Who Runs the Ransomware Group ‘The Gentlemen?’

Refract AI Intelligence Digest

BLUF

The Gentlemen ransomware gang is surging in activity due to lucrative affiliate deals, while investigators close in on its operator's identity.

NEWS

The Gentlemen has become the second most active ransomware group by victim count through aggressive recruitment promising affiliates 90% of ransom payments. Krebs on Security reports new intelligence suggesting potential leads on the real-world identity of the group's administrator. This high-revenue model is driving rapid expansion within the cybercrime ecosystem.

Why I Care

Organizations face increased ransomware risk as this group prioritizes volume over negotiation leverage. The high affiliate payout incentivizes more skilled attackers to join, escalating the threat landscape for all sectors. Identifying the operator could disrupt operations and aid law enforcement efforts.

Next Steps

Security teams should monitor for indicators of compromise associated with The Gentlemen immediately. CISOs must review incident response plans to account for groups offering high affiliate splits. Legal and IR teams should prepare for potential extortion attempts within the next quarter.

A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of hackers through an aggressive recruitment strategy that promises affiliates 90 percent of any ransom paid by victims. This post examines clues pointing to a real life identity for the administrator of The Gentlemen ransomware group.
Back to Blog Listing

Source: Krebs on Security ·

This digest was generated by Refract AI Collective to help the public sector security community stay informed.