Cybersecurity Threat Landscape

The Gentlemen: Inside the New No. 1 Hacker Group

Hacker, The Gentlemen ransomware, The Gentlemen ransomware group explained, how attackers exploit FortiGate vulnerabilities, The Gentlemen ransomware attack tactics, new top ransomware group 2026, The Gentlemen hacker, Ransomware, The Gentlemen, Cyber crime
Facebook
X
LinkedIn
Reddit
WhatsApp

A ransomware group that did not even exist a year ago has quickly climbed to the top of the global threat landscape. At the same time, cyberattacks targeting German companies are increasing significantly.

Named The Gentlemen, the group became the world’s most active ransomware operation in June 2026, according to Check Point. With 17 percent of all publicly reported ransomware attacks attributed to the group, it overtook former leader Qilin, which accounted for 11 percent.

Ad

The group was founded in mid-2025 by a Russian-speaking threat actor who had previously worked as an affiliate for Qilin and LockBit. Operating under a Ransomware-as-a-Service (RaaS) model, The Gentlemen provides attackers with malware and infrastructure in exchange for a share of ransom payments.

The group also operates as an access broker, providing affiliates with access to around 14,000 already compromised FortiGate devices. This capability may be a key factor behind the group listing more than 320 victims within just a few months.

Patrick Fetter from Check Point summarizes the development:

Ad

“This once again demonstrates how quickly new actors can establish themselves in this underground economy.”

Double extortion fuels rapid growth

The Gentlemen gained attention primarily through its double-extortion strategy. The group not only encrypts victims’ systems but also threatens to publish stolen data if the ransom demand is not met.

The attackers primarily target larger organizations with valuable and sensitive data assets. Their reputation as an especially aggressive threat actor is driven by the speed at which they have accumulated victims, publicly listed hundreds of targets, and gained access to pre-prepared entry points into compromised networks.

The group’s victim list now includes several hundred organizations across more than 60 countries and over 20 industries, with a focus on manufacturing, healthcare, and financial services. Named victims include Chinese industrial supplier Dongguan HYX Industrial, financial services provider Rogers Capital, and Warka Bank for Investment and Finance.

In another case, the group claimed responsibility for stealing 1.5 terabytes of data from a company called Solumek.

FortiGate vulnerabilities provide the gateway

From a technical perspective, The Gentlemen rarely relies on traditional phishing campaigns. Instead, the group specifically targets internet-facing network devices, particularly Fortinet FortiGate firewalls. Through a known FortiOS vulnerability, affiliates gain initial access, often using their own databases of previously compromised or brute-force-cracked VPN credentials.

Attackers then spend days exploring the Active Directory environment, disabling security tools, and extracting data before deploying encryption across the entire network through Group Policy. The ransomware itself operates across multiple platforms, including Windows, Linux, and ESXi environments. It uses the XChaCha20 and Curve25519 encryption algorithms and can operate in a worm-like mode, allowing it to independently spread to additional systems within the network.

Profile: The Gentlemen

FoundedMid-2025
FounderRussian-speaking threat actor, previously an affiliate for Qilin and LockBit
Operating ModelRansomware-as-a-Service (RaaS) and access broker
Attack methodData encryption combined with extortion through threats to publish stolen information
AccessAround 14,000 compromised FortiGate devices
Known victimsMore than 320 publicly listed victims
Share of ransomware attacks in June 202617 percent, ranking first worldwide

Top ransomware groups account for 35 percent of attacks

LockBit ranked third in June, increasing its share from one percent in May to seven percent. Together, the three largest ransomware groups accounted for 35 percent of all recorded attacks. Overall, Check Point identified 646 publicly disclosed ransomware incidents in June, representing a 33 percent increase compared with the previous year. The figures are based on data collected from ransomware groups’ leak sites.

Business services represented the largest share of affected organizations with 31 percent of all victims, followed by consumer goods and services as well as industrial manufacturing. North America recorded the highest regional share with 44 percent of attacks. The Asia Pacific region (APAC) overtook Europe for the first time, accounting for 23 percent compared with Europe’s 22 percent.

German companies face growing cyberattack pressure

German organizations recorded an average of 1,659 cyberattacks per week in June, according to Check Point. This represents a 35 percent increase compared with the previous year and a 21 percent rise compared with May. The figures are “alarming,” Fetter said when commenting on the German trend. While Germany remains below the European average of 2,003 attacks per week, the country’s growth rate is significantly above average.

Austria recorded 2,243 attacks per week, an increase of 37 percent. Switzerland experienced the strongest increase within the DACH region, rising by 44 percent.

Globally, organizations faced an average of 2,270 attacks per week, 10 percent more than in May and 17 percent higher than the previous year. The increase affected almost all regions and industries. Education remained the most targeted sector worldwide, with 4,816 attacks per week, followed by government organizations and telecommunications.

Significant increases were also recorded among non-profit organizations, energy providers, and agricultural companies.

In Germany, energy and education continued to rank as the most affected sectors. Software and telecommunications were newly added to the ranking.

Enterprise GenAI adoption remains a security risk

Every 26th GenAI prompt carried a high risk of exposing sensitive data in June, corresponding to an exposure rate of 3.9 percent. According to Check Point, 85 percent of organizations regularly using GenAI were affected. Another 27 percent of prompts contained potentially sensitive information.

The highest risk was identified in healthcare, with an exposure rate of 5.7 percent, followed by telecommunications and business services, each at 5.1 percent. Personal data accounted for the largest share of exposed content, representing 80 percent of all leaked information.

However, companies are not defenseless against these risks, Fetter emphasizes. A preventive, AI-powered security approach can help detect and neutralize even unknown attacks before they cause significant damage.

(lb)

Ad

Weitere Artikel