The Gentlemen is a ransomware operation that Trend Micro first documented in August 2025, when it found victims in 17 countries, led by Thailand and the United States. Palo Alto Networks' Unit 42 says the group, which Microsoft tracks as Storm-2697, worked as a Qilin affiliate before becoming a ransomware-as-a-service around September 2025, offering affiliates an unusually high 90% of ransoms. Researchers say it gains access through exposed edge devices such as Fortinet FortiGate firewalls, stolen credentials and access brokers, then steals data before encrypting Windows, Linux and ESXi systems. Manufacturing is its most-hit sector. SOCRadar, cited by The Hacker News, lists India among its most-targeted countries.
LatestComparitech counted 107 attacks by The Gentlemen in August 2026, second only to Qilin's 157. On 9 September 2026 Veradigm disclosed a patient data breach after the group listed it on 5 September; Veradigm did not name the attacker.
Timeline
Unit 42 says the group turned from a private operation into a ransomware-as-a-service on or about September 2025, offering affiliates a 90% payout.
Trend Micro published the first analysis of The Gentlemen, describing an August 2025 campaign that likely began through an internet-exposed FortiGate server and hit victims in 17 countries.
Check Point Research analysed a leak of the group's internal database, estimating about 332 published victims in the first five months of 2026 and ranking it the second most productive RaaS.
Check Point Research — Thus spoke… The Gentlemen (13 May 2026)
The Hacker News reported 478 claimed victims per Ransomware.live and Microsoft's finding that an optional flag lets the encryptor spread itself across a network.
The Hacker News — The Gentlemen ransomware claims 478 victims, can spread like a worm (11 Jun 2026)
Unit 42 counted 580 claimed victims in 77 countries through 7 July 2026, with a peak of 117 in June 2026.
AnMed, which runs hospitals in South Carolina and Georgia, was hit by a cyberattack; The Gentlemen later claimed it and posted on AnMed's Facebook page, which AnMed called unauthorised.
Nutex Health told the SEC that patient, employee and financial data were stolen in an August incident; The Gentlemen listed Nutex on its leak site, though Nutex did not name the attacker.
Veradigm disclosed a patient data breach via a third-party vendor after The Gentlemen claimed it on 5 September; Veradigm did not name the group.
Who is exposed, and what holds
Who is exposed
- Manufacturers, the sector Unit 42 and Trend Micro found most often hit
- Organisations with internet-facing FortiGate or other edge devices left unpatched or using weak credentials
- Healthcare providers and their vendors, several of which disclosed breaches in 2026 after the group claimed them
Recommended controls
- Patch and restrict management access on firewalls and VPNs, and rotate their credentials
- Enforce MFA on remote access and watch for new domain admin accounts or Group Policy changes
- Keep offline, tested backups of servers and ESXi hosts
Sources
- Trend Micro — Unmasking The Gentlemen ransomware: tactics, techniques, and procedures revealed (9 Sep 2025)
- Palo Alto Networks Unit 42 — No manners here: the ruthless rise of The Gentlemen ransomware (10 Jul 2026)
- Check Point Research — Thus spoke… The Gentlemen (13 May 2026)
- Comparitech — Ransomware roundup: August 2026 (8 Sep 2026)