Inside the Gentlemen Leak: How a New RaaS Gang Rapidly Scaled in 2026
A leaked internal database from The Gentlemen ransomware group exposed how the young RaaS operation rapidly scaled in 2026 using an affiliate model, exploitation of internet‑facing devices such as Fortinet and Cisco s... Internal chats and backend data from late 2025 to April 2026 revealed operational details about...
Published byEdited with GPT-5.5Images generated with GPT Image 2
A leaked internal database from The Gentlemen ransomware group exposed how the young RaaS operation rapidly scaled in 2026 using an affiliate model, exploitation of internet‑facing devices such as Fortinet and Cisco s...
Internal chats and backend data from late 2025 to April 2026 revealed operational details about affiliates, attack infrastructure, and victim targeting, offering rare insight into how modern ransomware‑as‑a‑service gr...
The leak highlights a major defensive lesson: exposed edge devices like firewalls, VPN gateways, and network management systems remain one of the most common and dangerous entry points for ransomware attacks.
What did the leaked internal database reveal about The Gentlemen ransomware-as-a-service gang’s operations, including its rapid rise in 2026Researchers gained rare insight into The Gentlemen ransomware operation after internal chats and backend data were leaked online.
AI Prompt
Create a landscape editorial hero image for this Studio Global article: What did the leaked internal database reveal about The Gentlemen ransomware-as-a-service gang’s operations, including its rapid rise in 2026. Article summary: The leak showed The Gentlemen is a young RaaS operation whose internal chats and alleged backend data were partially exposed, but the material should be treated as an incomplete view rather than a full organizational map. Topic tags: general, general web, government. Reference image context from search candidates: Reference image 1: visual subject "The Gentlemen ransomware emerged as a formidable Ransomware-as-a-Service (RaaS) operation in June 2025 and has rapidly escalated into a global cyber threat, claiming over 320 victi" source context "The Gentlemen Ransomware: A Rapidly Scaling RaaS Threat" Reference image 2: visual subject "Nascent ransomware-as-a-serv
openai.com
A rare look inside a rising ransomware operation
In May 2026, researchers uncovered leaked internal data from The Gentlemen, a rapidly growing ransomware‑as‑a‑service (RaaS) group that emerged in mid‑2025. The leak—advertised on underground forums—contained internal chat logs and backend data spanning roughly November 2025 to April 2026, providing an unusually detailed glimpse into how the gang organized its operations and carried out attacks. However, analysts caution that the dataset appears partial, meaning it should not be treated as a complete map of the organization.
Even so, the material offers valuable insight into how a modern ransomware ecosystem operates—from affiliate recruitment and infrastructure management to the exploitation of internet‑facing devices.
Studio Global AI
Continue your research
This page includes a source-backed answer you can continue inside Studio Global.
What is the short answer to "Inside the Gentlemen Leak: How a New RaaS Gang Rapidly Scaled in 2026"?
A leaked internal database from The Gentlemen ransomware group exposed how the young RaaS operation rapidly scaled in 2026 using an affiliate model, exploitation of internet‑facing devices such as Fortinet and Cisco s...
What are the key points to validate first?
A leaked internal database from The Gentlemen ransomware group exposed how the young RaaS operation rapidly scaled in 2026 using an affiliate model, exploitation of internet‑facing devices such as Fortinet and Cisco s... Internal chats and backend data from late 2025 to April 2026 revealed operational details about affiliates, attack infrastructure, and victim targeting, offering rare insight into how modern ransomware‑as‑a‑service gr...
What should I do next in practice?
The leak highlights a major defensive lesson: exposed edge devices like firewalls, VPN gateways, and network management systems remain one of the most common and dangerous entry points for ransomware attacks.
The Gentlemen is considered a relatively new ransomware brand, but it grew quickly. By early 2026, its data‑leak site listed hundreds of victim organizations across more than 50 countries, reflecting the typical double‑extortion strategy of stealing data before encrypting systems and threatening public release if a ransom is not paid.
Security reporting indicates the group became one of the most active RaaS programs in 2026. Researchers observed about 332 victims listed on its leak site in the first five months of the year alone, highlighting the speed at which the operation scaled.
Quarterly tracking also showed dramatic growth: the group posted 179 victims in Q1 2026—up 588% from just 26 victims in Q4 2025.
How the RaaS business model works
Like many modern ransomware gangs, The Gentlemen operates as a ransomware‑as‑a‑service platform, meaning core developers build the malware and infrastructure while outside affiliates conduct intrusions and deploy the ransomware.
The leaked backend database exposed internal accounts and operational data tied to this ecosystem. Researchers observed multiple operator accounts connected to the RaaS panel, with the infrastructure reportedly administered by a core operator known as “zeta88” (also called “hastalamuerte”).
In this model:
Core operators maintain the ransomware builder, infrastructure, and payment systems.
Affiliates perform the intrusions, data theft, and ransomware deployment.
Profits from ransom payments are split between the affiliates and the platform operators.
This division of labor allows the group to scale quickly while keeping the core team relatively small.
Targeting exposed edge infrastructure
One of the most important revelations from the leak is how heavily the group relied on internet‑facing network infrastructure for initial access.
Researchers linked the group’s intrusions to attacks on devices such as firewalls, VPN gateways, and network management systems—especially those exposed directly to the internet.
A key vulnerability repeatedly associated with their operations is CVE‑2024‑55591, a critical authentication‑bypass flaw affecting FortiOS and FortiProxy. The vulnerability can allow remote attackers to gain super‑administrator privileges through crafted requests.
By targeting edge appliances rather than endpoints, attackers can bypass many traditional security controls and gain a privileged foothold inside corporate networks.
A massive inventory of compromised FortiGate devices
Another striking detail from threat‑intelligence reporting is the scale of infrastructure the group appears to maintain.
Investigators found evidence that the operation tracked around 14,700 already exploited FortiGate devices worldwide, along with hundreds of validated VPN credentials associated with those systems.
Such an inventory can function as a pipeline for future attacks. Once access is obtained to a perimeter device, attackers can move deeper into a network without triggering the same defenses that typically detect phishing or malware delivery.
What the leaked chats revealed about operations
Although the leak is incomplete, internal communications provided insight into how the group coordinated attacks and managed campaigns. Chat channels documented discussions related to:
targeting and victim selection
infrastructure management
affiliate activity
coordination before publicly claiming victims
Researchers noted that the data included conversations across several operational channels and backend systems, shedding light on the timeline and workflow of ransomware campaigns.
Why the leak matters for defenders
Beyond exposing one ransomware group, the leak highlights a broader pattern in modern cybercrime: edge infrastructure is now a primary entry point for ransomware attacks.
Security teams often focus heavily on endpoint protection, but compromised firewalls, VPN appliances, and network management systems can effectively bypass those defenses. Once attackers control those systems, they can escalate privileges, harvest credentials, and move laterally inside the network.
Key defensive priorities include:
Rapid patching of edge appliances, especially critical flaws such as CVE‑2024‑55591 affecting Fortinet devices.
Removing public exposure of management interfaces whenever possible.
Using multi‑factor authentication and network segmentation for administrative access.
Monitoring logs from firewalls, VPN systems, and management interfaces as potential early indicators of compromise.
A partial but valuable window into ransomware operations
The leaked database does not reveal the full structure of The Gentlemen ransomware organization. Researchers emphasize that the dataset represents only a partial snapshot of internal activity, not the complete ecosystem.
Still, the leak offers a rare inside view of how a modern ransomware‑as‑a‑service program operates—and how quickly such operations can scale when affiliates, automated tooling, and exposed infrastructure combine.
For defenders, the message is clear: the network edge has become one of the most critical security frontiers in the ransomware era.