Skip to content

The Gentlemen

Ransomware Group3 claimsLast activity:

Overview

The Gentlemen is a financially motivated ransomware-as-a-service operation that emerged around mid-2025. Microsoft Threat Intelligence tracks the platform’s operators as Storm-2697 and reports that the operation began as a closed group before opening to affiliates in September 2025. Affiliates carry out intrusions, so a leak-site claim or malware association should not be treated as proof that the same people conducted every attributed attack.

Activity and targeting

The operation uses double extortion, combining encryption with data theft and threatened public release. Microsoft has observed The Gentlemen ransomware affecting education, transportation, healthcare and financial organizations across several continents. Check Point Research described a rapidly expanding affiliate program and reported more than 320 organizations listed on the group’s data-leak site by April 2026. Leak-site counts represent actor claims and should not be read as independently verified incident totals.

Check Point characterized the activity as largely opportunistic, emphasizing exposed or vulnerable internet-facing infrastructure rather than a single geographic or sector target set. Its incident-response research observed rapid progression from established administrative access through credential validation, lateral movement, security-tool disruption and domain-wide ransomware deployment. These findings describe observed Gentlemen-affiliate tradecraft, not a confirmed method for every claimed victim.

Methods and operational characteristics

Microsoft analyzed a Go-based Windows encryptor that uses per-file Curve25519 and XChaCha20 encryption, supports partial-encryption speed modes, targets local and network shares, deletes shadow copies, can overwrite free disk space, and attempts to propagate through several lateral-movement methods. The platform’s extortion model includes exfiltration and threatened disclosure as pressure for payment.

Check Point reported that affiliates commonly seek entry through internet-facing VPNs, firewalls and remote-access gateways, then move quickly once privileged access is available. Its research also described support for Windows, Linux and ESXi environments and a revenue split designed to attract experienced affiliates.

What type of group is it?

The Gentlemen is best characterized as a financially motivated ransomware group operating a service and affiliate ecosystem. Public CTI supports a profit-driven encryption and data-extortion model rather than political or state-directed objectives. Incident-level attribution should remain evidence-specific: the operator brand, affiliates, ransomware family and leak site are related parts of an ecosystem, but a public listing alone does not establish who gained access, whether the listed organization was encrypted, or whether claimed data was actually taken.

Incident claims

AnMed ransomware disrupts systems and patient care

View public claim
Incident date: Source: ransomware.livePublished: Discovered:

Claim details

Ransomware.live indexed an AnMed entry attributed to The Gentlemen, listing anmed.org and a publication time of Aug. 9. Gentlemen-branded messages later appeared through AnMed’s compromised social-media presence, linking to thegentlemen.st and claiming full network access and 6 terabytes of highly sensitive medical, identity, reproductive-health, behavioral-health, forensic and sexual-assault records. The messages offered samples and promised deletion and confidentiality in exchange for cooperation and payment.

AnMed confirmed that unauthorized posts appeared on its social-media accounts. Its Aug. 27 notice says a virus locked access to network files and files on certain systems were copied without permission, but it does not attribute the incident to The Gentlemen or validate the claimed volume, categories, encryption implementation or public release. Earlier victim-specific access to an Interlock negotiation server remains material contrary evidence.

Kenaitze Indian Tribe cybersecurity incident

View public claim
Incident date: Source: ransomware.livePublished: Discovered:

Claim details

Ransomware.live recorded a The Gentlemen leak-site claim against the Kenaitze Indian Tribe. The Tribe acknowledged that an unknown actor had claimed responsibility and said the claim was under investigation, but it did not confirm The Gentlemen, ransomware, data theft or a ransom demand.

Boyne City cyber incident disrupts utility billing

Incident date: Source: ransomware.liveDiscovered:

Claim details

Multiple public ransomware trackers recorded a later TheGentlemen claim involving Boyne City, but the claim could not be independently verified from the actor’s original leak site. The trackers consistently identify the victim as The City of Boyne City or City of Boyne City, associate the claim with cityofboynecity.com, and place the claim window around Jun. 30 to Jul. 1, 2026. Direct validation from TheGentlemen’s claim site was not possible because the site appeared consistently unreachable during review. The claim is assessed as plausible with medium confidence as a leak-site listing, but low confidence as confirmed attribution to the May incident because Boyne City has not publicly confirmed TheGentlemen, ransomware deployment, data theft, encryption, a ransom demand or leaked files.

Impacted organizations

Impacted locations

Sources