Ransomware Group intelligence
Thegentlemen
ActiveTrack Thegentlemen with 1098 published victims and 2 known leak locations in a single intelligence view.
Overview
Thegentlemen is tracked by Breach House as a ransomware group with 1098 published victims.
United States is currently the most targeted country in this dataset.
2 known leak locations are currently associated with this group.
Leak Status Distribution
No leak-status data available yet.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (2)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 2 | Onion service | Down checked 22m ago | i2ohjeeqe37jre4f2u7pyq73cbm6lecumdxapkvrlryna6rc3it4zsid.onion |
| Leak location 1 | Onion service | Down checked 23m ago | tezwsse5czllksjb7cwp65rvnk4oobmzti2znn42i43bjdfd2prqqkad.onion |
Top Activity Sectors (20)
- IT 118
- Manufacturing / Engineering 104
- Communication / Marketing 88
- Healthcare / Pharma 68
- Retail / E-commerce 57
- Finance / Legal / Insurance 50
- Construction / Real Estate 48
- Services 44
- Transportation / Travel / Logistics 30
- Not identified 27
- Agriculture / Food 23
- Education 22
- Public Sector 20
- Energy 18
- NGOs / Associations 12
- Hospitality / Food & Beverage / Tourism 12
- Telecommunications 6
- Media / Entertainment 1
- Law Enforcement / Public Sector 1
- Research 1
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Thegentlemen, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: thegentlemen executes PowerShell scripts to run payload logic, disable defenses, and propagate across systems.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: thegentlemen modifies registry run keys and startup locations to maintain persistence after reboots.
What that means: Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: thegentlemen disables or modifies security tools such as EDR and AV processes to hinder incident response.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: thegentlemen deletes Volume Shadow Copies and backup artifacts via system commands to prevent recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1003.001 LSASS Memory Credential Access
What they do: thegentlemen accesses LSASS memory to steal credentials for lateral movement and privilege escalation.
What that means: Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS).
-
T1135 Network Share Discovery Discovery
What they do: thegentlemen uses network share discovery to locate victim file shares and map accessible storage paths for encryption.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: thegentlemen uses SMB/Windows Admin Shares for lateral movement between networked hosts in manufacturing and IT environments.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: thegentlemen encrypts victim files and data stores using ransomware payloads to maximize impact and extortion pressure.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: thegentlemen calls system recovery inhibitors to block restore processes and harden ransomware impact.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
-
T1491.001 Internal Defacement Impact
What they do: thegentlemen performs internal defacement by replacing victim files with ransom notes and altered content.
What that means: An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems.
Tools Observed (64)
▼Software Thegentlemen has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Credential theft
Defense evasion
Discovery
Discovery & enumeration
Exfiltration
LOLBAS (living-off-the-land binaries)
Networking & tunnelling
OffSec
Offensive security tooling
RMM Tools
Remote monitoring & management
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Ransom Notes (3)
▼The note this group leaves on a compromised machine. Click a filename to read it.
README-GENTLEMEN_3.txt
[snip] = YOUR ID Gentlemen, your network has been encrypted. 1. Any modification of encrypted files will make recovery impossible. 2. Only our unique decryption key and software can restore your files. Brute-force, RAM dumps, third-party recovery tools are useless. It’s a fundamental mathematical reality. Only we can decrypt your data. 3. Law enforcement, authorities, and “data recovery” companies will NOT help you. They will only waste your time, take your money, and block you from recovering your files — your business will be lost. 4. Any attempt to restore systems, or refusal to negotiate, may lead to irreversible wipe of all data and your network. 5. We have exfiltrated all your confidential and business data (including NAS, clouds, etc). If you do not contact us, it will be published on our leak site and distributed to major hack forums and social networks. In addition, it will be reported to the relevant data protection authorities and regulators. This may result in official investigations, significant fines, and reputational damage for your company. 6. We guarantee 100% file recovery to their original state, bit by bit. To demonstrate the quality of our work, you can provide three sample files, and we will restore them free of charge. TOX CONTACT - RECOVER YOUR FILES Contact us (add via TOX ID): 13343E50C1B3466F0EA35B5B3E55A044CB7132FD28A8665EFEA0E5848E276D548C21B79F15C2 Download Tox messenger: https://tox.chat/download.html Contact us (add via SimpleX): https://smp14.simplex.im/a#4mlOiePV8NBXOv2QrZ9CaPeRPm1mBUgxn4SdpFnm978 Download SimpleX https://simplex.chat/downloads/ СONTACT TO PREVENT DATA LEAK (7 DAYS BEFORE YOUR COMPANY DATA WILL BE PUBLISHED IN OUR BLOG, WITH 239 HOURS REVEAL TIMER) Check our blog: http://tezwsse5czllksjb7cwp65rvnk4oobmzti2znn42i43bjdfd2prqqkad.onion/ Download Tor browser: https://www.torproject.org/download/ Follow us on X: https://x.com/TheGentlemen26 Clearnet blog link: https://thegentlemen.cc/ Any other means of communication are fake and may be set up by third parties. Only use the methods listed in this note or on the specified website. After adding (us) in Tox or Session, please wait for your request to be processed and stay online. If you do not receive a reply within 36 hours, create another account and contact us again. In your first message in chat, immediately provide your ID from the note and the name of your organization. Assign one person as contact responsible for all negotiations. Do not create multiple chats. We have stolen more than 100 GB of your corporate information from your servers, including critically important data. Your company is facing a massive information security breach. A total data leak has occurred. This greatly increases the risk of colossal financial and reputational losses.
README-GENTLEMEN_2.txt
[snip] = YOUR ID Gentlemen, your network has been encrypted. 1. Any modification of encrypted files will make recovery impossible. 2. Only our unique decryption key and software can restore your files. Brute-force, RAM dumps, third-party recovery tools are useless. It’s a fundamental mathematical reality. Only we can decrypt your data. 3. Law enforcement, authorities, and “data recovery” companies will NOT help you. They will only waste your time, take your money, and block you from recovering your files — your business will be lost. 4. Any attempt to restore systems, or refusal to negotiate, may lead to irreversible wipe of all data and your network. 5. We have exfiltrated all your confidential and business data (including NAS, clouds, etc). If you do not contact us, it will be published on our leak site and distributed to major hack forums and social networks. In addition, it will be reported to the relevant data protection authorities and regulators. This may result in official investigations, significant fines, and reputational damage for your company. 6. We guarantee 100% file recovery to their original state, bit by bit. To demonstrate the quality of our work, you can provide three sample files, and we will restore them free of charge. TOX CONTACT - RECOVER YOUR FILES Contact us (add via TOX ID): 98C132E2B20B531BE6604397D97040C1E9EB42FCE12EDF119BCE8B4031CA5C70DAF5E65FA3C3 Download Tox messenger: https://tox.chat/download.html Contact us (add via Session ID): 05809b2da1d5b1a302f48b5767fd1843d54f3c516f9ab0eb26b544ffa73340292e Download Session https://getsession.org СONTACT TO PREVENT DATA LEAK (7 DAYS BEFORE YOUR COMPANY DATA WILL BE PUBLISHED IN OUR BLOG, WITH 239 HOURS REVEAL TIMER) Check our blog: http://tezwsse5czllksjb7cwp65rvnk4oobmzti2znn42i43bjdfd2prqqkad.onion/ Download Tor browser: https://www.torproject.org/download/ Follow us on X: https://x.com/ Any other means of communication are fake and may be set up by third parties. Only use the methods listed in this note or on the specified website. After adding (us) in Tox or Session, please wait for your request to be processed and stay online. If you do not receive a reply within 36 hours, create another account and contact us again. In your first message in chat, immediately provide your ID from the note and the name of your organization. Assign one person as contact responsible for all negotiations. Do not create multiple chats.
README-GENTLEMEN.txt
[snip] = YOUR ID Gentlemen, your network is under our full control. All your files are now encrypted and inaccessible. 1. Any modification of encrypted files will make recovery impossible. 2. Only our unique decryption key and software can restore your files. Brute-force, RAM dumps, third-party recovery tools are useless. It’s a fundamental mathematical reality. Only we can decrypt your data. 3. Law enforcement, authorities, and “data recovery” companies will NOT help you. They will only waste your time, take your money, and block you from recovering your files — your business will be lost. 4. Any attempt to restore systems, or refusal to negotiate, may lead to irreversible wipe of all data and your network. 5. We have exfiltrated all your confidential and business data (including NAS, clouds, etc). If you do not contact us, it will be published on our leak site and distributed to major hack forums and social networks. TOX CONTACT - RECOVER YOUR FILES Contact us (add via TOX ID): F8E24C7F5B12CD69C44C73F438F65E9BF560ADF35EBBDF92CF9A9B84079F8F04060FF98D098E Download Tox messenger: https://tox.chat/download.html COOPERATE TO PREVENT DATA LEAK (239 HOURS LEFT) Check our blog: http://tezwsse5czllksjb7cwp65rvnk4oobmzti2znn42i43bjdfd2prqqkad.onion/ Download Tor browser: https://www.torproject.org/download/ Any other means of communication are fake and may be set up by third parties. Only use the methods listed in this note or on the specified website.
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (1098)
Search, filter and paginate the victim timeline for Thegentlemen. Showing 301–400 of 1098.
| Type | Target | Discovered | Country | Business Category | Intel Link | Leak status |
|---|---|---|---|---|---|---|
| Ransomware | Kontact Consortium India Pvt id31036 View details | India | IT | — | — | |
|
kontact.in is an Indian IT company, operating in the information technology sector. The company is based in India and provides various IT services. kontact.in was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | Kontact Consortium India Pvt id31036 View details | India | IT | — | — | |
|
kontact.in zoominfo.com/c/kontact-consortium-india-pvt-ltd/437934184 Kontact is an Indian engineering company with over 50 years of experience, specializing in electrical and mechanical solutions for the railway, infrastructure, and industrial sectors. They provide end-to-end services, including railway rolling stock supplies, LV/MV power distribution panels, and electrical contracting, backed by a 40,000+ sq. ft. manufacturing facility. The company is recognized for its reliability and quality, holding key international certifications such as ISO 9001, IRIS, and EN 15085-2 |
||||||
| Ransomware | Upanal CNC Solutions id31037 View details | Peru | Manufacturing / Engineering | — | — | |
|
Upanalcnc.com is a company based in Peru, operating in the manufacturing and engineering sector. The company likely provides services and products related to computer numerical control, given its name. Upanalcnc.com was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | Upanal CNC Solutions id31037 View details | Peru | Manufacturing / Engineering | — | — | |
|
upanalcnc.com zoominfo.com/c/upanal-cnc-solutions/370526030 Upanal CNC Solutions is an Indian company specializing in advanced metal cutting and metal forming technologies, particularly CNC machinery. Beyond supplying equipment, they provide comprehensive services including machine modernization, 24/7 technical support, and structured training programs for operators and engineers. Headquartered in Bangalore with a technical center in Chennai and an international office in Bahrain, the company serves a trusted network of over 500 clients across various manufacturing industries |
||||||
| Ransomware | Indus Protech Solutions id31038 View details | India | Manufacturing / Engineering | — | — | |
|
Indusprotech.com is a company based in India, operating in the manufacturing and engineering sector. The company likely provides various services and products related to its sector. Indusprotech.com was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | Indus Protech Solutions id31038 View details | India | Manufacturing / Engineering | — | — | |
|
indusprotech.com zoominfo.com/c/indus-protech-solutions-ltd/1323287130 Indus Protech Solutions is a Chennai-based company specializing in comprehensive bulk MRO (Maintenance, Repair, and Operations) and supply chain services for global trade. Acting as a one-stop sourcing partner, they provide access to over 1.5 million products across 50+ categories, serving diverse sectors like defense, energy, agriculture, and pharmaceuticals. The company connects businesses with global manufacturers, ensuring assured quality, competitive pricing, and streamlined procurement for Fortune 500 companies and large corporate networks |
||||||
| Ransomware | Angel Hotel id31039 View details | United Kingdom | Other | — | — | |
|
Angelpershore.co.uk is a UK-based entity operating in the other sector. The entity is located in Great Britain and provides various offerings. Angelpershore.co.uk was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | Angel Hotel id31039 View details | United Kingdom | Other | — | — | |
|
angelpershore.co.uk zoominfo.com/c/angel-hotel/1153643926 The Angel, Pershore is a historic Tudor-origin hotel and restaurant located in the heart of the market town of Pershore, Worcestershire, near the River Avon. It serves as a premier venue offering farm-to-table dining with locally sourced produce, comfortable accommodation, and a charming atmosphere. Beyond hospitality, the establishment is a vibrant community hub, regularly hosting live music, festivals, and popular annual events like Bonfire Night fireworks. |
||||||
| Ransomware | The Garfield County Sheriff Office id31040 View details | United States | Law Enforcement / Public Sector | — | — | |
|
Garcosheriff.com is a website associated with a law enforcement agency in the United States, providing information and services to the public sector. As a public sector entity, it plays a crucial role in maintaining law and order in its jurisdiction. Garcosheriff.com was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | The Garfield County Sheriff Office id31040 View details | United States | Law Enforcement / Public Sector | — | — | |
|
garcosheriff.com The Garfield County Sheriff's Office is the primary law enforcement agency serving Garfield County, Colorado. Its mission is to deliver exceptional service and problem-solving solutions to the community through professional, ethical, and compassionate conduct. The office provides comprehensive public safety services, including patrol, detentions, criminal investigations, and community outreach programs like "Shop with a Cop" and emergency mass notifications |
||||||
| Ransomware | Buck Knives id31019 View details | United States | Manufacturing / Engineering | — | — | |
|
Buckknives.com is a US-based company operating in the manufacturing and engineering sector, producing high-quality knives and outdoor gear. The company is known for its durable and reliable products, catering to various markets, including outdoor enthusiasts and professionals. Buckknives.com was listed as a ransomware victim associated with thegentlemen. |
||||||
| Ransomware | Buck Knives id31019 View details | United States | Manufacturing / Engineering | — | — | |
|
buckknives.com zoominfo.com/c/buck-knives-inc/16223110 Buck Knives is a historic American knife manufacturer founded in 1947 by Hoyt Buck, originating from a family blacksmith business dedicated to superior steel tempering. The brand revolutionized the knife industry in 1964 with the introduction of the iconic Model 110 Folding Hunter. Now headquartered in Post Falls, Idaho, this four-generation family company is renowned for its rugged durability, traditional American craftsmanship, and a lifetime "Forever Warranty" |
||||||
| Ransomware | Advanced Marketing id30859 View details | Mexico | Communication / Marketing | — | — | |
|
Advmkt.com.mx is a marketing company based in Mexico, operating in the communication and marketing sector. The company likely provides various marketing services to its clients. Advmkt.com.mx was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | Advanced Marketing id30859 View details | Mexico | Communication / Marketing | — | — | |
|
advmkt.com.mx zoominfo.com/c/advanced-marketing/546978407 Advanced Marketing is one of Mexico's largest book distribution and publishing companies, founded in 1994. It partners with around 70 national and international publishing houses to supply major retail chains like Gandhi and Porrúa. Additionally, it operates "AMS Libros," an online store selling a wide variety of children's, art, culture, and health books. |
||||||
| Ransomware | European Design id30780 View details | Canada | Retail / E-commerce | — | — | |
|
European Design is a Canadian company operating in the retail and e-commerce sector. The company is based in Canada and offers various products and services to its customers. European Design was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | European Design id30780 View details | Canada | Retail / E-commerce | — | — | |
|
***.ca zoominfo.com/c/european-design/365524802 European Design Jewellery Ltd is a Toronto-based wholesale supplier serving jewellers and manufacturers across Canada. They specialize in providing a wide range of genuine and synthetic gemstones, jewellery findings, diamonds, and finished pieces. Additionally, the company supplies professional jewellery-making equipment and tools, acting as an exclusive Canadian distributor for several industry brands |
||||||
| Ransomware | MK Jewelry id30781 View details | North Macedonia | Retail / E-commerce | — | — | |
|
mkjewel.com is an e-commerce platform operating in the retail sector, based in the country of MK, offering various products to its customers. As an online retailer, mkjewel.com provides a range of services to facilitate transactions and engage with its customer base. mkjewel.com was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | MK Jewelry id30781 View details | North Macedonia | Retail / E-commerce | — | — | |
|
***.com zoominfo.com/c/mk-jewelry-inc/346982894 MK Jewelry, Inc. is a fine jewelry manufacturing and distribution company based in Midtown Manhattan, established in 1986. They specialize in producing and supplying a wide range of jewelry, including bridal and bridge collections. The company serves both independent and major retailers across the US, Canada, and the Caribbean. As a premier industry supplier, they offer extensive private label and branded diamond jewelry lines |
||||||
| Ransomware | GUERREIROS seguros id30782 View details | Portugal | Retail / E-commerce | — | — | |
|
Guerreiros.pt operates in the retail and e-commerce sector in Portugal, offering various products and services to its customers. As an e-commerce company, it provides online shopping experiences. Guerreiros.pt was listed as a ransomware victim associated with thegentlemen. |
||||||
| Ransomware | GUERREIROS seguros id30782 View details | Portugal | Retail / E-commerce | — | — | |
|
***.pt zoominfo.com/c/guerreiros-seguros/483718773 GUERREIROS Seguros is a professional insurance mediation company based in Faro, Portugal, operating since 1990 and officially licensed as a mediator since 1994. They specialize in a wide range of insurance solutions, including auto, health, and life insurance. With over 30 years of experience, the company focuses on helping clients manage their policies, secure competitive rates, and ensure transparent, up-to-date coverage tailored to their specific needs |
||||||
| Ransomware | Tikona Infinet id30783 View details | India | Telecommunications | — | — | |
|
Tikona.in is a telecommunications company based in India, offering various services to its customers. The company operates in the telecommunications sector, providing essential services to individuals and businesses across the country. Tikona.in was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | Tikona Infinet id30783 View details | India | Telecommunications | — | — | |
|
***.in rocketreach.co/tikona-profile_b5c0d28cf42e0851 Tikona Infinet Private Limited is a prominent Indian telecommunications company based in Mumbai, established in 2008. They specialize in providing high-performance wireless broadband connectivity and advanced cloud solutions. The company serves a diverse client base, including residential homes, small businesses, and large enterprises across India, with a focus on delivering reliable next-generation internet service |
||||||
| Ransomware | TC Printing id30784 View details | Australia | Manufacturing / Engineering | — | — | |
|
tcprinting.com.au is an Australian company operating in the manufacturing and engineering sector. The company is based in Australia and provides various services related to printing. tcprinting.com.au was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | TC Printing id30784 View details | Australia | Manufacturing / Engineering | — | — | |
|
***.com.au zoominfo.com/c/tc-printing/369208765 TC Printing Australia Pty Ltd is a commercial printing and communications company based in Scoresby, Victoria, Melbourne. Established in the mid-1980s, it specializes in a comprehensive range of printing services, including offset, digital, and point-of-sale materials. The company serves diverse clients across the advertising and marketing industries, providing end-to-end solutions from graphic design to large-scale event printing |
||||||
| Ransomware | Oldelval Oleoductos del Valle id30785 View details | Argentina | Energy | — | — | |
|
Oldelval.com is an Argentine company operating in the energy sector, providing various services to the industry. The company's offerings likely include energy-related solutions, given its sector classification. Oldelval.com was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | Oldelval Oleoductos del Valle id30785 View details | Argentina | Energy | — | — | |
|
***.com zoominfo.com/c/oleoductos-del-valle-sa/456337922 Oldelval (Oleoductos del Valle S.A.) is a leading Argentine midstream energy company specializing in the transportation of liquid hydrocarbons. Based in Cipolletti, Río Negro, it transports over 50% of the oil produced in Argentina and approximately 80% of the oil from the Neuquén Basin. With over 60 years of history, the company focuses on sustainable operations, safety, and infrastructure maintenance, having recently extended its national concession until 2037. |
||||||
| Ransomware | Decoupe Laser Services id30786 View details | France | Manufacturing / Engineering | — | — | |
|
Dls-laser.com is a company based in France, operating in the manufacturing and engineering sector. The company likely provides laser-related products or services, given its name. Dls-laser.com was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | Decoupe Laser Services id30786 View details | France | Manufacturing / Engineering | — | — | |
|
***.com DLS (Découpe Laser Services) is a French laser cutting specialist based in La Ravoire, specializing in precision laser cutting of steel, stainless steel, and aluminum. The company offers comprehensive metal finishing services including deburring, bending, surface treatment, tapping, and milling. With large-format cutting capabilities (6000mm x 2000mm) and over 200 tons of material stock, DLS handles everything from prototypes to very large industrial production runs. They pride themselves on reactivity and flexibility, providing quotes within 24 hours. |
||||||
| Ransomware | Thialf id30787 View details | Netherlands | Construction / Real Estate | — | — | |
|
Thialf.nl is a company based in the Netherlands, operating in the construction and real estate sector. The company likely provides various services related to construction and real estate development in the region. Thialf.nl was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | Thialf id30787 View details | Netherlands | Construction / Real Estate | — | — | |
|
***.nl zoominfo.com/c/thialf/430686423 Thialf is a world-renowned ice arena located in Heerenveen, Netherlands, often referred to as the "Cathedral of Speed Skating." It serves as the home base for the Dutch national speed skating team and hosts a wide range of ice sports, including long track and short track speed skating, figure skating, and ice hockey. Recently, it was officially confirmed as the long-track speed skating venue for the 2030 Winter Olympics. The facility is celebrated for its modern, sustainable design and its role as a major hub for both elite professional competitions and public recreational skating. |
||||||
| Ransomware | Title Resources id30788 View details | Australia | Finance / Legal / Insurance | — | — | |
|
titleresourcesnt.com operates within the finance, legal, and insurance sector in Australia, providing various services to clients. As a finance sector entity, titleresourcesnt.com handles sensitive client information. titleresourcesnt.com was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | Title Resources id30788 View details | Australia | Finance / Legal / Insurance | — | — | |
|
***.com zoominfo.com/c/title-resources-llc/1137777688 Title Resources is a locally owned title company based in Denton, Texas, founded in 1989. They specialize in real estate transactions, comprehensive title searches, and title insurance across North Texas, including Denton, Dallas, and Collin counties. Their team of fully trained professional title officers thoroughly examines each property to identify and resolve any title issues, ensuring secure and smooth real estate closings |
||||||
| Ransomware | Clarke Radiology id30789 View details | Australia | Healthcare / Pharma | — | — | |
|
Clarkeradiology.com is a healthcare service provider based in Australia, offering medical imaging and radiology services. The company operates in the healthcare sector, providing essential medical services to patients. Clarkeradiology.com was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | Clarke Radiology id30789 View details | Australia | Healthcare / Pharma | — | — | |
|
***.com zoominfo.com/c/clarke-medical-imaging-center/370367094 Clarke Radiology (Clarke Medical Imaging Center) is a well-established medical imaging facility based in Montreal, Quebec, with over 40 years of experience. They provide a comprehensive range of diagnostic imaging services, including X-rays, MRI, ultrasound, mammography, bone density scans, and cortisone injections. The center is recognized for its top-of-the-line technology, rapid reporting (within 4 hours), and strong commitment to patient safety and accredited care standards |
||||||
| Ransomware | SICSOE id30790 View details | France | IT | — | — | |
|
Sicsoe.fr is an IT company based in France, providing various services to its clients. The company operates in the IT sector, offering solutions to businesses in France. Sicsoe.fr was listed as a ransomware victim associated with thegentlemen. |
||||||
| Ransomware | SICSOE id30790 View details | France | IT | — | — | |
|
***.fr zoominfo.com/c/sicsoe/359018881 SICSOE (Solution Vin Logistique) is a French wine logistics company based near Bordeaux, established in 1985. They provide comprehensive, customized logistics services for the wine industry, including winery operations, bottling, storage, and shipping. The company is recognized for its advanced technology ensuring full product traceability and its strong commitment to environmental and quality standards, including ISO 14001 certification |
||||||
| Ransomware | Gloria Maris Groupe id30791 View details | France | Other | — | — | |
|
Gloriamaris.com is a French entity operating in the other sector, providing various offerings. The company is based in France and caters to a specific audience. Gloriamaris.com was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | Gloria Maris Groupe id30791 View details | France | Other | — | — | |
|
***.com zoominfo.com/c/gloria-maris-groupe/552388964 Gloria Maris is a premium aquaculture company based in France and Sardinia, specializing in the sustainable farming of high-quality fish. With facilities in Corsica, Côte d'Opale, Gravelines, and Sardinia, the company focuses on traceability, environmental respect, and controlled growth in natural marine ecosystems. They produce around 3,800 tons of responsibly farmed fish and 35 million fry annually, exporting their products to over 25 countries worldwide |
||||||
| Ransomware | Compagnie des Caoutchoucs du Pakidie id30792 View details | Other | — | — | ||
|
Pakidie.com is an entity operating in the other sector. The specifics of its location and offerings are not well-documented. Pakidie.com was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | Compagnie des Caoutchoucs du Pakidie id30792 View details | Other | — | — | ||
|
***.com Compagnie des Caoutchoucs du Pakidié (CCP) is a pioneering Ivorian company established in 1960, specializing in the farming, production, and processing of natural rubber. Based in Abidjan, Côte d'Ivoire, it holds the historical distinction of being the country's first entirely private rubber enterprise and currently ranks as the second-largest national producer. The company is committed to sustainable practices, exporting its high-quality rubber to major international clients while prioritizing environmental and social responsibility. |
||||||
| Ransomware | Compagnie des Caoutchoucs du Pakidie id30792 View details | Côte d'Ivoire | Other | — | — | |
|
***.com Compagnie des Caoutchoucs du Pakidié (CCP) is a pioneering Ivorian company established in 1960, specializing in the farming, production, and processing of natural rubber. Based in Abidjan, Côte d'Ivoire, it holds the historical distinction of being the country's first entirely private rubber enterprise and currently ranks as the second-largest national producer. The company is committed to sustainable practices, exporting its high-quality rubber to major international clients while prioritizing environmental and social responsibility. |
||||||
| Ransomware | HBS Group id30793 View details | Australia | Construction / Real Estate | — | — | |
|
Hbsgroup.com.au is an Australian company operating in the construction and real estate sector, providing various services. The company is based in Australia and offers services related to construction and real estate. Hbsgroup.com.au was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | HBS Group id30793 View details | Australia | Construction / Real Estate | — | — | |
|
***.com.au zoominfo.com/c/hbs-group-pty-ltd/356757625 HBS Group is a privately owned Australian company specializing in heritage restoration, conservation, and remedial construction projects. Based in Alphington, Victoria, they have over 15 years of experience delivering complex construction and stonemasonry solutions nationwide. The company is recognized as an industry leader in preserving historical buildings and executing high-quality restoration work across major Australian cities |
||||||
| Ransomware | Agapit id30794 View details | Poland | IT | — | — | |
|
Agapit.pl is an IT company based in Poland, providing various IT services. The company operates in the IT sector, offering its services to clients in Poland. Agapit.pl was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | Agapit id30794 View details | Poland | IT | — | — | |
|
***.pl zoominfo.com/c/agapit-sp-z-oo-spk/372573662 Agapit is one of the largest suppliers of professional cleaning technology and equipment in Poland, with over 26 years of experience. The company provides comprehensive solutions, including industrial cleaning machines, robotic scrubbers, high-pressure washers, and specialized cleaning chemicals. They operate their own nationwide distribution, rental, and service network, with key locations in cities like Olsztyn, Wroclaw, and Gdynia |
||||||
| Ransomware | Raben Group id30795 View details | Poland | Transportation / Travel / Logistics | — | — | |
|
Raben Group is a European logistics and transportation company based in Poland, offering a range of services including freight forwarding, warehousing, and supply chain management. The company operates in various sectors, providing tailored solutions to its customers. Raben Group was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | Raben Group id30795 View details | Poland | Transportation / Travel / Logistics | — | — | |
|
***.com zoominfo.com/c/raben-group/350966506 Raben Group is a leading European logistics provider with Dutch roots, founded in 1931 and currently headquartered in Poznań, Poland. The company offers comprehensive transport and warehousing solutions, including road transport, contract logistics, and supply chain management across 17 European countries. With over 90 years of experience and a workforce of approximately 12,200 employees, Raben Group is recognized as a market leader focused on sustainable and efficient logistics operations |
||||||
| Ransomware | Henry Frerk Sons id30796 View details | United States | Manufacturing / Engineering | — | — | |
|
Hfsmaterials.com operates in the manufacturing and engineering sector, providing services and products in the United States. As a company in this sector, it likely offers a range of materials and solutions for various industrial applications. Hfsmaterials.com was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | Henry Frerk Sons id30796 View details | United States | Manufacturing / Engineering | — | — | |
|
***.com zoominfo.com/c/henry-frerk-sons-inc/44255454 Henry Frerk Sons (HFS Materials) is a premier masonry and plaster restoration supplier based in the Chicago region, with over 140 years of history. They specialize in custom matching and blending of historic mortars, concrete, and stone patching materials, alongside offering on-site volumetric ready-mix concrete services. The company provides a comprehensive range of building materials, including natural hydraulic lime, specialized cleaners, sealers, and preblended mortars for both historic preservation and new construction projects |
||||||
| Ransomware | SMRTR id30797 View details | United States | IT | — | — | |
|
Smrtrsolutions.com operates in the IT sector in the United States, providing various technology solutions. As an IT company, smrtrsolutions.com likely offers services such as software development, consulting, and support. Smrtrsolutions.com was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | SMRTR id30797 View details | United States | IT | — | — | |
|
***.com rocketreach.co/s4i-systems-profile_b5c16403f42e08fa SMRTR is a document and workflow automation company with over 20 years of experience, specializing in ERP-driven industries such as manufacturing, food & beverage, and distribution. They provide cloud-based solutions for document management, accounts payable automation, and supplier regulatory compliance. Operating as a remote-first, environmentally conscious organization, SMRTR focuses on seamless integration with existing financial and operational systems to improve efficiency and reduce manual tasks. |
||||||
| Ransomware | DayNDay id30798 View details | India | Retail / E-commerce | — | — | |
|
Daynday.co.in is an e-commerce company based in India, operating in the retail sector. The company offers various products and services to its customers. Daynday.co.in was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | DayNDay id30798 View details | India | Retail / E-commerce | — | — | |
|
***.co.in zoominfo.com/c/daynday/459254692 Day 'N' Day Services Private Limited is a leading integrated facility management company based in Chennai, India, established in 1987. They provide comprehensive facility management and business support services, including logistics, warehouse management, and maintenance solutions. With operations spanning across multiple locations in India and a large workforce, the company serves diverse sectors such as banking, insurance, and corporate enterprises |
||||||
| Ransomware | Affinity Designs id30799 View details | United States | Construction / Real Estate | — | — | |
|
Affinity Designs LLC is a company operating in the construction and real estate sector in the United States. The company likely provides design services to clients in the construction and real estate industries. Affinity Designs LLC was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | Affinity Designs id30799 View details | United States | Construction / Real Estate | — | — | |
|
***.com zoominfo.com/c/affinity-designs/374939106 Affinity Designs LLC is a fine jewelry wholesaler and manufacturer based in New York, specializing in the design, production, and marketing of elegant gemstone jewelry collections. The company offers a wide range of high-quality pieces crafted in 925 Sterling Silver and 10K, 14K, or 18K gold. Led by CEO Meir Sanandaji, who brings over 40 years of industry experience, the business caters to retailers seeking premium, trend-forward jewelry lines |
||||||
| Ransomware | Lenrose id30800 View details | Singapore | Other | — | — | |
|
Lenrose.com is a Singapore-based entity operating in the other sector. The company is based in Singapore and provides various offerings. Lenrose.com was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | Lenrose id30800 View details | Singapore | Other | — | — | |
|
***.com zoominfo.com/c/lenrose-pty-ltd/551499069 Lenrose & Ace David Jewellery is a premier jewellery manufacturing and casting company based in Melbourne, Australia. They specialize in precious metal casting (gold, platinum, silver, and bronze), CAD services, and the production of hand-made chain products. As a full-service, multi-faceted manufacturing facility, they utilize cutting-edge technology to bring custom jewellery designs to life for their clients |
||||||
| Ransomware | Lenrose id30800 View details | Australia | Other | — | — | |
|
***.com zoominfo.com/c/lenrose-pty-ltd/551499069 Lenrose & Ace David Jewellery is a premier jewellery manufacturing and casting company based in Melbourne, Australia. They specialize in precious metal casting (gold, platinum, silver, and bronze), CAD services, and the production of hand-made chain products. As a full-service, multi-faceted manufacturing facility, they utilize cutting-edge technology to bring custom jewellery designs to life for their clients |
||||||
| Ransomware | Velum id30801 View details | IT | — | — | ||
|
Velum.biz operates in the IT sector, providing various services. The company's specific offerings and location are not publicly disclosed. Velum.biz was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | Velum id30801 View details | IT | — | — | ||
|
***.biz zoominfo.com/c/velum-inc/372599932 We are making some files publicly available. We have hundreds of gigabytes of your files, including database projects, client contracts, personal data, and documents. If you do not want to face the consequences of a data breach, please contact us; otherwise, everything will be published. VELUM is a French manufacturer of professional lighting solutions based in Bischoffsheim, Alsace, operating since 1975. The company specializes in designing, developing, and manufacturing custom LED lighting fixtures for both indoor and outdoor environments. As a family-owned business, VELUM provides comprehensive support, including lighting studies, technical advice, and tailored solutions for professionals across various sectors |
||||||
| Ransomware | Ceska filharmonie id30802 View details | Czechia | Services | — | — | |
|
Ceskafilharmonie.cz is a Czech-based entity operating in the services sector, likely providing various offerings to its clients. The services sector encompasses a broad range of industries, including financial, professional, and personal services. Ceskafilharmonie.cz was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | Ceska filharmonie id30802 View details | Czechia | Services | — | — | |
|
***.cz zoominfo.com/c/esk-filharmonie/1100523885 The Czech Philharmonic (Česká filharmonie) is one of the world's most renowned symphony orchestras, based in Prague, Czech Republic. It gave its first independent concert on January 4, 1896, under the baton of Antonín Dvořák, and has been resident at the historic Rudolfinum concert hall for over a century. The orchestra is globally celebrated for its authentic and masterful interpretations of Czech composers such as Dvořák, Smetana, and Janáček. Currently, the ensemble is led by Chief Conductor and Music Director Semyon Bychkov, continuing its legacy of artistic excellence and international touring. |
||||||
| Ransomware | Herbahaz id30803 View details | Hungary | Agriculture / Food | — | — | |
|
Herbahaz.hu is a Hungarian entity operating in the agriculture and food sector. The company is based in Hungary and likely provides products or services related to this industry. Herbahaz.hu was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | Herbahaz id30803 View details | Hungary | Agriculture / Food | — | — | |
|
***.hu zoominfo.com/c/bennovum-kft/535573660 Herbaház is a Hungarian health and wellness specialty retail chain operating multiple stores nationwide alongside an online shop. The company specializes in dietary supplements, medicinal herbs, vitamins, and a wide range of organic, vegan, and "free-from" health foods. Their mission is to promote conscious, healthy living by providing a comprehensive, one-stop destination for natural health products and wellness solutions. |
||||||
| Ransomware | vpcgroup.com customfoam.com id30804 View details | United States | Manufacturing / Engineering | — | — | |
|
Customfoam.com is a US-based company operating in the manufacturing and engineering sector, providing custom foam solutions. The company's offerings cater to various industries, leveraging its expertise in foam technology. Customfoam.com was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | vpcgroup.com customfoam.com id30804 View details | United States | Manufacturing / Engineering | — | — | |
|
***.com vpcgroup.com zoominfo.com/c/custom-foam-systems-ltd/31526090 Custom Foam Systems (CFS) is a leading Canadian manufacturer of fabricated and molded custom polyurethane foam components, founded in 1973 and based in Kitchener, Ontario. The company specializes in serving the automotive, healthcare, and furniture industries across North America with over 45 years of manufacturing excellence. CFS operates under ISO 9001:2015 and FDA standards, utilizing advanced product development processes and lean manufacturing systems to deliver exceptional quality and on-time performance. As a family-owned business, they have built a strong reputation for innovation, reliability, and their commitment that "every component matters." |
||||||
| Ransomware | Optiforms id30805 View details | United States | IT | — | — | |
|
Optiforms.com is an IT company based in the United States, providing various services within the IT sector. As an IT company, optiforms.com likely offers solutions and support to its clients. Optiforms.com was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | Optiforms id30805 View details | United States | IT | — | — | |
|
***.com zoominfo.com/c/optiforms-inc/67340558 Optiforms, Inc. is a precision manufacturing company based in Temecula, California, specializing in electroforming, CNC machining, and enhanced surface finishes. Founded in 1984, the company produces custom metal components and high-performance optical coatings for demanding applications. They primarily serve the aerospace, defense, medical, semiconductor, and specialty lighting sectors with advanced, vertically integrated manufacturing solutions. |
||||||
| Ransomware | MatTek id30806 View details | United States | IT | — | — | |
|
Mattek.com is an IT company based in the United States, providing various IT services. The company operates in the IT sector, offering services to clients in the US. Mattek.com was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | MatTek id30806 View details | United States | IT | — | — | |
|
***.com zoominfo.com/c/mattek-corp/109184324 MatTek Corporation is a pioneering biotechnology company founded in 1985 and headquartered in Ashland, Massachusetts, specializing in the development of innovative in vitro 3D reconstructed human tissue models. They produce advanced microtissues and cell culture products that are widely used by researchers to accelerate drug development, conduct toxicity testing, and replace traditional animal testing. Originally an independent leader in tissue engineering, the company was recently acquired by the global life science supplier Sartorius and now operates as a key part of their advanced biological models portfolio |
||||||
| Ransomware | Conecsus id30807 View details | United States | IT | — | — | |
|
ConecSus LLC is an IT company based in the United States, providing various IT services. The company operates within the IT sector, offering solutions to its clients. ConecSus LLC was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | Conecsus id30807 View details | United States | IT | — | — | |
|
***.com zoominfo.com/c/conecsus-llc/358895914 Conecsus LLC is a global "green" metals recycler and refiner founded in 1980 and headquartered in Terrell, Texas. The company specializes in processing complex industrial residues and electronic wastes, particularly those containing tin, lead, silver, gold, and copper, such as SMT solder and solder paste wastes. Recognized as the largest secondary tin-lead recycler in the Western Hemisphere, Conecsus converts these materials into reusable metal products using state-of-the-art technology. |
||||||
| Ransomware | Wunschkind Klinik Dr Brunbauer id30808 View details | Austria | Healthcare / Pharma | — | — | |
|
Wunschkind.at is an Austrian entity operating in the healthcare and medicine sector, providing services in Austria. The company's offerings are focused on healthcare. Wunschkind.at was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | Wunschkind Klinik Dr Brunbauer id30808 View details | Austria | Healthcare / Pharma | — | — | |
|
***.at zoominfo.com/c/wunschkind-klinik-dr-brunbauer/1320140781 We have hundreds of gigabytes of your files, including database projects, client contracts, personal data and documents, medical data, medical histories, treatment records, medical reports, and more—all of which constitute critically important information. If you do not want to face the consequences of a data breach, please contact us; otherwise, everything will be published. fertility clinic in Vienna, Austria, led by Dr. Brunbauer. Located in the city center, the clinic specializes in fertility treatments including IVF, insemination, diagnostics, hormone therapy, egg donation, and cryopreservation. It is a recognized partner clinic of Austria's IVF-Fonds program. |
||||||
| Ransomware | Sirl id30764 View details | Portugal | IT | — | — | |
|
sirl.pt is a Portuguese IT company providing various services. Located in Portugal, the company operates within the IT sector, offering a range of solutions. sirl.pt was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | Sirl id30764 View details | Portugal | IT | — | — | |
|
***.pt zoominfo.com/c/sirl/372746430 Portuguese manufacturing company founded in 1988 and headquartered in Penela, Coimbra. It specializes in producing and selling machinery and tools for the civil construction industry.Their flagship products are concrete mixers, complemented by various other construction equipment and welding tools. The company employs 51–200 people and is a recognized supplier in the European construction machinery sector |
||||||
| Ransomware | Disney Family id30765 View details | United States | Finance / Legal / Insurance | — | — | |
|
Shamrock.com operates in the finance, legal, and insurance sector in the United States, providing various services to its clients. As a financial services provider, shamrock.com likely handles sensitive client information. Shamrock.com was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | Disney Family id30765 View details | United States | Finance / Legal / Insurance | — | — | |
|
This critical data breach involves Disney Family / Shamrock Holdings, the private investment firm and family office established by Roy E. Disney to manage the wealth of the Disney family branch, rather than the public Walt Disney Company. The compromised dataset, totaling over 800 GB and spanning from the 1980s to June 2026, exposes highly sensitive information across 14 critical categories, including family trusts, tax administration, and private equity fund management. Key victims include prominent figures such as Abigail Disney, Roy P. Disney, and Stanley Gold, whose personal financial records, passports, and KYC documents were leaked alongside detailed trust instruments for the "Disney Grandchildren Trusts." The breach reveals active operational data, including recent payroll records, bank reconciliations with CNB, and subscription agreements for funds like the Shamrock Israel Growth Fund. With unencrypted databases, embedded ERP credentials etc.. |
||||||
| Ransomware | Ecopetrol id30672 View details | Colombia | Energy | — | — | |
|
Ecopetrol is the largest company in Colombia and a main player in the country's energy sector, primarily involved in the exploration, production, and refining of petroleum products. As a major energy company, Ecopetrol provides a range of services and offerings related to the energy industry. Ecopetrol was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | Ecopetrol id30672 View details | Colombia | Energy | — | — | |
|
$33.1 Billion. www.***.com.co ECOPETROL copetrol SA is a company organized as a public limited company, of national order, linked to the Ministry of Mines and Energy. It has operations located in the center, south, east and north of Colombia, as well as abroad. It has two refineries in Barrancabermeja and Cartagena. Through its subsidiary Cenit, specialized in hydrocarbon transportation and logistics, it owns three ports for the export and import of fuels and crude oil in Coveñas (Sucre) and Cartagena (Bolvar) with access to the Atlantic, and Tumaco (Nariño) on the Pacific. Cenit also owns most of the country's oil and multi-purpose pipelines that connect production systems with large consumption centers and maritime terminals. Ecopetrol also has a stake in the biofuels business and is present in Brazil, Mexico and the United States (Gulf of Mexico and Permian Texas). 1TB+ Stock Symbol = ECOPETROL |
||||||
| Ransomware | Military Sealift Command id30646 View details | United States | Transportation / Travel / Logistics | — | — | |
|
Sealiftcommand.com is a US-based company operating in the transportation and logistics sector, providing services to support the movement of goods and supplies. The company's offerings cater to the needs of various industries, including travel and logistics. Sealiftcommand.com was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | Military Sealift Command id30646 View details | United States | Transportation / Travel / Logistics | — | — | |
|
***.com zoominfo.com/c/military-sealift-command/149045906 We attempted to contact the managers regarding the leaked documents (ITAR documentation, personal data, cargo manifests—including ESSM shipments—vessel blueprints, and both disclosed and undisclosed information)/ We managed to reach only Jennifer Miller , Todd Phillips and Dain Costlow However, these individuals dismissed the entire matter as a joke, ignoring all warnings about leaks and the importance of internal documents, and refused to provide any contact details for anyone authorized to handle such issues or to pass the information on to management, despite the availability of conclusive evidence. If you do not get in touch in the near future, the data will be published. |
||||||
| Ransomware | Advantage Home Health Care id30647 View details | United States | Healthcare / Pharma | — | — | |
|
AdvantageHHc is a healthcare company based in the US, operating in the medicine sector. The company provides various healthcare services. AdvantageHHc was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | Advantage Home Health Care id30647 View details | United States | Healthcare / Pharma | — | — | |
|
***.com zoominfo.com/c/advantage-home-health-care-inc/357944466 Advantage Home Health Care, a leading Indiana-owned provider of in-home care services with over 30 years of experience.The company operates multiple locations across Indiana, serving dozens of counties with post-procedure recovery and long-term home assistance. |
||||||
| Ransomware | Sunway Scientific id30648 View details | Taiwan, Province of China | Manufacturing / Engineering | — | — | |
|
Sun-way.com.tw is a company based in Taiwan, operating in the manufacturing and engineering sector. The company likely provides various products and services related to its sector. Sun-way.com.tw was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | Sunway Scientific id30648 View details | Taiwan, Province of China | Manufacturing / Engineering | — | — | |
|
***.com.tw zoominfo.com/c/sunway-scientific-corp/456158414 SUNWAY Co., Ltd., a leading Taiwanese distributor and exclusive agent for international scientific and laboratory equipment brands (such as HETTICH, EYELA, JASCO, and SHASHIN KAGAKU). The company specializes in providing advanced laboratory solutions, including centrifuges, freeze dryers, spectrometers, and cell disruptors for research, biotech, and chemical industries. |
||||||
| Ransomware | Tangram Interiors id30614 View details | United Kingdom | Construction / Real Estate | — | — | |
|
Tangram Interiors is a company based in the United Kingdom, operating in the construction and real estate sector. The company provides interior design and fit-out services. Tangram Interiors was listed as a ransomware victim associated with thegentlemen. |
||||||
| Ransomware | Tangram Interiors id30614 View details | United Kingdom | Construction / Real Estate | — | — | |
|
www.***.com Revenue $245.1 Million Founded in 1963, At Tangram Interiors, we've spent decades transforming spaces to inspire and empower. As industry leaders, our reputation stands on top-notch craftsmanship and innovative design. Tangram Interiors is a prominent commercial interior solutions provider and Steelcase dealer, specializing in integrated workspaces, including furniture, technology, and design. Serving Southern California, the Central Valley, and Texas, the firm offers comprehensive services ranging from space planning to custom, bespoke furniture solutions. Client pesonal data included. 400+gb |
||||||
| Ransomware | Tangram Interiors id30614 View details | United States | Construction / Real Estate | — | — | |
|
www.***.com Revenue $245.1 Million Founded in 1963, At Tangram Interiors, we've spent decades transforming spaces to inspire and empower. As industry leaders, our reputation stands on top-notch craftsmanship and innovative design. Tangram Interiors is a prominent commercial interior solutions provider and Steelcase dealer, specializing in integrated workspaces, including furniture, technology, and design. Serving Southern California, the Central Valley, and Texas, the firm offers comprehensive services ranging from space planning to custom, bespoke furniture solutions. Client pesonal data included. 400+gb |
||||||
| Ransomware | BRAC id30615 View details | Bangladesh | NGOs / Associations | — | — | |
|
BRAC is one of the largest non-governmental organizations in Bangladesh, working in various sectors including education, healthcare, and economic empowerment. The organization provides a range of services and support to vulnerable communities across the country. BRAC was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | BRAC id30615 View details | Bangladesh | NGOs / Associations | — | — | |
|
***.net zoominfo.com/c/brac-centre/8079683 is the largest non-governmental development organization in the world, founded in Bangladesh in 1972.Its mission is to empower communities facing poverty, illiteracy, disease, and social injustice.Today, it operates across multiple countries, reaching over 145 million people annually through programs in education, healthcare, livelihood, and human rights |
||||||
| Ransomware | Customs Watch id30616 View details | United States | Retail / E-commerce | — | — | |
|
Customswatch.com is an e-commerce company operating in the retail sector in the United States, offering various products to its customers. As a retail company, it provides online shopping experiences. Customswatch.com was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | Customs Watch id30616 View details | United States | Retail / E-commerce | — | — | |
|
***.com zoominfo.com/c/customs-watch/467458469 is an intelligence and IT consulting company specializing in anti-counterfeiting and product protection strategies throughout their lifecycle. The company primarily serves the pharmaceutical sector, working with 22 of the 25 largest pharmaceutical companies globally. Founded in 2001, it employs 51 to 200 people and is an active member of the International AntiCounterfeiting Coalition. |
||||||
| Ransomware | Gallant id30617 View details | Finland | IT | — | — | |
|
Gallant.fi is a Finland-based company operating in the IT sector, providing various services to its clients. The company's offerings likely include IT consulting, software development, and other technology-related solutions. Gallant.fi was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | Gallant id30617 View details | Finland | IT | — | — | |
|
***.fi zoominfo.com/c/gallant/474332534 is a forward-looking Finnish advisory and accounting company founded in 1967. It provides comprehensive financial, HR administration, taxation, and business law solutions for businesses of all sizes. The company operates in multiple locations across Finland, aiming to keep its clients one step ahead of their competition through modern financial management and strategic support |
||||||
| Ransomware | Hanseata id30618 View details | Germany | Finance / Legal / Insurance | — | — | |
|
Hanseata.de is a German company operating in the finance, legal, and insurance sectors, providing various financial services to its clients. Located in Germany, the company offers a range of services tailored to the needs of its customers. Hanseata.de was listed as a ransomware victim associated with thegentlemen. |
||||||
| Ransomware | Hanseata id30618 View details | Germany | Finance / Legal / Insurance | — | — | |
|
***.de traditional German flat glass wholesaler based near Hamburg, operating since 1953. The company specializes in supplying high-quality glass solutions, including vacuum glass, flat glass, and insulating glass, to commercial clients, architects, and construction firms worldwide. They are particularly known for their extensive stock capacity, specialized consulting for energy-efficient vacuum glazing, and comprehensive global logistics services |
||||||
| Ransomware | Metro Mondego id30595 View details | Portugal | Transportation / Travel / Logistics | — | — | |
|
Metromondego.pt is a transportation company operating in Portugal, specifically in the sector of travel and logistics. The company provides public transportation services, contributing to the country's infrastructure. Metromondego.pt was listed as a ransomware victim associated with thegentlemen. |
||||||
| Ransomware | Metro Mondego id30595 View details | Portugal | Transportation / Travel / Logistics | — | — | |
|
***.pt zoominfo.com/c/metro-mondego-sa/430685182 public transport company responsible for sustainable mobility in the Coimbra, Miranda do Corvo, and Lousã region of Portugal. Originally conceived as a light rail network, the project has been restructured into a fully electric, high-capacity Bus Rapid Transit system known as Metrobus. The network spans 42 kilometers with 42 dedicated stations and 35 electric buses, designed to provide efficient, eco-friendly, and integrated urban transportation for an estimated 13 million passengers annually |
||||||
| Ransomware | Comet Enterprise Corp id30596 View details | Taiwan, Province of China | Manufacturing / Engineering | — | — | |
|
Comet-bearing.com.tw is a company based in Taiwan, operating in the manufacturing and engineering sector. The company likely provides products and services related to bearing technology, given its name. Comet-bearing.com.tw was listed as a ransomware victim associated with thegentlemen |
||||||