The Gentlemen
The Gentlemen is a double-extortion-as-a-service operation that has been publicly observed since mid-2025. It operates a leak site and uses an encryption program written in Go to target various platforms; claims per victim require independent verification.
- Incidents
- 6
- High impact
- 0
- First seen
- Aug 2, 2025
- Latest seen
- May 28, 2026
Linked incidents
TheGentlemen Claims Responsibility for Ransomware Attack on Corporación Prokompra
The ransomware group TheGentlemen published information on the Venezuelan retailer Corporación Prokompra 2020, C.A. (based in Caracas) on its leak site on May 28, 2026. The attackers threatened to release sensitive data they claimed to have exfiltrated unless the company contacted them to negotiate. The listing was documented by the Ransomware.live tracker and replicated by several monitoring services, although the company has not publicly confirmed the incident, and neither the volume nor the type of data was specified.
The Gentlemen reports an attack against C.H. Express C.A.
In March 2026, the Venezuelan logistics and light freight company C.H. Express C.A. was targeted by a ransomware attack carried out by the threat group The Gentlemen. The group publicly claimed responsibility for the attack on March 26, 2026, and threatened to leak confidential data if negotiations were not initiated. The exact date of the initial network compromise and whether any data was actually leaked remains unclear.
The Gentlemen Denounce Attack on the Anzoátegui Specialty Center, C.A. (CEACA)
On March 16, 2026, the ransomware group “The Gentlemen” claimed responsibility for a cyberattack against the Centro de Especialidades Anzoátegui, C.A. (CEACA), a Venezuelan healthcare provider. The threat actor listed the organization on its data leak site with a countdown timer, threatening to publish confidential healthcare data unless negotiations began. It has not yet been verified whether any data was actually compromised or whether the incident caused any material or operational disruptions.
The Gentlemen Claims Responsibility for Attack on Industrias Iberia C.A.
In February 2026, the ransomware group “The Gentlemen” claimed to have attacked Industrias Iberia C.A., a Venezuelan food manufacturer. The threat actor disclosed the incident on February 24, 2026, but it is still unclear whether any data was leaked or if there was any material loss.
The Gentlemen Files Complaint Against Oriental de Seguros, C.A.
In September 2025, the ransomware group known as The Gentlemen claimed responsibility for a cyberattack against Oriental de Seguros, C.A., a Venezuelan insurance company. The incident was disclosed by the threat actor on September 9, 2025. While evidence indicates that the company’s website became inaccessible and a post detailing the company’s profile was published on a leak site, it is unclear whether any data was actually exfiltrated or whether the organization suffered any financial losses.
The Gentlemen Files Lawsuit Against Reaseguradora Internacional de Venezuela, C.A. (Venezuela Re)
On September 9, 2025, the ransomware group “The Gentlemen” claimed responsibility for a cyberattack against Reaseguradora Internacional de Venezuela, C.A. (Venezuela Re). The threat actor’s leak site also mentioned Banco Activo alongside Venezuela Re. It is still unclear whether any data was actually leaked or whether the organization suffered financial losses as a result of the incident.