TheGentlemen ransomware group was linked to a string of newly reported intrusions affecting organizations in several countries and sectors, including Senvest Capital in financial services, Euroscreen in digital printing and projection technology, CRASL Accounting Services in the UK, Roadvision Systems in transportation software, Babcock Africa in engineering and critical infrastructure support, Gfeller Treuhand in Switzerland, and San Carlo Gruppo Alimentare in Italy. The incidents were disclosed through separate reports that described ransomware-related breaches or victim listings tied to the same actor, with most reports indicating compromises or discoveries clustered within a short period.
Available reporting indicates TheGentlemen operates as a dual-extortion ransomware group, combining file encryption with data theft to pressure victims, and has previously been associated with techniques including T1486 for data encryption for impact. Sector diversity among the reported victims suggests broad targeting rather than a single-industry campaign, spanning finance, accounting, logistics software, manufacturing-related technology, food production, and infrastructure-linked engineering. One report on Gfeller Treuhand said business operations were not disrupted despite the attack, while other notices characterized the events as ransomware-driven data breaches without releasing technical indicators or intrusion details.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
An August 19 report said The Gentlemen attacked Gfeller Treuhand, a fiduciary and real-estate company in Dübendorf, Switzerland. The report stated the company's operational functioning was not affected.
Babcock Africa, associated with babcock.co.za in South Africa, was reported as the victim of a ransomware-related data breach attributed to thegentlemen. The organization was described as an engineering and asset management company.
Roadvision Systems, which operates roadvision.com, was reported as the victim of a ransomware-linked data breach attributed to thegentlemen. The company was described as providing cloud-based trucking management software.
Senvest Capital was identified as the victim of a ransomware attack attributed to thegentlemen. The incident affected the financial services firm associated with senvest.com.
CRASL Accounting Services in Suffolk, UK, was reported as the victim of a ransomware-related data breach attributed to thegentlemen. The affected domain was crasl.co.uk.
Euroscreen, an Italian company operating euroscreen.it, was reported as the victim of a ransomware-linked data breach attributed to thegentlemen. The breach time was listed as 16:32 UTC.
A security notice identified San Carlo Gruppo Alimentare as a target of TheGentlemen ransomware. The visible content provides no further technical or impact details.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcehookphish.com
Open sourcehookphish.com
Open sourcehookphish.com
Open sourcehookphish.com
Open sourcehookphish.com
Open sourcemalware.news
Open sourcemalpedia.caad.fkie.fraunhofer.de
Open sourceorkl.eu
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.