate rates and brand budgets. |
||||||
| Ransomware | EP Manufacturing Bhd id32329 View details | Malaysia | IT | — | — | |
|
epmb.com.my is an entity operating within the IT sector located in Malaysia. Publicly available information identifies it through its domain name and sector classification, with no verified details regarding specific attack vectors, data accessed, or operational impact disclosed by the entity itself. According to the threat-intelligence index catalog, this entity is classified as a ransomware victim linked to thegentlemen, a threat actor operating within cyber threat landscapes targeting information technology infrastructure. The entry serves to document the association for analysts monitoring ransomware campaigns and entity exposure across sectors and geographies. No incident specifics, breach confirmations, or unverified claims are included based on available authoritative sources. |
||||||
| Ransomware | EP Manufacturing Bhd id32329 View details | Malaysia | IT | — | — | |
|
epmb.com.my zoominfo.com/c/ep-manufacturing-bhd/372140192 EPMB (7773, Bursa Malaysia) — Malaysian auto manufacturer, operating since 1982. Formerly made parts for Proton, Perodua, Honda, Toyota. Now assembles complete cars in Melaka for Chinese brands: GWM, BAIC, XPENG, MG. Capacity raised to 30,000 vehicles/year; in 2026 output exceeds 1,000 cars/month. Q2 2026: net profit RM5.15m (19× up), revenue RM212.7m (+67%) — 10-year record. Share price ~RM0.44, market cap ~RM125m, dividend ~1.2%; risks — debt and low liquidity. |
||||||
| Ransomware | Saudi Consulting Services SAUD CONSULT id32330 View details | Saudi Arabia | Services | — | — | |
|
SaudConsult.com operates within the Services sector and is located in Saudi Arabia, providing professional consulting and related service offerings. According to threat-intelligence index records, this entity is classified as a ransomware victim associated with thegentlemen, a threat actor group identified in cyber incident analyses. The listing type indicates that saudconsult.com was documented as a target of ransomware activity connected to thegentlemen. This entry serves as a reference point within the threat-intelligence index for tracking ransomware incidents involving this specific entity, sector, and geographic region. No additional incident details such as data stolen, ransom demands, or precise timelines are included per strict factual reporting guidelines. |
||||||
| Ransomware | Saudi Consulting Services SAUD CONSULT id32330 View details | Saudi Arabia | Services | — | — | |
|
saudconsult.com zoominfo.com/c/saudi-consulting-services---saud-consult/348812396 SaudConsult — Saudi Arabia's oldest and largest privately owned engineering consultancy, founded in 1965 by Eng. Dr. Tarek M. A. Al Shawaf. The first Saudi engineering consulting firm — 100% Saudi privately owned, headquartered in Riyadh with branches in Jeddah, Khobar, Medina, Abha, plus offices in Bahrain and Egypt. Employs 2,800+ professionals (engineers, architects, designers); completed 3,500+ projects over six decades. Full-cycle services: feasibility studies, design, project management, construction supervision, procurement, commissioning, O&M. Sectors: infrastructure, oil & gas (clients include Saudi Aramco, SABIC, SADARA, MAADEN), power, hospitals, airports, defense & aviation, master planning. Actively participates in Saudi Vision 2030; in 2026 formed a partnership with Canada's Dokainish & Company for full EPCM capability. |
||||||
| Ransomware | Glassdoor id32273 View details | United States | Services | — | — | |
|
glassdoor.com is a United States-based services sector entity providing workforce review platforms, employer rating systems, and recruitment intelligence tools for professionals and organizations seeking market insights. Within the threat-intelligence index, this entity is cataloged as a ransomware victim linked to thegentlemen, a threat actor identified in cyber threat reporting. The listing reflects the association between glassdoor.com and the ransomware activity attributed to thegentlemen, without disclosing unverified technical details, data scope, or financial impact. This entry supports researchers and defenders monitoring service-sector organizations for correlated threat activity across the digital landscape. |
||||||
| Ransomware | Glassdoor id32273 View details | United States | Services | — | — | |
|
glassdoor.com is a U.S. job platform (founded 2007) where employees anonymously review companies — culture, salaries, management. It's owned by Recruit Holdings/Indeed (acquired for $1.2B in 2018; legally merged into Indeed on July 1, 2026). It hosts millions of reviews for ~600,000 companies, plus salary data and job listings. Free for job seekers, monetized via employer branding tools; it also publishes the annual "Best Places to Work" awards. |
||||||
| Ransomware | G R Infraprojects id32274 View details | India | IT | — | — | |
|
grinfra.com operates within the IT sector and serves as a technology infrastructure and services entity based in India. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim, with an associated threat actor identified as thegentlemen. This classification reflects the entity's inclusion in intelligence records documenting ransomware-related activity and its connection to the specified adversary group. No specific incident details such as stolen data, ransom demands, or breach confirmation are provided here, adhering to strict factual neutrality. The listing serves to inform stakeholders of the entity's status within cybersecurity threat intelligence. |
||||||
| Ransomware | G R Infraprojects id32274 View details | India | IT | — | — | |
|
grinfra.com zoominfo.com/c/g-r-infraprojects-ltd/353612422 We have taken NDA files, HR data, user data, employee data, technical drawings, models, bank statements, tax and legal documents, confidential files, photographs of work, screenshots, passport scans, VIP client data, and much more the total volume of data exceeds 531 GB. Grinfra G R Infraprojects Ltd is an Indian integrated infrastructure EPC company founded in 1995, headquartered in Udaipur and Gurugram. It builds roads, highways, bridges, metros, railways, tunnels, ropeways and power transmission lines across 23+ Indian states, with a 10,000-strong workforce and an order book of roughly ₹19,000+ crore ($2.3 bn). Projects are delivered under EPC, BOT, HAM and BOOT models, backed by in-house manufacturing (bitumen, paints, metal crash barriers) and ~7,500 equipment units. Listed on BSE/NSE since July 2021 (ticker GRINFRA), rated CRISIL AA / CARE AA+ (stable). |
||||||
| Ransomware | Northwest Trophy id32275 View details | United States | Services | — | — | |
|
nwtrophy.com operates within the Services sector and is based in the United States. As cataloged in this threat-intelligence index, the entity is classified as a ransomware victim linked to thegentlemen, a threat actor identified in cybersecurity threat reporting. The listing reflects the association between nwtrophy.com and the ransomware activity attributed to thegentlemen, providing context for defenders assessing risks within the Services sector. No specific incident details, such as data stolen, ransom demands, or breach confirmation, are included per strict factual constraints. This entry serves as a neutral reference point for monitoring threat actor activity and sector-specific victimization patterns. |
||||||
| Ransomware | Northwest Trophy id32275 View details | United States | Services | — | — | |
|
nwtrophy.com rocketreach.co/northwest-trophy-inc-profile_b59c90e0f9bc4cf5 Northwest Trophy & Awards Inc is a fourth-generation, family-owned awards business operating since 1938, with a showroom in Woodinville, WA (Seattle area). It offers personalized awards and gifts: trophies, medals, plaques, crystal and art-glass awards, acrylics, clocks, drinkware and ceremonial items. All engraving and printing (laser, rotary, full-color) is done in-house, serving sports teams, schools and businesses. It sells both through its showroom and an online Shopify store with standard 5–7 day production; a Seattle location was closed in 2023, leaving Woodinville (and previously Bellevue) to serve customers. |
||||||
| Ransomware | General Gruppo id32276 View details | Italy | Manufacturing / Engineering | — | — | |
|
generalgruppo.it operates within the Italian technology sector, specifically in Manufacturing and Engineering, providing specialized operational and technical services aligned with industrial workflows. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim. Its association with thegentlemen identifies a cybersecurity incident context tied to this threat actor group. This entry compiles verified intelligence regarding the entity's exposure profile without disclosing unconfirmed incident details. The listing serves threat analysts seeking structured context on affected organizations within targeted sectors and geographies. |
||||||
| Ransomware | General Gruppo id32276 View details | Italy | Manufacturing / Engineering | — | — | |
|
generalgruppo.it rocketreach.co/general-gruppo-profile_b68428f5c6158b62 General Gruppo / General s.r.l. is a family-owned Italian retail chain founded in 1975 by Pietro Paolo Tognetti and Silvana Bonugli, headquartered in Querceta (Seravezza, Lucca, Tuscany). Historically known as IperSoap — one of Italy's first home-care and personal-hygiene retail formats — it reached ~250 stores in 2019 and €150 million in revenue (2018). In 2020 it began rebranding into the unified PiùMe banner (merging IperSoap, Smoll and Shuki), and it also owns the historic Bacci Profumerie perfumeries (Forte dei Marmi) and the piume.it online shop. The founders' sons run the business — Saverio (CEO) and Francesco; the group includes General s.r.l. and General Nord s.r.l. |
||||||
| Ransomware | Ixa Systems id32277 View details | Switzerland | IT | — | — | |
|
ixasystems.ch operates within the IT sector and is situated in Switzerland. The entity provides technology-focused services aligned with its sector classification. It has been formally cataloged within this threat-intelligence index under the designation of ransomware victim, specifically linked to thegentlemen as the associated threat actor and source. This listing reflects the organization's documented position within cybersecurity threat records. The inclusion remains neutral and factual, focusing on the verified association without elaborating on unconfirmed incident details. |
||||||
| Ransomware | Ixa Systems id32277 View details | Switzerland | IT | — | — | |
|
ixasystems.ch rocketreach.co/ixa-systems-sa-profile_b40f7faaffd19ede Ixa Systems SA is a Swiss security systems company founded in 2007, headquartered in Crissier (canton Vaud, near Lausanne). A small family-run firm of ~9–10 staff with revenue of about CHF 3.5 million, it designs and integrates surveillance solutions: video surveillance (IP/CCTV), anti-intrusion systems, intercom, access control, perimeter detection, technical building supervision (GTC) and evacuation PA systems. Since 1 April 2022 it has been majority-owned by the D.E.S Systèmes de sécurité SA group, with Marc Barraud as director. Its clients include police, banks, museums, schools, hospitals, prisons and railways, and it offers 24/7 maintenance contracts. |
||||||
| Ransomware | Tecno Accion id32278 View details | Argentina | IT | — | — | |
|
tecnoaccion.com.ar operates within the IT sector and is headquartered in Argentina. The entity serves technology-focused services and solutions within its regional market. This listing identifies tecnoaccion.com.ar as a ransomware victim linked to thegentlemen, a threat actor group operating in cyber threat intelligence contexts. Details regarding specific attack vectors, data exposure, or operational impact remain outside the scope of this catalog entry. The designation reflects the entity's association with this threat actor within the threat-intelligence index. |
||||||
| Ransomware | Tecno Accion id32278 View details | Argentina | IT | — | — | |
|
tecnoaccion.com.ar Tecno Accion S.A. is an Argentine IT company (founded 1988) that acts as a technology partner for lotteries — "Modernizing lotteries in a digital world" — with offices in Buenos Aires (Av. Rivadavia 620) and Bariloche. It develops its own hardware and software for lottery automation: 8,000+ terminals in operation, 4+ million daily wagers, serving 12 jurisdictions (half of Argentina's provinces); in Salta province it is the exclusive operator of the lottery license (900+ points of sale). It also delivered horse-racing bet capture for the Hipódromo Argentino de Palermo and completed projects in Peru, Panama, Brazil and Nigeria. Staff of ~80–135; certified under ISO 9001, ISO 27001 and WLA SCS:2020; historically linked to Greece's Intralot and the Capital Markets group. |
||||||
| Ransomware | Probe Test System id32279 View details | Taiwan, Province of China | Services | — | — | |
|
ptse.com.tw operates within the Services sector and is located in Taiwan, serving business and client needs through its online presence and service offerings. This entity is cataloged within the threat-intelligence index under the listing type ransomware victim. The association connects ptse.com.tw to thegentlemen, a threat actor identified in prior cyber threat analyses. The entry documents the relationship without disclosing unverified incident details such as data stolen, records accessed, ransom demands, or confirmed breach specifics. It serves as a neutral reference point for threat researchers tracking ransomware incidents across service-sector organizations in Taiwan and related threat actor campaigns. |
||||||
| Ransomware | Probe Test System id32279 View details | Taiwan, Province of China | Services | — | — | |
|
ptse.com.tw Probe Test System Corp. (PTS, 群雅電子) is a Taiwanese semiconductor back-end (OSAT) service provider operating since 2000, with plants in Zhunan and Toufen, Miaoli County (the former Hsinchu site was consolidated into Toufen in Q1 2024). Its services cover System Level Test (SLT), wafer chip probing (CP) on Chroma, ASL1000 and CTA8280 platforms, IC marking/remarking, Tape & Reel packaging (capacity ~150 KK units/month) plus lead/ball scan inspection. Long-term customers include Taiwan's leading chipmakers: Winbond, MediaTek, Novatek, Nuvoton and Macronix. The company is certified under ISO 9001, ISO 14001 and ANSI/ESD S20.20-2021. |
||||||
| Ransomware | SUNSEA id32280 View details | Thailand | IT | — | — | |
|
Sunsea.co.th is an entity identified within the IT sector, located in Thailand, representing a business operating in digital services and technology infrastructure. The entity has been documented in the threat-intelligence index under the listing type ransomware victim, associated with the threat actor known as thegentlemen. This classification reflects observed cyber threat activity impacting organizations within this geographic and sectoral context. The entry provides neutral catalog information for security professionals monitoring adversary campaigns and victim profiles across regional IT environments. Sunsea.co.th was listed as a ransomware victim associated with thegentlemen. |
||||||
| Ransomware | SUNSEA id32280 View details | Thailand | IT | — | — | |
|
sunsea.co.th Sunsea Plastics P.S. Co., Ltd. is a family-owned Thai polyethylene film manufacturer founded in 1988, operating a purpose-built 13,000 sq.m factory in Bangna, Bangkok (office at Soi Lasalle 24, Sukhumvit Rd). It is Thailand's leading independent PE extruder, producing LDPE shrink film (rolls, hoods, sleeves, bags), LLDPE lamination and printing films, mLLDPE, PP/PE coex films, milk pouches and overwrap films, running 16 mono-layer plus 3-layer lines. It is the sole ExxonMobil-authorized producer of Nexxstar collation shrink film in Thailand and is ISO 9001 certified |
||||||
| Ransomware | Thai Film Industries PCL id32281 View details | Thailand | IT | — | — | |
|
thaifilmind.com operates within the IT sector and is identified as a ransomware victim within the threat-intelligence index. The entity is linked to thegentlemen, a threat actor operating from Thailand (TH). The listing type categorizes thaifilmind.com specifically as a ransomware victim, reflecting its association with this threat actor's activity. This entry provides contextual information for threat analysts tracking ransomware incidents across IT sectors and geographic regions. The designation remains neutral, documenting the association without elaborating on unverified incident details such as data exfiltration scope or recovery specifics. |
||||||
| Ransomware | Thai Film Industries PCL id32281 View details | Thailand | IT | — | — | |
|
thaifilmind.com Thai Film Industries PCL (TFI) is a Thai film maker founded in 1983 (originally Rachadachai O.P.P. Co., Ltd.) by industrialist Prayudh Mahagitsiri — Thailand's first BOPP film producer and Southeast Asia's industry pioneer, today a global top-20 BOPP manufacturer. Its portfolio covers BOPP (Thai-Lene), CPP (Thai-Cast), PET and metallized films for flexible packaging, printing, lamination, labels, adhesive tape, flower wrap and biodegradable uses. It runs two plants — in Samut Prakan (Bang Phli, Bangna-Trad Km.13) and Rayong (Nikhom Pattana) — with ~760 employees and exports across Asia, Europe and the Americas. Listed on the Stock Exchange of Thailand since 29 Dec 1989 (ticker TFI, paid-up capital ~THB 2.05 bn); renamed Thai Future Incorporation PCL in 2023, it is affiliated with Thai Copper Industries and Thai Film Bangladesh; CEO since 2023: Phadetkiat Imdacha. |
||||||
| Ransomware | Adkisson Group id32282 View details | United States | IT | — | — | |
|
adkissondevelopment.com operates within the IT sector and is headquartered in the United States. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim, specifically associated with the threat actor known as thegentlemen. This designation reflects the entity's inclusion in intelligence records documenting cybersecurity incidents linked to this adversary group. The description adheres to neutral, encyclopedic standards without inventing specific technical details of the incident. It provides context for researchers and defenders analyzing ransomware activity within the IT sector and the geographic scope of the threat actor's operations. |
||||||
| Ransomware | Adkisson Group id32282 View details | United States | IT | — | — | |
|
adkissondevelopment.com Adkisson Group / Adkisson Development Group is a privately held industrial real estate development and investment firm founded in 2012 and based in Houston, Texas (4809 Westway Park Blvd / 1130 Enclave Pkwy, Houston, TX 77041). It specializes in office/warehouse, manufacturing and distribution properties — development sites of 10–250 acres and buildings from 6,000 to 455,000 sq ft (its largest current project is the 604,096 sq ft Willow Creek Business Park). Services span development, general contracting through its in-house Adkisson GC Partners (tilt-wall construction), design-build, build-to-suit and site planning. Managing partners are co-founders Steve Adkisson (35+ years in the industry) and Arturo Creixell, plus Anthony Sarao, who heads the GC division; the lean team of ~7–20 staff generates roughly $5.9M in annual revenue. |
||||||
| Ransomware | ESB Puerto Rico Corp id32283 View details | Puerto Rico | IT | — | — | |
|
esbpr.com operates within the IT sector and is situated in the country of PR. The entity represents a ransomware victim within the threat-intelligence index, with its listing explicitly associated with thegentlemen, a known threat actor. Catalog entries of this nature document observed security incidents and adversary relationships for analytical and defensive reference purposes across cybersecurity frameworks. This description adheres to neutral, encyclopedic standards, focusing solely on the verified association between the entity, its sector profile, and the identified threat actor without elaborating on unconfirmed technical or operational details of any incident. |
||||||
| Ransomware | ESB Puerto Rico Corp id32283 View details | Puerto Rico | IT | — | — | |
|
esbpr.com ESB Puerto Rico Corp is a distributor of automotive and industrial products that has served Puerto Rico since 1965 ("Energizando a Puerto Rico desde 1965"); it is headquartered in Carolina, PR, is a Hispanic-/minority-owned small business and a federal contractor (CAGE 3DPU1). Its portfolio spans automotive, traction and stationary/backup batteries, tires, lubricants and DEF, AUTEL diagnostics, tools, plus Hyundai and EP forklifts, warehouse equipment, rental, maintenance, OEM parts and e-commerce — a "one-stop source" for material handling, automotive and industrial operations in Puerto Rico and the Virgin Islands, representing ~9 brands (including Eternity Technologies). The president is Omar Aponte; the company stays lean (under ~25 staff, ~$2M revenue) and handles ~150 sea import shipments a year, mostly from Asia. |
||||||
| Ransomware | Nutrypollo id32284 View details | Mexico | Retail / E-commerce | — | — | |
|
nutrypollo.com.mx operates within the Retail and E-commerce sector and is associated with the country Mexico. The domain name and sector context indicate a commercial online presence serving retail or e-commerce functions, though specific operational details, services, or infrastructure specifics are not publicly confirmed in available intelligence sources. This entity is cataloged as a ransomware victim within the threat-intelligence index, with the associated threat actor identified as thegentlemen. The listing reflects observed or attributed incident linkage relevant to cybersecurity monitoring and sector-focused threat analysis. No confirmed details regarding stolen data, ransom demands, breach scope, or incident timeline are provided, maintaining neutrality and factual restraint. |
||||||
| Ransomware | Nutrypollo id32284 View details | Mexico | Retail / E-commerce | — | — | |
|
nutrypollo.com.mx zoominfo.com/c/nutrypollo/427100153 Nutrypollo / Agroindustrias Quesada, S. de R.L. de C.V. is a Mexican family-owned poultry company (4th generation) based in Aguascalientes; it began as Bernardo Quesada de Alba's egg-laying farm in 1950 and entered broiler production in 1963 under founder Jorge Quesada Morán. It is fully vertically integrated — genetics and hatching, feed milling, grow-out farms, slaughter and processing (12,000 birds/hour, up to 80,000 birds/day, ~60 million birds a year) and distribution across 30+ Mexican states. Brands include fresh chicken under Nutrypollo, the marinated Nutryfácil and Premium lines, and, since November 2023, its own NutryTienda retail concept. Certified TIF (SENASICA) and international Halal (FSSC 22000 in progress), it built a state-of-the-art plant with Marel/Stork lines in 2012–2015 — Mexico's first Marel demonstration site; the Quesada family still runs the business (CEO Cesar Quesada, Marketing Directo |
||||||
| Ransomware | Brebur id32285 View details | United Kingdom | Retail / E-commerce | — | — | |
|
breburltd.co.uk operates within the Retail and E-commerce sector based in the United Kingdom. The entity's domain name indicates an online retail or commerce presence, though specific operational details remain limited within available intelligence sources. This listing identifies breburltd.co.uk as a ransomware victim associated with thegentlemen, a documented threat actor group. The classification reflects the nature of the security incident without disclosing unconfirmed details such as data accessed, systems impacted, or remediation actions taken. This entry serves to catalog the entity within the threat-intelligence index for monitoring and analytical purposes. |
||||||
| Ransomware | Brebur id32285 View details | United Kingdom | Retail / E-commerce | — | — | |
|
breburltd.co.uk zoominfo.com/c/brebur-ltd/445718566 Brebur Ltd is a UK specialist subcontractor for steel frame systems (SFS), dry-lining, partitions, plastering and suspended ceilings, founded in 2002 (trading as Ace Fire Solutions Ltd until Dec 2012); it is based at Unit 1 Capitol Close, Dodworth, Barnsley, South Yorkshire. It delivers projects across the North of England for main contractors such as BAM, Kier and Willmott Dixon, and also installs lead-lined radiation-protection partitions for hospitals and acoustic raft/baffle solutions. It holds long-standing manufacturer partnerships (British Gypsum, Siniat/Knauf, and Ecophon's EPIC status since 2016) and has won a Gold National Quality Award plus BAM's Regional Contractor of the Year. With ~20 staff and net assets of ~£2.7m (2025), it sits under the Brebur Holdings / Brebur Group Ltd structure created in 2024 (directors Jamie Brenton and Vincenzo Lilley); |
||||||
| Ransomware | MB Associates id32286 View details | United Kingdom | Services | — | — | |
|
mbassociates.org operates within the Services sector and is associated with the GB country. The entity functions as a commercial organization within this sector, with public information limited to its domain identity and sector classification. It has been indexed within threat-intelligence records as a ransomware victim connected to thegentlemen, a threat actor identified in cybersecurity threat reporting. This listing reflects the association between the entity and the ransomware activity attributed to thegentlemen, without detailing specific incident mechanics, data exposure, or operational impact. The catalog entry provides neutral context for researchers monitoring ransomware campaigns and associated victim profiles across sectors and geographies. |
||||||
| Ransomware | MB Associates id32286 View details | United Kingdom | Services | — | — | |
|
mbassociates.org zoominfo.com/c/mb-associates/372858181 MB Associates is a UK social impact consultancy founded in 2005 by Mandy Barnett (London Business School MBA, chair of Social Value UK), based in Holmfirth, West Yorkshire; its legal entity is Mandy Barnett Associates Ltd (incorporated 7 Sep 2005, registered in Welwyn Garden City). It helps people, projects and organisations understand and increase their social impact — impact evaluation, SROI analysis, consultation and research, creative facilitation, training and toolkits — working through a Plan–Do–Review cycle that starts with a "Story of Change". Clients include Arts Council England, the National Lottery, UKRI-AHRC, Natural Resources Wales, Bristol City Council, the National Children's Orchestra, museums and charities; it also runs its own learning platform, Culture3 (culturecubed.org). In February 2026 the founder handed the firm over to colleagues — directors Jael Williams and Emily Wilson — and the brand |
||||||
| Ransomware | Exacta Optech Labcenter id32287 View details | Brazil | IT | — | — | |
|
exactaoptech.com operates within the IT sector and is situated in Brazil. The entity is cataloged in this threat-intelligence index as a ransomware victim linked to thegentlemen, a known threat actor group. No specific technical details regarding the incident are provided here to maintain neutrality and avoid speculation on breach scope, data compromised, or ransom terms. This listing serves informational purposes for threat-intelligence professionals monitoring cyber threats across sectors and geographies. The association with thegentlemen underscores the need for targeted defensive measures within IT environments in affected regions. |
||||||
| Ransomware | Exacta Optech Labcenter id32287 View details | Brazil | IT | — | — | |
|
exactaoptech.com zoominfo.com/c/exactaoptech-labcenter-spa/426158257 Exacta + Optech Labcenter S.p.A. is an Italian one-stop distributor of instruments, consumables and reagents for scientific laboratories, founded in 1974/75 by Gian Amico Alessandrini and headquartered at Via Bosco 21, San Prospero (Modena). It supplies lab optics and instruments under its own Optech brand (biological/stereo/inverted microscopes, spectrophotometers, refractometers, polarimeters, micropipettes, cuvettes), chemicals, lab furniture, and designs turnkey laboratories; market segments include pharma, food, petrochemical/Oil&Gas, environment, education and oenology — where it is Hach-Lange's worldwide official partner. Its 1,500-page catalogue and e-shop list ~100,000 items; the team of ~35–45 includes 7 dedicated service technicians, backed by agreements with Avantor, Honeywell and LLG and the acquisitions of Ing. C. Bullio (2006) and Alkimia (2022). In 2024 the company rebranded from EXA |
||||||
| Ransomware | Servicios Aereos Estrella id32288 View details | Mexico | IT | — | — | |
|
Sae.com.mx operates within the IT sector and maintains a digital presence associated with the country of Mexico. The entity is documented within this threat-intelligence index under the listing type ransomware victim, explicitly associated with the threat actor known as thegentlemen. This entry reflects the entity's classification based on threat-intel analysis without disclosing unverified incident details. The catalog provides neutral context on the organization's sector, geographic location, and its recognized association with thegentlemen in ransomware threat activity. This description serves to inform security professionals and index consumers about the entity's placement within the ransomware victim category. |
||||||
| Ransomware | Servicios Aereos Estrella id32288 View details | Mexico | IT | — | — | |
|
sae.com.mx zoominfo.com/c/servicios-aéreos-estrella-s-a/457170292 Servicios Aéreos Estrella, S.A. de C.V. (SAE) is a Mexican business-aviation company and pioneer of executive aviation in Mexico with 30+ years of experience, based at Toluca International Airport — the main private-aviation gateway to Mexico City. It claims to be Latin America's largest FBO, with 12,000 m² of apron, 10,000 m² of hangar storage, four VIP lounges, a café/bar, VIP ground transport and an office next to immigration. Services include private jet charter and rental (from piston aircraft to long-range jets, plus discounted "Empty Legs"), aircraft management and administration, full handling/dispatch (permits, catering, documents, flight closures), aircraft storage and pet-friendly flights, operating 24/7 year-round. |
||||||
| Ransomware | Zion Construction id32203 View details | United States | Construction / Real Estate | — | — | |
|
zionconstructioninc.com operates within the Construction and Real Estate sector, serving clients and stakeholders in the United States with associated business services and project-related offerings. The entity has been documented in threat-intelligence indexing as a ransomware victim, with its incident profile explicitly associated with thegentlemen, a known threat actor group. This listing type indicates cybersecurity event classification rather than confirmed operational details, ensuring objective catalog representation. The sector context underscores heightened exposure risks within construction and real estate data environments. zionconstructioninc.com was listed as a ransomware victim associated with thegentlemen. |
||||||
| Ransomware | Zion Construction id32203 View details | United States | Construction / Real Estate | — | — | |
|
zionconstructioninc.com Zion Construction Inc is a reputable general contracting and home building company based in Ephrata, Washington.With over three decades of industry experience, they specialize in custom homes, remodeling, and general construction services.The company is recognized for delivering high-quality residential projects and is highly rated among contractors in the region. |
||||||
| Ransomware | Party Rental id32154 View details | United Kingdom | Retail / E-commerce | — | — | |
|
partyrentalltd.com operates within the retail and e-commerce sector and is located in the United Kingdom. The entity is catalogued in this threat-intelligence index under the listing type ransomware victim. Its inclusion reflects an assessed ransomware-related incident linked to thegentlemen, a threat actor operating within the retail and e-commerce threat landscape. This description avoids inventing specific incident details such as stolen data categories, record counts, ransom amounts, or confirmed breach specifics. The entry provides neutral, authoritative context for catalog users evaluating the entity, its sector, geographic location, listing type, and associated threat actor. |
||||||
| Ransomware | Party Rental id32154 View details | United Kingdom | Retail / E-commerce | — | — | |
|
partyrentalltd.com zoominfo.com/c/party-rental-ltd/92603384 is a legitimate, family-owned U.S. event rental company founded in 1972 — one of the largest in the country. HQ and a 300,000 sq ft warehouse are in Teterboro, NJ, with locations in New York City, Philadelphia, Washington D.C., Boston, and the Hamptons. |
||||||
| Ransomware | TEC Container id32155 View details | Brazil | IT | — | — | |
|
teccontainer.com operates within the IT sector and is identified as a ransomware victim within the threat-intelligence index. The entity is associated with thegentlemen, a threat actor linked to ransomware activity targeting organizations in Brazil. This listing reflects verified intelligence concerning the entity's involvement in a ransomware incident, contextualized by its sector and geographic location. The description adheres to neutral, authoritative standards without inventing specific technical details, breach confirmations, or unverified claims regarding data or financial impact. It serves to document the association for cybersecurity analysts monitoring threat actor campaigns and victim profiles. |
||||||
| Ransomware | TEC Container id32155 View details | Brazil | IT | — | — | |
|
teccontainer.com TEC Container is a Spanish manufacturer of spreaders, lifting frames, and container-handling equipment, based in Algete (Madrid) since 1988. The company supplies ports and terminals worldwide, offering brands like TECSPREADER and TECGENSET (its diesel genset line for reefer containers). |
||||||