The Gentlemen is a financially motivated ransomware-as-a-service operation that emerged around mid-2025. Microsoft Threat Intelligence tracks the platform’s operators as Storm-2697 and reports that the operation began as a closed group before opening to affiliates in September 2025. Affiliates carry out intrusions, so a leak-site claim or malware association should not be treated as proof that the same people conducted every attributed attack.
Activity and targeting
The operation uses double extortion, combining encryption with data theft and threatened public release. Microsoft has observed The Gentlemen ransomware affecting education, transportation, healthcare and financial organizations across several continents. Check Point Research described a rapidly expanding affiliate program and reported more than 320 organizations listed on the group’s data-leak site by April 2026. Leak-site counts represent actor claims and should not be read as independently verified incident totals.
Check Point characterized the activity as largely opportunistic, emphasizing exposed or vulnerable internet-facing infrastructure rather than a single geographic or sector target set. Its incident-response research observed rapid progression from established administrative access through credential validation, lateral movement, security-tool disruption and domain-wide ransomware deployment. These findings describe observed Gentlemen-affiliate tradecraft, not a confirmed method for every claimed victim.
Methods and operational characteristics
Microsoft analyzed a Go-based Windows encryptor that uses per-file Curve25519 and XChaCha20 encryption, supports partial-encryption speed modes, targets local and network shares, deletes shadow copies, can overwrite free disk space, and attempts to propagate through several lateral-movement methods. The platform’s extortion model includes exfiltration and threatened disclosure as pressure for payment.
Check Point reported that affiliates commonly seek entry through internet-facing VPNs, firewalls and remote-access gateways, then move quickly once privileged access is available. Its research also described support for Windows, Linux and ESXi environments and a revenue split designed to attract experienced affiliates.
What type of group is it?
The Gentlemen is best characterized as a financially motivated ransomware group operating a service and affiliate ecosystem. Public CTI supports a profit-driven encryption and data-extortion model rather than political or state-directed objectives. Incident-level attribution should remain evidence-specific: the operator brand, affiliates, ransomware family and leak site are related parts of an ecosystem, but a public listing alone does not establish who gained access, whether the listed organization was encrypted, or whether claimed data was actually taken.