Gentlemen ransomware hits big companies

Published July 1, 2026

The Gentlemen ransomware gang locks up data and demands payment from large businesses and critical sites. They use strong encryption to block access until victims pay a ransom.

Report priority
High
Involves
Gentlemen ransomware group
Group
Gentlemen

What is known

Attackers break in through internet-facing VPNs and firewalls using leaked, default, or bought login credentials, then spread across the network using stolen admin tools and a fake Windows update policy that turns off antivirus before locking every machine.

What to do

Check if your company was listed on the Gentlemen ransomware group's leak site or received a ransom demand.

Do not pay the ransom. Isolate infected systems immediately and contact your IT security team or a cybersecurity firm for help.

Reported details

A logistics company's IT team notices files are locked and renamed with a. Gentlemen extension. The attackers sent phishing emails with fake invoices, tricking an employee into opening a malicious attachment. The malware then spread through the network, encrypting servers and workstations. The attackers left a ransom note on every locked screen demanding $5 million in Bitcoin.

The Gentlemen RaaS operation, active since mid-2025 and accelerating since February 2026, offers affiliates a 90/10 revenue split versus the industry-standard 80/20, which is pulling experienced operators from other ransomware brands. Initial access comes from exposed VPNs and firewalls. Internal recon uses SharpADWS, NetScan and Advanced IP Scanner; lateral movement rides NETLOGON shares and a custom deploy_gpo.ps1 script, with PsExec as backup.

The group disables Windows Defender via fake update GPOs and BYOVD attacks using drivers such as ProcessMonitorDriver.sys and biontdrv.sys. Its Go-based ransomware uses Curve25519 with XChaCha20 encryption and a Yamux-based backdoor for C2; a C variant with an ESXi locker uses AES-256-GCM with RSA-wrapped keys.