Skip to content

The Gentlemen: New Ransomware Group Claims Top Position in Threat Landscape

Bottom line: The Gentlemen, a ransomware group founded in early 2025 with access to 14,000 compromised FortiGate devices, has risen to become the world’s most active extortion group with a 17 percent market share.

The Gentlemen ransomware group has developed into the world’s most active extortion group within just a few months, displacing established competitors such as Qilin and LockBit. The group employs a combination of data encryption, publication extortion, and access to thousands of compromised network devices.

The Gentlemen was founded in mid-2025 by a Russian-speaking actor who previously worked as an affiliate for the ransomware groups Qilin and LockBit. According to Check Point, the group achieved a 17 percent share of all known ransomware attacks globally in June 2026, surpassing the previous market leader Qilin (11 percent). In total, Check Point counted 646 publicly reported ransomware attacks in June — an increase of 33 percent compared to the previous year.

The group operates under the Ransomware-as-a-Service (RaaS) model, providing attackers with malware and infrastructure in exchange for profit sharing. Additionally, The Gentlemen acts as an access broker, offering affiliates access to approximately 14,000 compromised Fortinet FortiGate devices. This enables rapid entry points into target networks and significantly contributes to the group’s speed: within just a few months, the group publicly listed over 320 victims.

Technically, The Gentlemen specifically targets externally accessible network devices, particularly FortiGate firewalls. Affiliates exploit known vulnerabilities in FortiOS or use brute-force attacks against VPN access points, often supported by a database of already compromised credentials. Following initial compromise, the attackers conduct extensive Active Directory reconnaissance, disable security software, and exfiltrate data — before final encryption via group policies. The ransomware itself is based on the XChaCha20 and Curve25519 encryption algorithms and runs cross-platform on Windows, Linux, and ESXi. In worm mode, it can spread independently across the network.

The Gentlemen employs double extortion: in addition to encrypting systems, the group threatens to publish previously stolen data if payment is refused. The victim list includes over 320 organizations from more than 60 countries and over 20 industries — with a focus on manufacturing, healthcare, and financial services. Notable victims include Chinese industrial supplier Dongguan HYX Industrial, financial services firm Rogers Capital, and Warka Bank for Investment and Finance. In one case, the group claimed to have stolen 1.5 terabytes of data from a company named Solumek.

On a global level, the extortion landscape is consolidating: the three largest groups (The Gentlemen, Qilin, LockBit with 7 percent each in June) together account for 35 percent of all registered attacks. The business services sector is most heavily affected, accounting for 31 percent of all attacks.


Source: www.it-daily.net · Published July 15, 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification via Lumi News Pipeline v1.7.3.

Share on: