Skip to content

The Gentlemen

Ransomware Group3 claimsLast activity:

Overview

The Gentlemen is a financially motivated ransomware-as-a-service operation that emerged around mid-2025. Microsoft Threat Intelligence tracks the platform’s operators as Storm-2697 and reports that the operation began as a closed group before opening to affiliates in September 2025. Affiliates carry out intrusions, so a leak-site claim or malware association should not be treated as proof that the same people conducted every attributed attack.

Activity and targeting

The operation uses double extortion, combining encryption with data theft and threatened public release. Microsoft has observed The Gentlemen ransomware affecting education, transportation, healthcare and financial organizations across several continents. Check Point Research described a rapidly expanding affiliate program and reported more than 320 organizations listed on the group’s data-leak site by April 2026. Leak-site counts represent actor claims and should not be read as independently verified incident totals.

Check Point characterized the activity as largely opportunistic, emphasizing exposed or vulnerable internet-facing infrastructure rather than a single geographic or sector target set. Its incident-response research observed rapid progression from established administrative access through credential validation, lateral movement, security-tool disruption and domain-wide ransomware deployment. These findings describe observed Gentlemen-affiliate tradecraft, not a confirmed method for every claimed victim.

Methods and operational characteristics

Microsoft analyzed a Go-based Windows encryptor that uses per-file Curve25519 and XChaCha20 encryption, supports partial-encryption speed modes, targets local and network shares, deletes shadow copies, can overwrite free disk space, and attempts to propagate through several lateral-movement methods. The platform’s extortion model includes exfiltration and threatened disclosure as pressure for payment.

Check Point reported that affiliates commonly seek entry through internet-facing VPNs, firewalls and remote-access gateways, then move quickly once privileged access is available. Its research also described support for Windows, Linux and ESXi environments and a revenue split designed to attract experienced affiliates.

What type of group is it?

The Gentlemen is best characterized as a financially motivated ransomware group operating a service and affiliate ecosystem. Public CTI supports a profit-driven encryption and data-extortion model rather than political or state-directed objectives. Incident-level attribution should remain evidence-specific: the operator brand, affiliates, ransomware family and leak site are related parts of an ecosystem, but a public listing alone does not establish who gained access, whether the listed organization was encrypted, or whether claimed data was actually taken.

Incident claims

AnMed ransomware disrupts systems and patient care

Incident date: Source: XPublished: Discovered:

Claim details

International Cyber Digest published an image of Gentlemen-branded messages posted through AnMed’s social-media presence. The image displays AnMed’s account name, links to thegentlemen.st and claims full network access and 6 terabytes of exfiltration, including highly sensitive medical, identity, reproductive-health, behavioral-health, forensic and sexual-assault records. It offers samples and promises deletion and confidentiality in exchange for cooperation and payment. AnMed later confirmed that unauthorized posts appeared on its social-media accounts, removed the content and disabled platform access, but said the posts’ claims had not been verified. Earlier victim-specific access to an Interlock negotiation server provides stronger operational attribution evidence and remains material contrary evidence. The Gentlemen claim is not treated as confirmed actor responsibility, encryption, data theft, data volume or affected-data scope.

Kenaitze Indian Tribe Cybersecurity Incident

View public claim
Incident date: Source: ransomware.livePublished: Discovered:

Claim details

Ransomware.live recorded a The Gentlemen leak-site claim against the Kenaitze Indian Tribe. The Tribe acknowledged that an unknown actor had claimed responsibility and said the claim was under investigation, but it did not confirm The Gentlemen, ransomware, data theft or a ransom demand.

Boyne City cyber incident disrupts utility billing

Incident date: Source: ransomware.liveDiscovered:

Claim details

Multiple public ransomware trackers recorded a later TheGentlemen claim involving Boyne City, but the claim could not be independently verified from the actor’s original leak site. The trackers consistently identify the victim as The City of Boyne City or City of Boyne City, associate the claim with cityofboynecity.com, and place the claim window around Jun. 30 to Jul. 1, 2026. Direct validation from TheGentlemen’s claim site was not possible because the site appeared consistently unreachable during review. The claim is assessed as plausible with medium confidence as a leak-site listing, but low confidence as confirmed attribution to the May incident because Boyne City has not publicly confirmed TheGentlemen, ransomware deployment, data theft, encryption, a ransom demand or leaked files.

Impacted organizations

Impacted locations

Sources