The Gentlemen Hit 18 Companies in 24 Hours, Now the Second Busiest Ransomware Crew
The Gentlemen, a ransomware crew spun out of a Qilin payment dispute, has scaled to record volumes. On July 10 it claimed 18 fresh victims in a single day, outpacing even Qilin.
The ransomware group The Gentlemen added 18 companies to its leak site in 24 hours on July 10, 2026, most of them in IT, software and construction. It was the crew's biggest single-day haul. According to ransomware activity trackers, The Gentlemen ran ahead of its rivals through the first half of July: 11 victims on July 1, 20 on July 6 and 18 on July 10. Qilin, by comparison, claimed 7 to 9 victims on the same days.
Who The Gentlemen are
The group launched as a Ransomware-as-a-Service operation in September 2025. Researchers believe its operators previously worked as Qilin affiliates and broke away after a dispute over payments. The crew runs around 20 people, and Microsoft tracks it as Storm-2697.
In under a year of independent operation, The Gentlemen has claimed 580 victims across 77 countries as of July 7, 2026, making it the second most active RaaS program of the year behind Qilin. The trajectory is steep: the group claimed 117 victims in June, four times its January figure.
The growth comes down to economics. The Gentlemen hands affiliates 90 percent of each ransom, against the 70 to 80 percent that is standard on the market. In May the group struck a partnership with the BreachForums marketplace and opened recruitment to affiliates, penetration testers and initial access brokers.
How they break in
The group gets its initial foothold mainly through vulnerable edge devices: Fortinet FortiGate VPN gateways and Cisco appliances. Its toolkit includes exploits for unpatched systems, among them CVE-2024-55591 (FortiOS), CVE-2025-32433 (SSH in Erlang/OTP) and CVE-2025-33073 (the Windows SMB client). It also relies on RDP password brute-forcing, stolen credentials and access bought from brokers.
The signature tool: GentleKiller
What sets The Gentlemen apart from other crews is their own infrastructure for switching off security software, which the operators sell to affiliates under the name GentleKiller. It is a set of at least eight BYOVD variants (attacks that abuse legitimate but vulnerable drivers), able to terminate more than 400 security processes from 48 vendors. For privilege escalation the group exploits a flaw in the ThrottleStop.sys driver (CVE-2025-7771).
The encryptor itself is written in C and Go, which lets the group deploy it on Windows and inside virtual environments alike. To spread across a network, the crew exploits SMB and gains SSH access to VMware ESXi hosts.
The scale, seen from inside
In May 2026 an insider leaked the group's internal database. The dump exposed the operation's back office: 3,366 internal chat messages, operator identities, ransom negotiations and a victim list naming more than 1,570 organizations. That is well above what the group publishes on its leak site, and it gives a sense of the real reach of the operation.
The Gentlemen's main targets are manufacturing (its largest category), construction, healthcare and insurance. In July the geography shifted toward France, the United States, Japan, Taiwan and China.
Based on research by Palo Alto Unit 42, Trend Micro and Microsoft.
Written by
Read next
$643M in Six Months: How Lazarus Operates and Where the Evidence Runs Out
In the first half of 2026, analysts at TRM Labs attributed roughly $643 million to groups linked to North Korea, about 66% of everything stolen from the cryptocurrency industry, out of some $972 million lost across 207 incidents. Almost all of it came from two April attacks on DeFi protocols: the roughly $292 million breach of KelpDAO and the $285 million hit on Drift Protocol. A year earlier the shape was similar but the scale was not. Chainalysis put 2024 losses to DPRK-linked hackers at $1.34
Microsoft Patches a Record 570 Flaws, Two Zero-Days Already Under Attack
On Tuesday, July 14, Microsoft shipped the largest set of fixes in Patch Tuesday history, closing 570 vulnerabilities at once. Attackers are already exploiting two of them in the wild, and a third was publicly disclosed before the patch landed. The most serious of the exploited bugs is CVE-2026-56164 in Microsoft SharePoint Server. A missing authentication check in a critical function lets an unauthenticated attacker escalate privileges across the network, with no password at all. Researchers a
LegacyHive: Unpatched Windows Zero-Day PoC Dropped Hours After Patch Tuesday
Within hours of July's Patch Tuesday, a researcher going by Nightmare Eclipse (also seen as Chaotic Eclipse) published a proof-of-concept exploit for a new Windows vulnerability dubbed LegacyHive. No patch existed at the time of release, and the exploit works on the latest build of the system, assembled with July's updates already applied. The vulnerability lives in the Windows User Profile Service (ProfSvc) and its registry hive loading mechanism. When a user signs in, Windows mounts the UsrCl