TheGentlemen ransomware group was linked to a string of newly reported intrusions affecting organizations in several countries and sectors, including Senvest Capital in financial services, Euroscreen in digital printing and projection technology, CRASL Accounting Services in the UK, Roadvision Systems in transportation software, Babcock Africa in engineering and critical infrastructure support, Gfeller Treuhand in Switzerland, and San Carlo Gruppo Alimentare in Italy. The incidents were disclosed through separate reports that described ransomware-related breaches or victim listings tied to the same actor, with most reports indicating compromises or discoveries clustered within a short period.
Available reporting indicates TheGentlemen operates as a dual-extortion ransomware group, combining file encryption with data theft to pressure victims, and has previously been associated with techniques including T1486 for data encryption for impact. Sector diversity among the reported victims suggests broad targeting rather than a single-industry campaign, spanning finance, accounting, logistics software, manufacturing-related technology, food production, and infrastructure-linked engineering. One report on Gfeller Treuhand said business operations were not disrupted despite the attack, while other notices characterized the events as ransomware-driven data breaches without releasing technical indicators or intrusion details.

TTPs, infrastructure, and targeting history in one profile.
24 events from the most recent confirmed update back to the earliest known activity.
Meridian Logistics Group, a U.S.-based transportation organization operating meridianlogisticgroup.com, was reported as the victim of a ransomware attack attributed to thegentlemen. The report said attackers staged a full network image and recovered ERP exports, a dispatch database, and payroll archives, with final inventory still underway before publication of stolen data.
Eyecare Center of Snohomish, a U.S.-based optometry clinic in Snohomish, Washington, was reported as the victim of a ransomware attack attributed to thegentlemen. The affected domain was eyecarecenterofsnohomish.com, with the breach reported at 08:29 UTC on August 21, 2026, and discovered on August 23, 2026.
Gould Sherwood Consulting, a boutique IT support and services firm in Lexington, Massachusetts, was reported as the victim of a ransomware attack attributed to thegentlemen. The incident summary lists gouldsherwood.com as the affected domain, with the breach reported at 08:31 UTC on August 21, 2026, and discovered on August 23, 2026.
Espac / ESPAC Construcción, a Chile-based manufacturer and distributor serving the building industry, was reported as the victim of a ransomware-linked data breach attributed to thegentlemen. The incident report states the breach occurred at 08:32 UTC on August 21, 2026, and was discovered on August 23, 2026.
Layher Chile, the local branch of the German scaffolding and access systems manufacturer operating layher.cl, was reported as the victim of a ransomware-linked data breach attributed to thegentlemen. The incident report states the breach occurred at 08:34 UTC on August 21, 2026, and was discovered on August 23, 2026.
Volktek, a technology company operating volktek.com and associated with Singapore in the report, was identified as the victim of a ransomware-linked data breach attributed to thegentlemen. The incident report states the breach occurred at 08:35 UTC on August 21, 2026, and was discovered on August 23, 2026.
AGS Cinemas, a multiplex chain and film exhibition company in Chennai, India, was reported as the victim of a ransomware attack attributed to thegentlemen. The incident affected agscinemas.com, with the breach listed at 08:28 UTC on August 21, 2026, and discovery on August 23, 2026.
Magdalena Grand Beach Golf Resort, a luxury hotel and resort in Lowlands, Tobago operating magdalenagrand.com, was reported as the victim of a ransomware-linked data breach attributed to thegentlemen. The breach was listed at 07:50 UTC and discovery at 08:28 UTC on August 21, 2026.
Akatake Engineering, a Japanese manufacturing company based in Numazu, Shizuoka, was reported as the victim of a ransomware-linked data breach attributed to thegentlemen. The affected domain was akatake.co.jp, with the breach reported at 07:55 UTC and discovery at 08:28 UTC on August 21, 2026.
Lexacaucho, a Peruvian manufacturing company in Lima operating lexacaucho.com, was reported as the victim of a ransomware attack attributed to thegentlemen. The incident report states the breach occurred at 07:47 UTC and was discovered at 08:29 UTC on August 21, 2026.
ESCON Group, a veteran-owned electrical contracting company in Bay City, Michigan, was reported as the victim of a ransomware-linked data breach attributed to thegentlemen. The affected domain was escon.us, with the breach reported at 07:56 UTC and discovery at 08:28 UTC.
dlp motive, a German full-service event technology provider operating dlp-motive.de, was reported as the victim of a ransomware attack attributed to thegentlemen. The breach time was listed as 07:43 UTC, with discovery reported at 08:30 UTC.
AWJ Holding was reported as the victim of a ransomware attack attributed to thegentlemen. The Saudi-based investment firm associated with awjholding.com was listed with a breach time of 07:45 UTC.
Geb Sas, a French chemical manufacturing company operating geb.fr, was reported as the victim of a ransomware attack attributed to thegentlemen. The breach time was listed as 08:00 UTC.
Almeer General Contracting Establishment was reported as the victim of a ransomware-linked data breach attributed to thegentlemen. The affected domain was al-meergroup.com, and the breach time was listed as 07:58 UTC.
LOG Systems, a Polish software company based in Wrocław, was reported as the victim of a ransomware-linked data breach attributed to thegentlemen. The affected domain was logsystem.pl, and the breach time was listed as 07:48 UTC.
UOLconsult GmbH, a boutique management consulting firm in Vienna, Austria, was reported as the victim of a ransomware-linked data breach attributed to thegentlemen. The affected domain was uol-consult.com, and the breach time was listed as 07:41 UTC.
An August 19 report said The Gentlemen attacked Gfeller Treuhand, a fiduciary and real-estate company in Dübendorf, Switzerland. The report stated the company's operational functioning was not affected.
Babcock Africa, associated with babcock.co.za in South Africa, was reported as the victim of a ransomware-related data breach attributed to thegentlemen. The organization was described as an engineering and asset management company.
Roadvision Systems, which operates roadvision.com, was reported as the victim of a ransomware-linked data breach attributed to thegentlemen. The company was described as providing cloud-based trucking management software.
Senvest Capital was identified as the victim of a ransomware attack attributed to thegentlemen. The incident affected the financial services firm associated with senvest.com.
CRASL Accounting Services in Suffolk, UK, was reported as the victim of a ransomware-related data breach attributed to thegentlemen. The affected domain was crasl.co.uk.
Euroscreen, an Italian company operating euroscreen.it, was reported as the victim of a ransomware-linked data breach attributed to thegentlemen. The breach time was listed as 16:32 UTC.
A security notice identified San Carlo Gruppo Alimentare as a target of TheGentlemen ransomware. The visible content provides no further technical or impact details.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
26 references tracked. Mallory keeps watching after this page renders.
hookphish.com
Open sourcehookphish.com
Open sourcehookphish.com
Open sourcehookphish.com
Open sourcehookphish.com
Open sourcemalware.news
Open sourcemalpedia.caad.fkie.fraunhofer.de
Open sourceorkl.eu
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.