← Sample products

RPT-2026-07 · Ransomware

What ten months of leak-site data say about The Gentlemen's operational tempo

2026-07 · Díaz, R.

Ransomware coverage runs on headlines, and headlines are events: a new group, a big victim, an arrest. But an extortion operation is not an event. It is a publishing business with a cadence. This piece looks at The Gentlemen, one of the fastest-growing ransomware brands of the past year, through the least glamorous lens available: every victim post on its leak site, counted week by week, for ten months. The result is a tempo chart. And halfway through it, the group’s own backend leaked, which lets us check how much of the operation that public tempo actually captures.

Why this group

The Gentlemen only surfaced in September 2025, yet its growth curve outpaced almost everything else on the extortion scene. The engine is no mystery: a 90% affiliate revenue share, tying the highest rate on record. Money attracts affiliates; affiliates produce victims; victims produce posts. Which makes the leak site itself a decent instrument panel for the operation’s health, provided you read it as a time series instead of a news feed.

Data and method

Everything here comes from public sources. The dataset is the group’s victim posts as captured by ransomware.live, an open tracker that monitors leak sites and archives each claim: 618 posts between September 9, 2025 and July 16, 2026, spanning 79 countries.

A few honesty notes about what this data can and cannot say:

  • The primary timestamp is when the tracker first observed each post, a proxy for publication rather than for the intrusion itself. Trackers onboard groups late and re-crawl, so the earliest weeks partly reflect backfill.
  • Cross-checking against claimed attack dates reproduces the figures in public reporting (June 2026 as the peak month at 117 claimed victims, matching SOCRadar’s tally), and the findings below hold on both timestamp bases.
  • A leak site is a floor, not a census: it lists victims the group chose to pressure publicly. More on how wrong the floor is later; the group’s own data settled that question.
  • The final partial week is excluded from the chart. Analysis was done with a short Python script over the tracker’s public API.

The tempo

Weekly victim posts on The Gentlemen leak site, September 2025 to July 2026. A dashed line marks the May 4 backend leak; the biggest week on record, 50 posts, is the week of the leak itself.

Three phases show up clearly:

  1. Launch and lull (Sep–Dec 2025). A 38-post opening month (a brand announcing itself), then a quiet quarter: 10, 19 and 13 posts in October, November and December. This is the pattern of an operation still recruiting.
  2. The inflection (Jan–Feb 2026). 47 posts in January, then 89 in February, a near-doubling that public reporting attributes to the affiliate program hitting critical mass. Tempo never returned to 2025 levels.
  3. Sustained pressure (Mar 2026 onward). 50 to 90 posts a month through spring, and July 2026 tracking as the fastest month yet: 100 posts in the first 16 days, a pace of roughly 44 per week.

The cadence has a workweek shape: 44% of all posts land on Tuesday or Wednesday, with Friday the quietest day (52 posts in ten months). Extortion sites are staffed like newsrooms: publication is a scheduled activity aimed at maximum attention, not a side effect of intrusions.

Geographically, the spread is unusual. The United States accounts for only 16% of victims (98), with Thailand second (37), then France (33) and Germany (31), a far flatter distribution than the US-heavy pattern typical of large RaaS brands. By sector, Manufacturing leads (108 posts, roughly 17%), followed by Business Services (74), Technology (68) and Healthcare (54).

The backend leak, and what the tempo did next

On May 4, 2026, The Gentlemen’s administrator acknowledged that an internal database (infrastructure, affiliates, victims) had leaked. Check Point Research, with access to the leaked backend, counted more than 1,570 likely corporate victims at a time when the public leak site showed roughly 483. SOCRadar framed it as the hunter becoming the hunted, and a month later Krebs on Security tied the operator aliases “hastalamuerte” and “Zeta88” to a named individual in Izhevsk, Russia.

You might expect an operation to go quiet after its own breach. The tempo data says the opposite:

  • The week of May 4 is the single biggest posting week in the group’s history: 50 victims.
  • Two days after the admission, on May 6, the site published 40 victims in one day, nearly a single-day record. And these were fresh claims (median three days old), not a re-dump of old material.
  • Average tempo rose after the leak: from roughly 17 to 19 posts per week in the three months before, to 20 to 22 in the two months after, depending on the timestamp basis. July then set a new record pace.

Read as signaling, the message of that 40-post day is hard to miss: the leak changed nothing; affiliates, keep working. Whether that bravado survives the attribution pressure that followed is a different question, but as of mid-July 2026 the publishing business is operating at full speed.

What this is actually useful for

  1. Count the floor, remember it’s a floor. The one moment we got ground truth, the public site was showing roughly a third of the backend’s victim count. Any metric built on leak-site data, including this piece, systematically understates the real operation.
  2. Tempo beats headlines as a health metric. The February inflection was visible in the weekly series weeks before it was a story, and the post-breach acceleration contradicted the “hunter hacked” narrative in near real time. A weekly count is a cheap indicator any CTI team can maintain.
  3. Publishing behavior is deliberate behavior. Midweek scheduling, burst-dumps as signaling, countdown management: the leak site is a communications channel the group operates strategically, and it rewards being read that way.
  4. Check your targeting assumptions. A footprint that is 16% US, spans 79 countries and skews to manufacturing fits the affiliate-economics story (take whatever access is for sale) better than any narrative about chosen sectors. If your threat model assumes “they target companies like ours,” the data disagrees.

Written from public sources only: ransomware.live’s open dataset and the published research linked above. Nothing here draws on my employer’s data or casework. Figures as of July 16, 2026.

Sources: ransomware.live · Check Point Research · Check Point blog · SOCRadar dark web profile · SOCRadar leak analysis · Unit 42 · Krebs attribution recap