The Gentlemen ransomware group, also tracked as Storm-2697, has been linked to a string of new victims across multiple sectors and countries, including Dutch ice arena Thialf, U.S. IT services firm Promatrix, Indian companies Delkart Industries, Kontact Consortium India, and Indus Protech Solutions, and the UK-based Angel Hotel. In the Thialf incident, the attackers threatened to leak allegedly stolen internal documents, employee data, and financial contracts unless a ransom was paid, while the venue said its forensic investigation found minimal impact and no compromise of operational processes or core data. Reporting described Thialf as the group’s eighth known victim in the Netherlands and said the gang uses double extortion to pressure targets.
Separate technical reporting said The Gentlemen is deploying a kernel-level driver, anticheatG13.sys, to disable endpoint protections before encryption. Analysts said the driver can terminate nearly 180 security-related processes and supports process manipulation, file operations, kernel-memory modification, and network traffic control or redirection, extending functionality previously associated with G12drv.sys. The capability underscores a more aggressive tradecraft pattern in which ransomware operators use privileged drivers to suppress detection and forensic visibility before locking systems and threatening data exposure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
24 events from the most recent confirmed update back to the earliest known activity.
Control Concepts Technology, a Texas-based industrial automation and electronics repair company in the United States, was identified as the victim of a ransomware-related data breach attributed to thegentlemen. The incident report lists the breach time as August 4, 2026 at 13:00 UTC and associates the attack with the domain controlconceptstexas.com.
TopMark Funding, a U.S.-based commercial financing company in California, was identified as the victim of a ransomware-related data breach attributed to thegentlemen. The report lists the breach time as August 4, 2026 at 12:59 UTC and associates the attack with the domain topmarkfunding.com.
Philippine Savings Bank, a financial services organization in the Philippines, was reported as the victim of a ransomware-related data breach attributed to thegentlemen. The incident report lists the breach time as August 1, 2026 at 13:09 UTC and associates the attack with the domain psbank.com.ph.
CFS Inc., a Massachusetts-based U.S. company operating the domain cfsinc.com, was identified as the victim of a ransomware attack attributed to thegentlemen. The report lists the breach time as July 31, 2026 at 11:55 UTC and classifies the organization in the United States.
Krafman, a Sweden-based organization operated by Krafguard AB, was identified as the victim of a ransomware-related data breach attributed to thegentlemen. The incident report lists the breach time as July 31, 2026 at 11:33 UTC and associates the attack with the domain krafman.se.
Additive Manufacturing LLC, a U.S.-based manufacturing company in Las Vegas, Nevada, was identified as the victim of a ransomware attack attributed to thegentlemen. The incident report lists the breach time as July 31, 2026 at 11:24 UTC and associates the attack with the domain additivemanufacturingllc.com.
Kosh Innovations, a manufacturing solutions provider associated with the domain koshinnovations.com, was identified as the victim of a ransomware-related data breach attributed to thegentlemen. The report lists the breach time as July 31, 2026 at 11:39 UTC.
Saturn Industries, a Winnipeg, Manitoba-based manufacturer, was identified as the victim of a ransomware attack attributed to thegentlemen. The incident report lists the breach time as July 31, 2026 at 11:41 UTC and associates the attack with the domain saturnind.com.
Salem Saleh Babgi, associated with Saudi Arabia's Babgi Group, was identified as the victim of a ransomware-related data breach attributed to thegentlemen. The incident report lists the breach time as July 31, 2026 at 11:26 UTC and associates the attack with the domain babgi.com.sa.
Kenaitze Indian Tribe, a federally recognized sovereign nation on Alaska’s Kenai Peninsula, was identified as the victim of a ransomware attack attributed to thegentlemen. The incident report lists the breach time as July 31, 2026 at 11:17 UTC and associates the attack with the domain kenaitze.org.
The Angel Hotel incident was discovered on July 30, 2026, according to the report. The affected organization is a hospitality business in Worcestershire, Great Britain.
The Indus Protech Solutions incident was discovered on July 30, 2026, at 06:48 UTC, according to the report. The affected organization was categorized in the technology sector.
The Kontact Consortium India Pvt incident was discovered on July 30, 2026, according to the report. The company provides engineering services in India.
The Delkart Industries Pvt incident was discovered on July 30, 2026, according to the report. The victim operates in the manufacturing sector in India.
The Promatrix incident was discovered on July 30, 2026, according to the incident report. The victim was identified in the technology sector in the United States.
Angel Hotel in Great Britain was identified as the victim of a ransomware-related data breach attributed to thegentlemen. The breach timestamp was listed as July 29, 2026.
Indus Protech Solutions, a Chennai-based technology company, was identified as a victim of a ransomware attack attributed to thegentlemen. The breach was dated July 29, 2026, at 19:36 UTC.
Kontact Consortium India Pvt, an Indian engineering company, was identified as a victim of a ransomware attack attributed to thegentlemen. The report states the breach occurred on July 29, 2026.
Delkart Industries Pvt, an Indian manufacturing company, was identified as a victim of a ransomware attack attributed to thegentlemen. The incident report states the breach occurred on July 29, 2026.
Promatrix, a U.S.-based IT consulting and outsourcing company, was reported as the victim of a ransomware-related breach attributed to thegentlemen. The report lists the breach date as July 29, 2026.
Catalyst analysts identified a kernel-level driver, anticheatG13.sys, used by The Gentlemen ransomware operation to disable security software before encryption. The reporting says the driver can terminate nearly 180 security-related processes and extends functionality seen in a related component, G12drv.sys.
The ransomware group The Gentlemen, also tracked as Storm-2697, claimed responsibility for the Thialf attack and threatened to publish allegedly stolen data if a ransom was not paid within days. The group said it had taken internal documents, employee information, financial contracts, and other sensitive material.
After investigating the incident, Thialf said its forensic investigation found minimal impact and concluded that its data and operational processes were not compromised. This was the organization’s official response to the attack claims.
Dutch ice arena Thialf in Heerenveen was targeted in a ransomware attack. Reporting said the attackers demanded payment to restore access to computer systems and to prevent an alleged data leak.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
18 references tracked. Mallory keeps watching after this page renders.
hookphish.com
Open sourcehookphish.com
Open sourcehookphish.com
Open sourcehookphish.com
Open sourcehookphish.com
Open sourcehookphish.com
Open sourcehookphish.com
Open sourceteiss.co.uk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.