The Gentlemen Ransomware: Emerging Multi-Region Enterprise Threat — 80+ Victims Across 30+ Countries Since September 2025 — Threadlinqs Intelligence
As of 2026-05-30, The Gentlemen Ransomware: Emerging Multi-Region Enterprise Threat — 80+ Victims Across 30+ Countries Since September 2025 is a high-severity ransomware threat attributed to The Gentlemen, tracked by Threadlinqs Intelligence with 12 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 30 indicators of compromise.
Threat ID: TL-2026-0076 · Severity: HIGH · CVSS: 7.5 · Status: ACTIVE · Category: RANSOMWARE
Attribution: The Gentlemen · FINANCIAL
The Gentlemen is an emerging ransomware group first observed in September 2025 that has rapidly established itself as a prolific, multi-region enterprise threat with 80+ confirmed victims across 30+
The Gentlemen ransomware group represents a new entrant in the Ransomware-as-a-Service (RaaS) ecosystem that has achieved remarkable scale in under 6 months of observed operations. First tracked in September 2025 with initial victims (JN Aceros, Flexofast Indonesia, Cremona Inoxidable), the group has grown to 80+ confirmed victims by February 2026.
OPERATIONAL CHARACTERISTICS:
1. GEOGRAPHIC TARGETING — Unusually broad geographic spread across 30+ countries:
- Southeast Asia: Thailand (multiple — USTAR, BioNet-Asia, Lotus Bedding, JIEI, Thai Future Inc.), Vietnam (SASI JSC, AiHealth, KIM Dental, Donacoop), Taiwan (NFT Technology, PAO HWA, Wieson Technologies), Philippines (Personal Collection, 2GO Group), Indonesia (Flexofast, PT Pupuk Iskandar Muda), Malaysia (WCT Holdings, PLUS Malaysia, BIB Insurance)
- Latin America: Brazil (UniFil, Stewart Engenharia, Santa Casa de Assis, Unimed Anápolis), Colombia (Área Limpia, Autofinanciera), Peru (JN Aceros, AUSA), Mexico (Cadisa, Del Campo Supreme), Chile (Seguros la Cámara), Ecuador (Ecuacorriente)
- Europe: Spain (CPQ Ingenieros, Sansala, L'Aeroclub, Grupo Halcon), Italy (Silvi SRL, ICET Studios, Talarico, Sita Sud), Portugal (Museu do Caramulo), France (Hafa), Germany (Röben, BAM), Ireland (Smartply Europe), Poland (MBM, Wamtechnik, Systherm, Hart), Czech Republic (Garko, Orlík), Sweden (Hafa), Austria (Gady Family), Luxembourg (BAM)
- Middle East/Africa: UAE (Marina Home Interiors), Israel (Magen Eco Energy, Shtainmetz Aminoach), Turkey (Erg Otoyol, Ankara-İzmir, Pos Bilişim, Dekoyap), South Africa (Rola Motor Group, Paltrack), Kenya (Wells Fargo Ltd, CPF Financial), Ghana (energy sector), Madagascar (Madagascar Airlines), Mauritius (Rogers Capital)
- North America: USA (Clark Foam Products, KlearNow.AI, Hog Slat, Abatix, Infinite Tiers, Dome Partners, Torus), Canada (All Rush)
- Other: Hong Kong (Novetex Textiles), Japan (Nishiyama Seisakusho, Sincere Corp), India (Nobel Hygiene, DRD Communications), Dominican Republic (Casa de España), Zimbabwe (Proplastics)
2. SECTOR DIVERSITY — Targeting across all major industries:
- Manufacturing: Clark Foam, Smartply, Novetex Textiles, Nishiyama, Röben, Silvi SRL, Wieson Technologies, Nobel Hygiene, Flexofast, Cremona Inoxidable
- Financial Services: Wells Fargo Ltd (Kenya), EXIM Bank (Jamaica), CPF Financial, Rogers Capital, Kandeo Fund, Silverlake Axis
- Construction/Infrastructure: WCT Holdings, Erg Otoyol, PLUS Malaysia, Ankara-İzmir Railway, CPQ Ingenieros
- Education: Thammasat University, British School of Brasilia, UniFil, MBM, Cervantes
- Healthcare: Unimed Anápolis, KIM Dental, AiHealth, BioNet-Asia (vaccine manufacturer), Santa Casa de Assis
- Technology: KlearNow.AI, NFT Technology, Silverlake Axis, Infinite Tiers, Pos Bilişim
- Transportation/Logistics: PLUS Malaysia, 2GO Group, Madagascar Airlines, AUSA, L'Aeroclub, Sita Sud
3. OPERATIONAL TEMPO — Rapid escalation:
- Sep 2025: ~10 initial victims (first observed)
- Oct 2025: ~10 additional victims including publicly traded companies
- Nov 2025: ~8 victims including Colliers International ($5.2B)
- Dec 2025: ~8 victims across 5 countries
- Jan 2026: ~20+ victims — dramatic acceleration
- Feb 2026 (first 11 days): 15+ new victims — sustained high tempo
4. DATA EXFILTRATION SCALE:
- KlearNow.AI: 3 TB of data including 'all correspondence'
- Unnamed Asian investment firm: 1.5 TB (company with >$10B AUM)
- Regional grocery network: 'entire infrastructure' of ~80 stores
- Multi-terabyte theft indicates dwell time for staging and exfiltration
5. ATTACK TIMING DISCREPANCIES:
- Several victims show attack dates MONTHS before discovery (Thin Red Line: attacked Sep 2025, discovered Feb 2026 — 5 months)
- Multiple victims listed with 'Estimated Attack Date: 2025-02-19' suggesting possible bulk data from early 2025 operations or a different dating methodology
- Rapid posting of 15+ victims in a single week
Target sectors: Manufacturing, Financial Services, Construction, Education, Healthcare, Technology, Transportation, Energy, Public Sector, Consumer Services, Automotive
Target regions: Southeast Asia, Latin America, Europe, Middle East, Africa, North America, East Asia
Detections & IOCs
As of 2026-07-28, this threat has 12 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 30 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
RANSOMWARE, HIGH, threat intelligence, cybersecurity, T1591, T1588, T1585, T1190, T1078, T1566, T1059, T1543, T1078, T1562