Who Runs the Ransomware Group ‘The Gentlemen?’
BLUF
The Gentlemen ransomware gang is surging in activity due to lucrative affiliate deals, while investigators close in on its operator's identity.
NEWS
The Gentlemen has become the second most active ransomware group by victim count through aggressive recruitment promising affiliates 90% of ransom payments. Krebs on Security reports new intelligence suggesting potential leads on the real-world identity of the group's administrator. This high-revenue model is driving rapid expansion within the cybercrime ecosystem.
Why I Care
Organizations face increased ransomware risk as this group prioritizes volume over negotiation leverage. The high affiliate payout incentivizes more skilled attackers to join, escalating the threat landscape for all sectors. Identifying the operator could disrupt operations and aid law enforcement efforts.
Next Steps
Security teams should monitor for indicators of compromise associated with The Gentlemen immediately. CISOs must review incident response plans to account for groups offering high affiliate splits. Legal and IR teams should prepare for potential extortion attempts within the next quarter.
Source: Krebs on Security ·
