Ransomware Group intelligence
Thegentlemen
ActiveTrack Thegentlemen with 1098 published victims and 2 known leak locations in a single intelligence view.
Overview
Thegentlemen is tracked by Breach House as a ransomware group with 1098 published victims.
United States is currently the most targeted country in this dataset.
2 known leak locations are currently associated with this group.
Leak Status Distribution
No leak-status data available yet.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (2)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 2 | Onion service | Down checked 22m ago | i2ohjeeqe37jre4f2u7pyq73cbm6lecumdxapkvrlryna6rc3it4zsid.onion |
| Leak location 1 | Onion service | Down checked 22m ago | tezwsse5czllksjb7cwp65rvnk4oobmzti2znn42i43bjdfd2prqqkad.onion |
Top Activity Sectors (20)
- IT 118
- Manufacturing / Engineering 104
- Communication / Marketing 88
- Healthcare / Pharma 68
- Retail / E-commerce 57
- Finance / Legal / Insurance 50
- Construction / Real Estate 48
- Services 44
- Transportation / Travel / Logistics 30
- Not identified 27
- Agriculture / Food 23
- Education 22
- Public Sector 20
- Energy 18
- NGOs / Associations 12
- Hospitality / Food & Beverage / Tourism 12
- Telecommunications 6
- Media / Entertainment 1
- Law Enforcement / Public Sector 1
- Research 1
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Thegentlemen, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: thegentlemen executes PowerShell scripts to run payload logic, disable defenses, and propagate across systems.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: thegentlemen modifies registry run keys and startup locations to maintain persistence after reboots.
What that means: Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: thegentlemen disables or modifies security tools such as EDR and AV processes to hinder incident response.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: thegentlemen deletes Volume Shadow Copies and backup artifacts via system commands to prevent recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1003.001 LSASS Memory Credential Access
What they do: thegentlemen accesses LSASS memory to steal credentials for lateral movement and privilege escalation.
What that means: Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS).
-
T1135 Network Share Discovery Discovery
What they do: thegentlemen uses network share discovery to locate victim file shares and map accessible storage paths for encryption.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: thegentlemen uses SMB/Windows Admin Shares for lateral movement between networked hosts in manufacturing and IT environments.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: thegentlemen encrypts victim files and data stores using ransomware payloads to maximize impact and extortion pressure.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: thegentlemen calls system recovery inhibitors to block restore processes and harden ransomware impact.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
-
T1491.001 Internal Defacement Impact
What they do: thegentlemen performs internal defacement by replacing victim files with ransom notes and altered content.
What that means: An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems.
Tools Observed (64)
▼Software Thegentlemen has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Credential theft
Defense evasion
Discovery
Discovery & enumeration
Exfiltration
LOLBAS (living-off-the-land binaries)
Networking & tunnelling
OffSec
Offensive security tooling
RMM Tools
Remote monitoring & management
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Ransom Notes (3)
▼The note this group leaves on a compromised machine. Click a filename to read it.
README-GENTLEMEN_3.txt
[snip] = YOUR ID Gentlemen, your network has been encrypted. 1. Any modification of encrypted files will make recovery impossible. 2. Only our unique decryption key and software can restore your files. Brute-force, RAM dumps, third-party recovery tools are useless. It’s a fundamental mathematical reality. Only we can decrypt your data. 3. Law enforcement, authorities, and “data recovery” companies will NOT help you. They will only waste your time, take your money, and block you from recovering your files — your business will be lost. 4. Any attempt to restore systems, or refusal to negotiate, may lead to irreversible wipe of all data and your network. 5. We have exfiltrated all your confidential and business data (including NAS, clouds, etc). If you do not contact us, it will be published on our leak site and distributed to major hack forums and social networks. In addition, it will be reported to the relevant data protection authorities and regulators. This may result in official investigations, significant fines, and reputational damage for your company. 6. We guarantee 100% file recovery to their original state, bit by bit. To demonstrate the quality of our work, you can provide three sample files, and we will restore them free of charge. TOX CONTACT - RECOVER YOUR FILES Contact us (add via TOX ID): 13343E50C1B3466F0EA35B5B3E55A044CB7132FD28A8665EFEA0E5848E276D548C21B79F15C2 Download Tox messenger: https://tox.chat/download.html Contact us (add via SimpleX): https://smp14.simplex.im/a#4mlOiePV8NBXOv2QrZ9CaPeRPm1mBUgxn4SdpFnm978 Download SimpleX https://simplex.chat/downloads/ СONTACT TO PREVENT DATA LEAK (7 DAYS BEFORE YOUR COMPANY DATA WILL BE PUBLISHED IN OUR BLOG, WITH 239 HOURS REVEAL TIMER) Check our blog: http://tezwsse5czllksjb7cwp65rvnk4oobmzti2znn42i43bjdfd2prqqkad.onion/ Download Tor browser: https://www.torproject.org/download/ Follow us on X: https://x.com/TheGentlemen26 Clearnet blog link: https://thegentlemen.cc/ Any other means of communication are fake and may be set up by third parties. Only use the methods listed in this note or on the specified website. After adding (us) in Tox or Session, please wait for your request to be processed and stay online. If you do not receive a reply within 36 hours, create another account and contact us again. In your first message in chat, immediately provide your ID from the note and the name of your organization. Assign one person as contact responsible for all negotiations. Do not create multiple chats. We have stolen more than 100 GB of your corporate information from your servers, including critically important data. Your company is facing a massive information security breach. A total data leak has occurred. This greatly increases the risk of colossal financial and reputational losses.
README-GENTLEMEN_2.txt
[snip] = YOUR ID Gentlemen, your network has been encrypted. 1. Any modification of encrypted files will make recovery impossible. 2. Only our unique decryption key and software can restore your files. Brute-force, RAM dumps, third-party recovery tools are useless. It’s a fundamental mathematical reality. Only we can decrypt your data. 3. Law enforcement, authorities, and “data recovery” companies will NOT help you. They will only waste your time, take your money, and block you from recovering your files — your business will be lost. 4. Any attempt to restore systems, or refusal to negotiate, may lead to irreversible wipe of all data and your network. 5. We have exfiltrated all your confidential and business data (including NAS, clouds, etc). If you do not contact us, it will be published on our leak site and distributed to major hack forums and social networks. In addition, it will be reported to the relevant data protection authorities and regulators. This may result in official investigations, significant fines, and reputational damage for your company. 6. We guarantee 100% file recovery to their original state, bit by bit. To demonstrate the quality of our work, you can provide three sample files, and we will restore them free of charge. TOX CONTACT - RECOVER YOUR FILES Contact us (add via TOX ID): 98C132E2B20B531BE6604397D97040C1E9EB42FCE12EDF119BCE8B4031CA5C70DAF5E65FA3C3 Download Tox messenger: https://tox.chat/download.html Contact us (add via Session ID): 05809b2da1d5b1a302f48b5767fd1843d54f3c516f9ab0eb26b544ffa73340292e Download Session https://getsession.org СONTACT TO PREVENT DATA LEAK (7 DAYS BEFORE YOUR COMPANY DATA WILL BE PUBLISHED IN OUR BLOG, WITH 239 HOURS REVEAL TIMER) Check our blog: http://tezwsse5czllksjb7cwp65rvnk4oobmzti2znn42i43bjdfd2prqqkad.onion/ Download Tor browser: https://www.torproject.org/download/ Follow us on X: https://x.com/ Any other means of communication are fake and may be set up by third parties. Only use the methods listed in this note or on the specified website. After adding (us) in Tox or Session, please wait for your request to be processed and stay online. If you do not receive a reply within 36 hours, create another account and contact us again. In your first message in chat, immediately provide your ID from the note and the name of your organization. Assign one person as contact responsible for all negotiations. Do not create multiple chats.
README-GENTLEMEN.txt
[snip] = YOUR ID Gentlemen, your network is under our full control. All your files are now encrypted and inaccessible. 1. Any modification of encrypted files will make recovery impossible. 2. Only our unique decryption key and software can restore your files. Brute-force, RAM dumps, third-party recovery tools are useless. It’s a fundamental mathematical reality. Only we can decrypt your data. 3. Law enforcement, authorities, and “data recovery” companies will NOT help you. They will only waste your time, take your money, and block you from recovering your files — your business will be lost. 4. Any attempt to restore systems, or refusal to negotiate, may lead to irreversible wipe of all data and your network. 5. We have exfiltrated all your confidential and business data (including NAS, clouds, etc). If you do not contact us, it will be published on our leak site and distributed to major hack forums and social networks. TOX CONTACT - RECOVER YOUR FILES Contact us (add via TOX ID): F8E24C7F5B12CD69C44C73F438F65E9BF560ADF35EBBDF92CF9A9B84079F8F04060FF98D098E Download Tox messenger: https://tox.chat/download.html COOPERATE TO PREVENT DATA LEAK (239 HOURS LEFT) Check our blog: http://tezwsse5czllksjb7cwp65rvnk4oobmzti2znn42i43bjdfd2prqqkad.onion/ Download Tor browser: https://www.torproject.org/download/ Any other means of communication are fake and may be set up by third parties. Only use the methods listed in this note or on the specified website.
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (1098)
Search, filter and paginate the victim timeline for Thegentlemen. Showing 101–200 of 1098.
| Type | Target | Discovered | Country | Business Category | Intel Link | Leak status |
|---|---|---|---|---|---|---|
| Ransomware | Verbux id32156 View details | Germany | Transportation / Travel / Logistics | — | — | |
|
verbux.com operates within the Transportation, Travel, and Logistics sector, based in Germany, providing services aligned with freight coordination, passenger movement, and supply chain connectivity. As documented in the threat-intelligence index, verbux.com is classified as a ransomware victim associated with thegentlemen, a threat actor operating from Germany. This listing type indicates a confirmed security incident involving unauthorized access and ransomware activity targeting the entity within its operational domain. The entry reflects verified intelligence linking the organization to thegentlemen without disclosing unconfirmed technical details or secondary breach claims. Stakeholders monitor this record for sector-specific threat patterns and defensive context. |
||||||
| Ransomware | Verbux id32156 View details | Germany | Transportation / Travel / Logistics | — | — | |
|
verbux.com zoominfo.com/c/verbux-soluciones-informáticas-limitada/457993216 Verbux is a Chilean IT company — Verbux Soluciones Informáticas Limitada — operating since 2001, headquartered at Juana de Arco Nº2012, Oficina 33, Providencia, Santiago, Chile (also verbux.cl). It delivers IT infrastructure, engineering, professional IT services, cloud computing, IoT and SCADA process-control solutions for industrial, mining and power-generation clients. Claims 1,000+ implemented IT solutions (from file servers to data centers with high availability), and is currently implementing ISO 9001:2015 quality certification. |
||||||
| Ransomware | Espinos id32157 View details | Mexico | Energy | — | — | |
|
espinos.energy operates within the Energy sector and is associated with the country Mexico. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim, linked to thegentlemen as the associated threat actor or source. Publicly available information does not confirm specific incident details such as data stolen, ransom demands, or operational impact; therefore, this description remains factual and neutral regarding the entity’s sector, location, and classification. The listing reflects documented intelligence linking espinos.energy to thegentlemen within ransomware victim records. This entry supports threat-aware cataloging for Energy sector security professionals tracking actor-linked incidents across jurisdictions. |
||||||
| Ransomware | Espinos id32157 View details | Mexico | Energy | — | — | |
|
espinos.energy dnb.com/business-directory/company-profiles.espinos_sa.7081c859ec6ec62bc369252d901ee655.html Espinos S.A. is a Chilean power generation company operating under the Potencia Chile brand (Grupo Agrisol), with 17 years of experience and ~260 MW of installed capacity. It runs a diversified portfolio: thermal (Central Espinos in Los Vilos), hydroelectric (Renaico, Alto Renaico), solar (Lipangue, Pumas) and battery storage (BESS Mandarinos). Headquartered at Av. Apoquindo 4501, Las Condes, Santiago, Chile; RUT 76.925.800-0. |
||||||
| Ransomware | Incolur id32158 View details | Chile | Services | — | — | |
|
incolur.cl operates within the Services sector and is situated in Chile (country code CL). The entity is cataloged as a ransomware victim within this threat-intelligence index, with its association explicitly linked to thegentlemen, a known threat actor. Publicly available records do not confirm specific technical details of the incident, including data accessed, impact scope, or recovery actions. This listing provides neutral contextual information for analysts monitoring threat actor activity and victim profiles across sectors and geographies. The designation reflects the entity's inclusion in ransomware victim indexing tied to thegentlemen. |
||||||
| Ransomware | Incolur id32158 View details | Chile | Services | — | — | |
|
incolur.cl zoominfo.com/c/incolur/372497016 Incolur Corretajes Limitada is a Chilean import & distribution company specialized in industrial supplies. It imports and distributes: machine tools and their accessories, abrasives (grinding/cutting wheels), welding equipment, measuring & precision instruments, industrial gauges and tooling for workshops and construction. De facto it works as a B2B supplier, reselling international industrial brands to the Chilean market. |
||||||
| Ransomware | AGS Cinemas id32022 View details | India | Services | — | — | |
|
agscinemas.com operates within the Services sector and is headquartered in India. The entity functions as a commercial organization providing services aligned with its sector classification. Within threat-intelligence indexing frameworks, agscinemas.com is cataloged specifically as a ransomware victim linked to thegentlemen, a documented threat actor. This listing reflects the entity's inclusion in cybersecurity databases tracking ransomware incidents and associated actors. No specific incident details, such as data stolen, ransom demands, or breach confirmation, are attributed here; the description remains strictly aligned with the indexed classification. |
||||||
| Ransomware | AGS Cinemas id32022 View details | India | Services | — | — | |
|
agscinemas.com zoominfo.com/c/ags-cinemas-private-ltd/356074293 AGS Cinemas is a prominent multiplex chain and film exhibition company based in Chennai, India, operating under the AGS Entertainment brand. The theaters feature state-of-the-art technical facilities, including Dolby Atmos sound systems and 4K projection for a premium viewing experience. Their official platform allows customers to easily book tickets online and pre-order a wide variety of food and beverages for their visit. |
||||||
| Ransomware | Eyecare Center of Snohomish id32023 View details | United States | Healthcare / Pharma | — | — | |
|
eyecarecenterofsnohomish.com operates within the healthcare and medicine sector, providing eye care services likely serving the Snohomish region of the United States. As a healthcare organization, it handles sensitive patient information and clinical services, making it a potential target for cyber threats. This entity is cataloged in the threat-intelligence index under the listing type ransomware victim, specifically linked to thegentlemen threat actor. The association indicates documented threat activity targeting this organization. This listing reflects verified intelligence regarding the entity's exposure to ransomware incidents connected to thegentlemen. |
||||||
| Ransomware | Eyecare Center of Snohomish id32023 View details | United States | Healthcare / Pharma | — | — | |
|
eyecarecenterofsnohomish.com zoominfo.com/c/eyecare-center-of-snohomish/442336650 Eyecare Center of Snohomish is a trusted optometry clinic in Snohomish, Washington, proudly serving its community since 1964. They offer comprehensive vision and medical eye exams, diagnosing and treating various eye diseases to ensure long-term ocular health. The clinic also features a full-service optical boutique offering custom-fitted contact lenses and designer eyewear frames from top global brands. |
||||||
| Ransomware | Gould Sherwood Consulting id32024 View details | United States | Services | — | — | |
|
gouldsherwood.com operates within the Services sector and is located in the United States. The entity represents a commercial organization whose security posture was impacted by a ransomware incident. This listing identifies gouldsherwood.com specifically as a ransomware victim linked to thegentlemen, a threat actor of interest within cyber threat intelligence frameworks. The catalog entry reflects documented intelligence associating the domain with this actor and incident classification without disclosing unverified technical or operational details. Understanding such associations supports risk assessment and threat tracking for sector-focused security analysis. |
||||||
| Ransomware | Gould Sherwood Consulting id32024 View details | United States | Services | — | — | |
|
gouldsherwood.com zoominfo.com/c/gould-sherwood-consulting-llc/347553210 Gould-Sherwood Consulting is a boutique IT support and services firm based in Lexington, Massachusetts, serving the Greater Boston area since 2005. They specialize in comprehensive computer and network support, including planning, maintenance, and troubleshooting for both Mac and PC environments. The company primarily caters to small-to-medium businesses, creative professionals, and home users, ensuring their technology infrastructure runs smoothly and securely. |
||||||
| Ransomware | Espac id32025 View details | Chile | Services | — | — | |
|
espac.cl operates within the Services sector and is associated with the country of Chile. The entity functions as a commercial organization within this service context and is cataloged within the threat-intelligence index under the designation ransomware victim. This listing reflects an assessed relationship between espac.cl and thegentlemen, a threat actor identified in cyber-threat intelligence records. The description avoids speculative claims regarding breach details, data exfiltration, or operational impact, maintaining a neutral and authoritative tone consistent with catalog documentation standards. The classification serves to inform threat analysts and security stakeholders about this entity's association with thegentlemen within the ransomware victim category. |
||||||
| Ransomware | Espac id32025 View details | Chile | Services | — | — | |
|
espac.cl zoominfo.com/c/espac/425816287 ESPAC Construcción is a leading Chilean company based in Santiago that manufactures and distributes specialized products for the building industry. They produce high-quality construction materials, including steel shores, heavy-duty pallets, scaffolding systems, and material handling carts. Additionally, the firm offers comprehensive rental services for formwork and structural support equipment to assist large-scale construction projects across the country. |
||||||
| Ransomware | Layher id32026 View details | Chile | Services | — | — | |
|
layher.cl operates within the Services sector and is located in Chile (country code CL). The entity represents a business organization whose infrastructure was impacted by a ransomware incident. According to the threat-intelligence index, layher.cl was formally listed as a ransomware victim associated with thegentlemen, a threat actor identified in cyber threat reporting. This listing reflects the entity's connection to the attack campaign without disclosing unverified technical details or confirming specific breach elements. The catalog entry serves to inform security teams and analysts about affected organizations within the Services sector across Latin American regions. |
||||||
| Ransomware | Layher id32026 View details | Chile | Services | — | — | |
|
layher.cl zoominfo.com/c/layher-del-pacífico-sa--layher-chile/1319092699 Layher Chile is the local branch of the globally renowned German manufacturer specializing in scaffolding and access systems. They supply high-quality scaffolding solutions, safety equipment, and event structures for the construction, industrial, and infrastructure sectors. The company provides comprehensive services, including product sales, equipment rentals, custom engineering design, and technical support for complex projects across the country. |
||||||
| Ransomware | Volktek id32027 View details | Singapore | IT | — | — | |
|
volktek.com operates within the IT sector and serves as a technology-focused entity referenced in threat-intelligence indexing. Its inclusion as a ransomware victim indicates an incident where thegentlemen, a threat actor identified in cyber threat intelligence records, was associated with activity against this organization. The entity is geographically linked to Singapore (SG), aligning with the reported country context for this listing. This catalog entry provides neutral descriptive context for researchers assessing ransomware victim profiles, threat actor relationships, and sector-specific exposure patterns without disclosing unverified incident details such as stolen data, ransom terms, or confirmed breach specifics. |
||||||
| Ransomware | Volktek id32027 View details | Singapore | IT | — | — | |
|
volktek.com zoominfo.com/c/volktek-corp/161873991 Volktek is a leading Taiwanese manufacturer established in 1994, specializing in high-performance industrial networking and Ethernet solutions. They design and produce a wide range of robust equipment, including industrial Ethernet switches, PoE devices, and fiber optic converters. With in-house production facilities, the company provides reliable connectivity and automation infrastructure for metro networks, surveillance, and harsh industrial environments. |
||||||
| Ransomware | Volktek id32027 View details | Taiwan, Province of China | IT | — | — | |
|
volktek.com zoominfo.com/c/volktek-corp/161873991 Volktek is a leading Taiwanese manufacturer established in 1994, specializing in high-performance industrial networking and Ethernet solutions. They design and produce a wide range of robust equipment, including industrial Ethernet switches, PoE devices, and fiber optic converters. With in-house production facilities, the company provides reliable connectivity and automation infrastructure for metro networks, surveillance, and harsh industrial environments. |
||||||
| Ransomware | Meridian Logistics Group id31958 View details | United States | — | — | — | |
|
Full network image staged. ERP exports, dispatch DB and payroll archives recovered. Pending final inventory before publication. |
||||||
| Ransomware | UOLconsult id31976 View details | Brazil | — | — | — | |
|
uol-consult.com UOLconsult GmbH is a boutique management consulting firm based in Vienna, Austria, founded in 2015. They specialize in strategic management, business development, and investment consulting. |
||||||
| Ransomware | UOLconsult id31976 View details | Austria | — | — | — | |
|
uol-consult.com UOLconsult GmbH is a boutique management consulting firm based in Vienna, Austria, founded in 2015. They specialize in strategic management, business development, and investment consulting. |
||||||
| Ransomware | dlp motive id31977 View details | Germany | — | — | — | |
|
dlp-motive.de dlp motive is a German full-service event technology provider founded in 2007, successfully realizing around 600 projects annually. They offer comprehensive technical solutions including lighting, audio, video, kinetics, and rigging for corporate, e-sports, and public events. The company handles the entire event lifecycle, providing everything from initial concept and design to logistics, on-site production, and equipment rental. |
||||||
| Ransomware | AWJ Holding id31978 View details | United Arab Emirates | — | — | — | |
|
awjholding.com zoominfo.com/c/awj-holding-co/448239448 AWJ Holding Company is a prominent Saudi-based single-family office and investment firm established in 2016. Headquartered in Riyadh, the company specializes in real estate development, property management, and strategic investment management. It focuses on high-impact developments and operates dynamic subsidiaries across retail, hospitality, and infrastructure sectors. |
||||||
| Ransomware | Lexacaucho id31979 View details | — | — | — | ||
|
lexacaucho.com zoominfo.com/c/lexacaucho--laminados-y-extruidos-de-caucho-sac/457170004 Lexacaucho is a Peruvian manufacturing company based in Lima with over 25 years of experience in the rubber and polymer industry. They specialize in producing molded rubber sheets, profiles, linings, and custom parts using materials like natural rubber, SBR, and EPDM. The company primarily serves the mining, fishing, and general industrial sectors by providing durable elastomer solutions. |
||||||
| Ransomware | LOG Systems id31980 View details | Poland | — | — | — | |
|
logsystem.pl zoominfo.com/c/log-systems/372786485 LOG Systems is a Polish software company based in Wrocław that develops comprehensive IT management and Helpdesk solutions. Their flagship product, LOG Plus, is an advanced ITSM platform designed to streamline ticketing, incident management, and IT infrastructure monitoring. The software also includes powerful Software Asset Management features to help organizations optimize licensing and ensure data security. |
||||||
| Ransomware | Magdalena Grand Beach Golf Resort id31981 View details | Mexico | — | — | — | |
|
magdalenagrand.com zoominfo.com/c/magdalena-grand-beach--golf-resort/348187300 Magdalena Grand Beach & Golf Resort is a luxury hotel and resort located in Lowlands on the beautiful island of Tobago. It features premium oceanfront accommodations with access to a championship golf course, spa, pools, and tennis courts. The property is also a popular destination for weddings, offering guests a variety of dining options and vibrant nightlife. |
||||||
| Ransomware | Akatake Engineering id31982 View details | Japan | — | — | — | |
|
akatake.co.jp crunchbase.com/organization/akatake-engineering-co-ltd Akatake Engineering Co., Ltd. is a Japanese manufacturing company based in Numazu, Shizuoka, established in 1971. They specialize in powder handling technology, providing comprehensive solutions for the storage, feeding, weighing, and transportation of bulk powders. The company designs and manufactures custom industrial equipment and container systems for various industries dealing with fine particulate materials. |
||||||
| Ransomware | ESCON Group id31983 View details | United States | — | — | — | |
|
escon.us zoominfo.com/c/escon-group/352605618 ESCON Group is a veteran-owned electrical contracting company based in Bay City, Michigan, with a history tracing back to 1907. They specialize in providing comprehensive commercial and residential electrical services, low voltage solutions, and fiber optics. The company also offers advanced security systems, smart integrations, and robust commercial generator installations to ensure reliable power. |
||||||
| Ransomware | Almeer id31984 View details | United Arab Emirates | — | — | — | |
|
al-meergroup.com zoominfo.com/c/almeer/1326290906 Almeer General Contracting Establishment is a Saudi-owned company established in 2010 and headquartered in Jubail, Saudi Arabia. They specialize in comprehensive electrical, civil construction, and mechanical erection services for industrial facilities. The firm primarily serves large-scale sectors, including oil refineries and fertilizer plants, utilizing a team of qualified engineers. |
||||||
| Ransomware | Geb Sas id31985 View details | France | — | — | — | |
|
geb.fr zoominfo.com/c/geb-sas/372743980 GEB SAS is a historic French chemical manufacturing company established in 1860. They specialize in formulating and producing essential sealing solutions, adhesives, and PVC glues. The family-owned business primarily provides high-quality maintenance and installation products for plumbing and heating professionals. |
||||||
| Ransomware | ARBEITERKAMMERN id31986 View details | Austria | — | — | — | |
|
arbeiterkammer.at The Austrian Chamber of Labour is a statutory public organization dedicated to representing the interests of employees and consumers across Austria. It provides its members with free legal advice on labor and social law, educational support, and strong consumer protection services. The organization actively advocates for workers' rights, fair wages, and social justice through extensive research and political lobbying. |
||||||
| Ransomware | Aquasea id31987 View details | Norway | — | — | — | |
|
aquasea.com rocketreach.co/aquasea-inc-profile_b468216cfc5c9f6e Aquasea Inc. is a clothing and apparel manufacturing company headquartered in Compton, California, operating since 1995. The business specializes in full-package production, including cut and sew services, private label manufacturing, and screen printing. They also operate nearshore textile manufacturing facilities to support their comprehensive apparel production capabilities. |
||||||
| Ransomware | CAZ Investments id31988 View details | Belize | — | — | — | |
|
cazinvestments.com zoominfo.com/c/caz-investments-lp/16765398 CAZ Investments We have taken NDA files, HR data, user data, employee data, models, bank statements, tax and legal documents, confidential files, photos of your work and leisure time, screenshots, information about interactions with offshore accounts, your and your clients' dirty laundry, passport scans, VIP client data, and much more the total volume of data exceeds 478 GB. is a Houston-based wealth management and multi-family office firm founded in 2001. They manage over $10.3 billion in assets, providing exclusive access to alternative investments like private equity, credit, and sports ownership. The firm curates unique investment opportunities for a global network of individual investors, financial advisors, and institutions. |
||||||
| Ransomware | Oceanica Internacional id31989 View details | Samoa | — | — | — | |
|
oceanica.ws Oceanica Internacional is a comprehensive logistics and freight forwarding company operating across Central America. They serve as a strategic logistics partner, providing international trade and supply chain solutions in countries like Costa Rica, Panama, and Guatemala. The company specializes in coordinating imports, exports, and cargo transportation to support businesses throughout the region. |
||||||
| Ransomware | Ariel Energia id31990 View details | Italy | — | — | — | |
|
arielenergia.it zoominfo.com/c/gdl-spa/1311974459 Ariel Energia is a prominent Italian company based in Turin with over 40 years of experience in the home energy and comfort sector. They specialize in producing and distributing "Made in Italy" heating and cooling solutions, including pellet stoves, boilers, and air conditioners. The company also provides renewable energy systems like photovoltaics and advanced water purifiers to promote sustainability and energy efficiency. |
||||||
| Ransomware | BioPharma id31849 View details | — | — | — | ||
|
BioPharma is a global biopharmaceutical innovator founded in 2003 and headquartered in Taiwan. It specializes in developing best-in-class therapies and biologics for blood disorders, hematologic cancers, and other serious diseases. The company is fully integrated and operates internationally with a strong commercial and clinical presence in the U.S., Europe, and Japan. |
||||||
| Ransomware | BioPharma id31849 View details | United States | — | — | — | |
|
BioPharma is a global biopharmaceutical innovator founded in 2003 and headquartered in Taiwan. It specializes in developing best-in-class therapies and biologics for blood disorders, hematologic cancers, and other serious diseases. The company is fully integrated and operates internationally with a strong commercial and clinical presence in the U.S., Europe, and Japan. |
||||||
| Ransomware | P**** R***** id31850 View details | — | — | — | ||
|
full-service event rental company established in 1972, specializing in high-quality items and equipment for special events. They serve the Northeast and Mid-Atlantic regions along the East Coast, offering an extensive selection of furniture, linens, and decor. The company is dedicated to helping clients bring their unique event visions to life with professional customer care and design support. With its main facility in Teterboro, New Jersey, and a showroom in New York City, it remains a leading provider in the event services industry. |
||||||
| Ransomware | Euroscreen id31911 View details | Italy | — | — | — | |
|
euroscreen.it zoominfo.com/c/euroscreen-srl/454657849 Euroscreen is a leading Italian company specializing in digital printing technologies and the manufacturing of high-quality projection screens. They design and produce a wide range of professional and home cinema screens entirely in Italy, including motorized models up to 12 meters wide and projector lifts. Their bespoke audio-visual and printing solutions are exported worldwide to serve both commercial and residential markets. |
||||||
| Ransomware | CRASL id31912 View details | United Kingdom | — | — | — | |
|
crasl.co.uk zoominfo.com/c/crasl-accounting-services/355829364 CRASL Accounting Services is an approachable, user-friendly accounting firm based in Suffolk, UK, dedicated to supporting individuals, sole traders, and growing businesses. They combine traditional financial values with modern efficiency, offering personalized bookkeeping, tax planning, and strategic business advice. Their client-focused approach ensures you receive the clear insights and practical tools needed to make confident decisions and achieve your financial goals. |
||||||
| Ransomware | Senvest Capital id31913 View details | Canada | — | — | — | |
|
senvest.com zoominfo.com/c/senvest-capital-inc/91423931 Senvest (including Senvest Capital and Senvest Management) is a major international investment firm and hedge fund sponsor managing billions of dollars in assets. Founded by Richard Mashaal, it specializes in contrarian value investing strategies across public equities, private markets, and real estate. Headquartered in New York and Montreal, the firm focuses on discretionary investment advisory services and direct capital deployment for institutional clients. |
||||||
| Ransomware | Roadvision Systems id31914 View details | Sweden | — | — | — | |
|
roadvision.com zoominfo.com/c/roadvision-systems-llc/358950436 Roadvision is a cloud-based trucking management software (TMS) designed to help logistics companies and carriers, particularly in the less-than-truckload (LTL) sector, operate more efficiently. Headquartered in Hanover, New Hampshire, it provides an all-in-one platform to automate workflows, reduce operational costs, and modernize fleet management. |
||||||
| Ransomware | Babcock id31915 View details | South Africa | — | — | — | |
|
babcock.co.za rocketreach.co/babcock-international-group-africa-profile_b5cda591f42e0b42 Babcock Africa is a leading engineering and asset management company specializing in critical infrastructure and heavy equipment across the African continent. With over 130 years of experience, it provides lifetime engineering solutions, including industrial power systems, construction machinery, plant hire, and defense support. The company partners with demanding sectors such as energy, mining, transport, and manufacturing to ensure safe, reliable, and efficient operations. Its core focus is on designing, building, and sustaining complex assets through comprehensive maintenance and innovative technical services. |
||||||
| Ransomware | IPS id31673 View details | Italy | IT | — | — | |
|
IPSSRL.com is an Italian company operating in the IT sector, providing various services and solutions. The company is based in Italy and caters to the needs of its clients in the IT industry. IPSSRL.com was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | IPS id31673 View details | Italy | IT | — | — | |
|
ipssrl.com zoominfo.com/c/ips-srl/372710487 I.P.S. Srl is an Italian company founded in 2005 that specializes in the recovery and recycling of inert waste from construction and demolition activities. They provide environmental services, supply recycled aggregates, and manufacture "Wastile," a 100% ecological and infinitely recyclable thermoplastic tile. The company has received national awards for its rapid revenue growth and high financial reliability in the environmental sector. |
||||||
| Ransomware | Gfeller Treuhand und Verwaltungs id31675 View details | Switzerland | — | — | — | |
|
gfeller-treuhand.ch zoominfo.com/c/gfeller-treuhand-und-verwaltungs-ag/372661395 Gfeller Treuhand und Verwaltungs AG is a Swiss real estate and fiduciary company based in Dübendorf, operating since 1980. They specialize in comprehensive property management, real estate sales, and leasing services. The firm provides professional administrative support, utilizing modern IT solutions to efficiently handle property maintenance and tenant relations. |
||||||
| Ransomware | Gravity Coffee id31677 View details | United States | — | — | — | |
|
gravitycoffee.com zoominfo.com/c/gravity-coffee-company-llc/373342412 Gravity Coffee is a premium coffee brand known for serving high-quality beverages in its physical cafes and through retail products. Their signature medium roast blends feature a bold, smooth flavor profile with popular notes of hazelnut and chocolate. The company operates multiple locations and focuses on providing an exceptional coffee experience for its customers |
||||||
| Ransomware | Ollies Place Kidswear id31679 View details | Australia | — | — | — | |
|
olliesplace.com.au zoominfo.com/c/ollies-place-kidswear/359503050 Ollie's Place is an Australian retail brand specializing in high-quality, trendy, and comfortable clothing for babies and children. The company offers a unique shopping experience both online and through physical stores across Australia, featuring vibrant prints and stylish designs. They focus on providing fashionable, value-for-money pieces for kids' everyday wear and special milestones. |
||||||
| Ransomware | The Coffee Bean id31680 View details | Malaysia | — | — | — | |
|
coffeebean.com.my zoominfo.com/c/the-coffee-bean/425047768 The Coffee Bean & Tea Leaf Malaysia is the official digital portal for the popular cafe chain, which currently operates over 150 locations across the country. The website allows customers to easily explore the full menu, access exclusive promotions, and manage their MyCBTL loyalty app rewards. It serves as a convenient central platform for ordering premium beverages, redeeming digital vouchers, and staying updated on seasonal cafe offerings. |
||||||
| Ransomware | KFC Kosova id31681 View details | — | — | — | ||
|
kfckosova.com zoominfo.com/c/kfc-kosova/401225793 KFC Kosova is the official regional branch of the global fast-food chain, operating multiple restaurants across Kosovo, including a prominent location at the Albi Mall in Pristina. Their website serves as a central hub for customers to find nearby branches, check out menu options, and access delivery services. Additionally, the platform acts as a primary career portal for local job seekers to apply for various corporate and restaurant positions. |
||||||
| Ransomware | First Coast Heart Vascular Center id31682 View details | United States | — | — | — | |
|
firstcoastheart.com zoominfo.com/c/first-coast-heart--vascular-center/356606344 First Coast Heart & Vascular Center is a premier cardiovascular care provider serving patients across Northeast Florida. Their website highlights a comprehensive range of services, including expert cardiology, electrophysiology, advanced imaging, and vascular surgery. The medical center focuses on delivering innovative, evidence-based treatments and minimally invasive procedures to ensure the highest standard of heart health. |
||||||
| Ransomware | Cityside Homes id31683 View details | United Kingdom | — | — | — | |
|
citysidehomes.com zoominfo.com/c/cityside-homes-llc/355153806 Cityside Homes is a new construction home builder based in Houston, Texas, specializing in developing homeowner-focused residential communities. Since 2011, the company has built over 100 distinct neighborhoods, offering modern living spaces tailored to local buyers. Their website serves as a primary resource for exploring floor plans, browsing model homes, and discovering available properties across the greater Houston area. |
||||||
| Ransomware | Retail Business Management Systems id31684 View details | United Kingdom | — | — | — | |
|
rbms.com zoominfo.com/c/retail-business-management-systems-inc/101712744 Retail Business Management Systems (RBMS) is a specialized technology provider that has delivered Point of Sale and retail management solutions for over 25 years. Focusing heavily on NCR Counterpoint software and hardware integrations, the company supports retail businesses of all sizes primarily across the New York and New Jersey regions. Their platform serves as a central hub for merchants seeking comprehensive tools to optimize store operations, inventory tracking, and overall customer experience. |
||||||
| Ransomware | TOA id31685 View details | Japan | — | — | — | |
|
toa-const.co.jp zoominfo.com/c/toa-corp/425840057 TOA Corporation is a prominent Japanese general contractor specializing in marine civil engineering, land reclamation, and port infrastructure development. The company focuses on delivering high-quality, economically viable construction projects while prioritizing environmental sustainability and technological innovation. Through its corporate portal, stakeholders can access detailed information on their advanced engineering services, corporate philosophy, and investor relations. |
||||||
| Ransomware | Tempel id31686 View details | Germany | — | — | — | |
|
tempel.com zoominfo.com/c/tempel/87867666 Tempel Steel Company, a division of Worthington Steel, is a leading global manufacturer of high-precision electrical steel laminations. Established in 1945, the company provides essential components for motors, generators, and transformers used across the automotive, eMobility, and energy sectors. Their platform showcases advanced precision metal stamping and overmolding services designed to improve product performance and efficiency. |
||||||
| Ransomware | Plaza Auto Mall id31687 View details | Mexico | — | — | — | |
|
plazaautomall.com zoominfo.com/c/plaza-auto-mall/194512238 Plaza Auto Mall is a family-owned dealership group based in Brooklyn, New York, that has been serving local drivers since 1975. They offer an extensive inventory of over 1,000 new, used, and certified pre-owned vehicles across multiple automotive brands all in one location. The platform also provides comprehensive automotive services, including financing options, vehicle maintenance, parts sales, and a dedicated body shop. |
||||||
| Ransomware | Avanta Maroc Ex Adecco id31688 View details | Morocco | — | — | — | |
|
avanta.ma rocketreach.co/avanta-maroc-ex-adecco-profile_b7352c87c4297b95 Avanta Maroc, formerly known as Adecco Maroc, is a prominent human resources and recruitment agency based in Casablanca, Morocco. The company specializes in connecting job seekers with top employers by offering tailored workforce solutions and staffing services. Their platform serves as a vital hub for career opportunities, professional development, and corporate HR management across various industries in the region. |
||||||
| Ransomware | EKEPIS id31689 View details | Greece | — | — | — | |
|
ekepis.gr rocketreach.co/ekepis-ethniko-kentro-pistopoiisis-domon-profile_b6d46b6ac7408ffe EKEPIS was Greece's National Centre for the Accreditation of Continuing Vocational Training, responsible for certifying adult educators and lifelong learning providers. The organization no longer exists, as its accreditation and certification duties were absorbed by EOPPEP (ΕΟΠΠΕΠ), the National Organisation for the Certification of Qualifications and Vocational Guidance. Today, anyone looking for their services must go through EOPPEP or the official Greek government portal, since the old ekepis.gr domain is no longer an official resource. |
||||||
| Ransomware | Megalaser Industria Metalurgica LTDA id31690 View details | Brazil | — | — | — | |
|
megalaser.com.br zoominfo.com/c/megalaser-industria-metalúrgica-ltda/1315472404 Megalaser is a Brazilian metallurgical company based in São Paulo, specializing in advanced metalworking services like laser cutting, CNC bending, and robotic welding. Founded in 2006, the manufacturer provides high-quality machined components and assemblies for diverse industries, including renewable energy, mining, automotive, and oil and gas. Their platform highlights a strong commitment to precision engineering, integrated manufacturing solutions, and sustainable industrial practices. |
||||||
| Ransomware | Community Connections id31691 View details | United States | — | — | — | |
|
comconnections.org zoominfo.com/c/community-connections-inc/350834294 Community Connections is a non-profit organization based in Ketchikan, Alaska, dedicated to providing individualized support for children, seniors, and individuals with disabilities. Founded over 40 years ago, their core mission focuses on encouraging independence, community belonging, and improving the overall quality of life for those they serve. The organization offers a wide range of specialized programs, including early childhood learning, mental health support, and comprehensive disability services. |
||||||
| Ransomware | Acli id31692 View details | Italy | — | — | — | |
|
acli.it zoominfo.com/c/acli/372618594 ACLI (Christian Associations of Italian Workers) is a major Italian Catholic social promotion organization founded in 1944 to advocate for labor rights and human dignity. Operating a vast network of local clubs, the association provides essential community services, including tax assistance, employment support, and vocational training. Today, it continues to champion social solidarity, democratic participation, and active citizenship across Italy and internationally. |
||||||
| Ransomware | Vector Two Technology id31693 View details | Brazil | IT | — | — | |
|
vtt.com.br zoominfo.com/c/vtt/372441609 VTT is a pioneering Brazilian technology company founded in 1996 that specializes in Digital Signage and Retail Media solutions. As a leading provider in Latin America, the company delivers innovative digital displays, menu boards, and interactive customer experience tools for the retail sector. Their platform also supports a robust channel partner program, helping businesses across the region modernize their visual communication and in-store marketing strategies. |
||||||
| Ransomware | Safeware id31658 View details | United States | IT | — | — | |
|
Safewareinc.com is an IT company based in the United States, offering various services within the IT sector. As a US-based entity, safewareinc.com operates in a highly competitive market, providing IT solutions to its clients. It was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | Safeware id31658 View details | United States | IT | — | — | |
|
safewareinc.com Safeware Inc. is a national leader providing safety and security solutions for first responders, schools, and government agencies. For over 40 years, they have supplied advanced protective equipment and public preparedness training across the United States. The company simplifies government purchasing by offering specialized gear through competitive cooperative contract pricing. |
||||||
| Ransomware | PharmaEssentia id31506 View details | Taiwan, Province of China | Healthcare / Pharma | — | — | |
|
PharmaEssentia is a Taiwan-based company operating in the healthcare and pharmaceutical sector, offering various products and services. The company is involved in the development and manufacturing of pharmaceuticals. PharmaEssentia was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | PharmaEssentia id31506 View details | Taiwan, Province of China | Healthcare / Pharma | — | — | |
|
pharmaessentia.com zoominfo.com/c/pharmaessentia-corp/145441146 PharmaEssentia is a global biopharmaceutical innovator founded in 2003 and headquartered in Taiwan. It specializes in developing best-in-class therapies and biologics for blood disorders, hematologic cancers, and other serious diseases. The company is fully integrated and operates internationally with a strong commercial and clinical presence in the U.S., Europe, and Japan. |
||||||
| Ransomware | CONTAC Ingenieros id31507 View details | Chile | IT | — | — | |
|
contac.cl is an IT company based in Chile, providing various IT services. As an entity in the IT sector, contac.cl operates in the technology industry, catering to clients in Chile. contac.cl was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | CONTAC Ingenieros id31507 View details | Chile | IT | — | — | |
|
contac.cl zoominfo.com/c/contac-ingenieros-division-sistemas/372522727 Contac is a technology company based in Santiago, Chile, specializing in operations and asset management technologies. They provide comprehensive automation services and real-time information systems to help industrial clients maximize their operational performance. The company focuses on delivering custom solutions to optimize asset management, reduce costs, and improve overall system reliability. |
||||||
| Ransomware | RAK Construction id31508 View details | India | Construction / Real Estate | — | — | |
|
Rak Construction is a construction and real estate company based in India, offering various services in the sector. The company operates in the Indian market, providing construction and real estate solutions. Rakconstruction.in was listed as a ransomware victim associated with thegentlemen. |
||||||
| Ransomware | RAK Construction id31508 View details | India | Construction / Real Estate | — | — | |
|
rakconstruction.in zoominfo.com/c/rak-construction/1266108608 RAK Construction is a premier construction company based in Bangalore, India, with over 20 years of industry experience. They specialize in delivering high-quality residential and commercial building projects as a leading civil contractor. The company employs a dedicated team of professionals focused on providing reliable construction and contracting services. |
||||||
| Ransomware | Lancesoft India id31509 View details | India | IT | — | — | |
|
Lancesoft.in is an Indian IT company, operating in the information technology sector. The company is based in India and provides various IT services. Lancesoft.in was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | Lancesoft India id31509 View details | India | IT | — | — | |
|
lancesoft.in zoominfo.com/c/lancesoft-india/547301190 LanceSoft India is a key division of a global workforce solutions and IT services company founded in 2000. Based in Bengaluru, it employs thousands of professionals to deliver comprehensive staffing solutions, including temporary and permanent placements. The company connects businesses worldwide with top-tier talent across diverse industries such as IT, engineering, and healthcare. |
||||||
| Ransomware | AIMS Group id31510 View details | United Kingdom | IT | — | — | |
|
Aimsgroup.com is an IT company based in the United Kingdom, providing various IT services. The company operates in the IT sector, offering services to clients in GB. Aimsgroup.com was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | AIMS Group id31510 View details | United Kingdom | IT | — | — | |
|
aimsgroup.com AIMS Group LLC is a major conglomerate based in Ajman, UAE, established in 2003 with a workforce of thousands. It operates primarily in the environmental services and construction sectors, specializing in infrastructure and road development. The company provides comprehensive industrial solutions, including asphalt production, building materials supply, and fleet management |
||||||
| Ransomware | AnMed id31511 View details | United States | Healthcare / Pharma | — | — | |
|
AnMed Health is a healthcare organization based in the United States, providing medical services to patients. The organization operates in the healthcare sector, offering various medical treatments and care. AnMed Health was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | AnMed id31511 View details | United States | Healthcare / Pharma | — | — | |
|
anmed.org zoominfo.com/c/anmed/1238269198 AnMed is an independent, not-for-profit health system founded in 1908, serving Upstate South Carolina and northeast Georgia. Its anchor facility, AnMed Medical Center, is a 461-bed acute care hospital located in Anderson, South Carolina. The network provides comprehensive medical services, including emergency care, cardiovascular surgery, advanced imaging, and specialized outpatient clinics. |
||||||
| Ransomware | NTU Alumni Club id31512 View details | Singapore | NGOs / Associations | — | — | |
|
ntualumni.org.sg is a website of the Nanyang Technological University Alumni Association in Singapore, providing services and resources to its members. As an association, it aims to foster a sense of community among its alumni. ntualumni.org.sg was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | NTU Alumni Club id31512 View details | Singapore | NGOs / Associations | — | — | |
|
ntualumni.org.sg zoominfo.com/c/ntu-alumni-club/447180090 The NTU Alumni Club is an independent association for graduates of Nanyang Technological University in Singapore. It serves as a dedicated platform for alumni to connect, network, and maintain a lifelong relationship with their alma mater. Members enjoy exclusive perks, career opportunities, and access to physical facilities like lounges and co-working spaces at their clubhouse. |
||||||
| Ransomware | Canopy Support Services id31513 View details | Canada | Healthcare / Pharma | — | — | |
|
canopysupport.ca is a Canadian entity operating in the healthcare and medicine sector, providing support services. Located in Canada, the company offers various services to healthcare providers. canopysupport.ca was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | Canopy Support Services id31513 View details | Canada | Healthcare / Pharma | — | — | |
|
canopysupport.ca zoominfo.com/c/canopy-support-services/347650822 Canopy Support Services is a community-based organization in Peterborough, Ontario, dedicated to supporting individuals with intellectual and developmental disabilities. They provide a safe, welcoming environment for people, including those with Autism Spectrum Disorder, to learn new skills and achieve their personal goals. The organization empowers its clients to overcome everyday barriers, build self-confidence, and lead more independent lives |
||||||
| Ransomware | Mikel Coffee id31514 View details | Mexico | Retail / E-commerce | — | — | |
|
Mikelcoffee.com is an e-commerce company based in Mexico, operating in the retail sector. The company likely offers various products for sale online, catering to customers in Mexico and possibly other countries. Mikelcoffee.com was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | Mikel Coffee id31514 View details | Mexico | Retail / E-commerce | — | — | |
|
mikelcoffee.com zoominfo.com/c/mikel-coffee/456172290 Mikel Coffee Company is a prominent Greek coffeehouse chain that began its journey in 2008 in the city of Larissa. It has rapidly expanded into a global brand, operating a network of over 410 coffee shops across 19 different countries. The company offers a comprehensive menu of premium coffee blends, beverages, snacks, and retail products, focusing on delivering a unique and welcoming coffee experience. |
||||||
| Ransomware | Mikel Coffee id31514 View details | Greece | Retail / E-commerce | — | — | |
|
mikelcoffee.com zoominfo.com/c/mikel-coffee/456172290 Mikel Coffee Company is a prominent Greek coffeehouse chain that began its journey in 2008 in the city of Larissa. It has rapidly expanded into a global brand, operating a network of over 410 coffee shops across 19 different countries. The company offers a comprehensive menu of premium coffee blends, beverages, snacks, and retail products, focusing on delivering a unique and welcoming coffee experience. |
||||||
| Ransomware | Hong Kong Baptist University id31515 View details | Hong Kong | Education | — | — | |
|
Hong Kong Baptist University, located in Hong Kong, is a public university that offers a range of academic programs. The university is part of the education sector in Hong Kong, providing various undergraduate and postgraduate degree programs. It was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | Hong Kong Baptist University id31515 View details | Hong Kong | Education | — | — | |
|
hkbu.edu.hk zoominfo.com/c/hong-kong-baptist-university/429650952 Hong Kong Baptist University (HKBU) is a leading public research university established in 1956 in Hong Kong. It is highly regarded for its academic excellence, particularly in liberal arts, business, communication, and traditional Chinese medicine. As one of the region's eight statutory publicly funded universities, it is dedicated to fostering global citizenship and innovative research. |
||||||
| Ransomware | Eva Care id31516 View details | United Kingdom | Healthcare / Pharma | — | — | |
|
Evacare.com operates in the healthcare and pharmaceutical sector, providing services in the United Kingdom. As a healthcare entity, evacare.com is likely involved in medical care and pharmaceutical services. Evacare.com was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | Eva Care id31516 View details | United Kingdom | Healthcare / Pharma | — | — | |
|
evacare.com rocketreach.co/eva-care-profile_b7a227f8c53b4785 Eva Care Group is a healthcare provider specializing in the post-acute care industry, headquartered in Los Angeles, California. With over 50 years of combined experience, the company operates and manages a network of nursing homes and rehabilitation facilities. They deliver comprehensive solutions encompassing clinical, financial, operational, and environmental management to ensure high-quality patient care. |
||||||
| Ransomware | Premier Pigs id31517 View details | United Kingdom | Agriculture / Food | — | — | |
|
Premierpigs.com operates in the agriculture and food sector in the United Kingdom, providing services related to pig farming. As a company in this sector, premierpigs.com is involved in activities such as pig breeding, farming, and possibly related food production. Premierpigs.com was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | Premier Pigs id31517 View details | United Kingdom | Agriculture / Food | — | — | |
|
premierpigs.com zoominfo.com/c/premier-pigs/458500816 Grupo Premier Pigs is a family-owned agricultural company based in Spain, founded in 1992 and specializing in the swine farming industry. Operating as a major pig farming integrator, the business manages its own breeding and fattening farms alongside a dedicated feed production mill. The organization is committed to sustainable livestock practices and comprehensive agricultural management, which also includes cereal farming. |
||||||
| Ransomware | Zion Contracting id31518 View details | United States | Construction / Real Estate | — | — | |
|
Zion Contracting is a construction and real estate company based in the United States, offering various services within the sector. The company operates within the construction and real estate industry, providing services to clients in the US. Zion Contracting was listed as a ransomware victim associated with thegentlemen. |
||||||
| Ransomware | Zion Contracting id31518 View details | United States | Construction / Real Estate | — | — | |
|
zioncontracting.com Zion Contracting LLC is a trusted general contractor based in New York, specializing in complex infrastructure and transportation projects. As a certified MBE, DBE, and SBE firm, they partner with government agencies to help fulfill minority and diversity contracting goals. Their main focus is delivering essential public works projects that strengthen communities across the state |
||||||
| Ransomware | Hartfiel Automation id31464 View details | Germany | Other | — | — | |
|
Hartfiel.com is a company based in Germany, operating in the Other sector. The company provides various offerings, although specific details about its services are not readily available. Hartfiel.com was listed as a ransomware victim associated with thegentlemen. |
||||||
| Ransomware | Hartfiel Automation id31464 View details | Germany | Other | — | — | |
|
hartfiel.com zoominfo.com/c/hartfiel-automation-inc/27608695 Hartfiel Automation is an industrial automation company providing comprehensive manufacturing solutions like pneumatics, robotics, motion control, and hydraulics. For over 60 years, they have been a specialized high-tech provider supporting the American manufacturing sector. Headquartered in Minnesota, the company employs hundreds of professionals dedicated to engineering and optimizing production processes |
||||||
| Ransomware | DHC id31435 View details | Japan | — | — | — | |
|
dhc.co.jp zoominfo.com/c/dhc-corp/372590440 DHC Corporation is a prominent Japanese brand renowned for its high-quality cosmetics, dietary supplements, and health foods. Originally founded as a translation company, it achieved global success by focusing on pure, natural ingredients—most notably its signature olive oil skincare. Today, DHC is trusted worldwide for combining rigorous scientific research with effective, affordable wellness products. |
||||||
| Ransomware | INKA Group GmbH Co id31436 View details | Germany | — | — | — | |
|
INKA Group GmbH & Co. KG is a German real estate holding company headquartered in Munich, registered in the Munich Commercial Register under HRA 99442. It specializes in leasing and renting own or leased land, buildings, and apartments, as well as managing commercial real estate on a fee or contract basis. The company operates as a closed investment and management vehicle with no public website or brand. It should not be confused with the Turkish İnka Group holding or other similarly named companies. |
||||||
| Ransomware | Vitex Pharmaceuticals id31437 View details | — | — | — | ||
|
vitexpharma.com zoominfo.com/c/vitex-pharmaceuticals-pty-ltd/90505264 Vitex Pharmaceuticals is a leading Australian contract manufacturer specializing in vitamins, minerals, and nutritional complementary medicines. Founded in 1989, this wholly Australian-owned company operates one of the country's largest and most state-of-the-art pharmaceutical manufacturing facilities. Recently, the company significantly expanded its capacity by opening a massive $250 million facility in Western Sydney to supply both domestic and global markets |
||||||
| Ransomware | Mdj Management id31438 View details | — | — | — | ||
|
appliedbizinvest.com zoominfo.com/c/mdj-management-llc/410565499 Applied Business Investments, Inc. (operating alongside MDJ Management LLC) is a private US-based management and finance consulting firm registered in Florida. Founded in the late 2000s, the company focuses on business investments, corporate management strategies, and financial advisory services. It operates as a boutique entity providing specialized support and investment structuring for various commercial projects |
||||||
| Ransomware | Hst id31439 View details | United States | — | — | — | |
|
hstechnology.com zoominfo.com/c/hst/352516154 digital platform for Healthcare Solutions Team (HST), a US-based healthcare cost-containment company now operating as Claritev. The company specializes in value-driven health plans, reference-based pricing solutions, and patient advocacy to reduce medical expenses. Through its HST Care Connect portal, it helps employers and individuals seamlessly find quality healthcare providers and optimize their medical benefits |
||||||
| Ransomware | Groupe BPCE id31440 View details | Viet Nam | — | — | ||
|
bpce-vietnam.com zoominfo.com/c/groupe-bpce/457963650 BPCE International (formerly Natixis), the Ho Chi Minh City branch of France’s second-largest banking group, Groupe BPCE. Operating in Vietnam since 1988, it is one of the country's longest-established foreign bank branches, holding a full banking license. The institution specializes in corporate and investment banking, offering specialized finance, trade solutions, and transaction processing to businesses across the region. |
||||||