Adaptavist Group, a UK enterprise software consultancy, disclosed a security breach after an unauthorized actor used stolen credentials in late March to access some of its systems. The company said it launched an internal review and brought in external forensic specialists to investigate, adding that the affected environment held routine business information including contact details, contracts, and NDAs. Adaptavist said it has found no evidence that customer or partner personal data, client systems, or production systems were compromised, and disputed claims that sensitive customer data was accessed or exfiltrated.
A ransomware group calling itself The Gentlemen claimed responsibility on its leak site and alleged a far broader intrusion, including theft of customer records, source code, internal documents, credentials, and access to production systems, but those assertions remain unverified. Adaptavist also warned that unknown actors are sending misleading emails impersonating the company, suggesting follow-on phishing activity linked to the incident while the forensic investigation continues.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Adaptavist reported that unknown actors were sending misleading emails impersonating the company following the incident. The activity suggested follow-on phishing attempts connected to the breach.
By April 2026, the ransomware group calling itself The Gentlemen posted claims that it had fully compromised Adaptavist's infrastructure and stolen customer records, source code, internal documents, credentials, and other data. Adaptavist disputed the breadth of those claims and said they remained unverified.
After discovering the intrusion in late March, Adaptavist began an internal review and engaged external security specialists to investigate the incident. The company said it had found no evidence that customer or partner personal data, client systems, production systems, or sensitive customer data were accessed or exfiltrated.
In late March 2026, an unauthorized individual gained access to some Adaptavist Group systems using stolen credentials. The affected systems reportedly contained typical business information such as contact details, contracts, and NDAs.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.