Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run Scan×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Leaked Chat Logs Expose How The Gentlemen Ransomware Group Operates

The Gentlemen ransomware leak exposes a business-like RaaS operation built on stolen access, specialized affiliates, data theft and managed extortion.
From TheFinanceBase Team6 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A partial backend compromise disclosed on May 4, 2026, gave researchers an unusual view of The Gentlemen, a ransomware-as-a-service (RaaS) operation tracked by Microsoft as Storm-2697. The exposed chats and related records show a criminal enterprise divided among platform administrators, developers, access brokers, affiliates, negotiators and infrastructure staff—not a lone hacker writing an encryption program.

For businesses and individuals, the practical lesson is financial as much as technical: stolen credentials and data can enable payroll fraud, account takeover, extortion and attacks on customers or suppliers even after encrypted files are restored.

What the leak exposed

The group’s administrator acknowledged on underground forums on May 4, 2026, that its backend infrastructure had been compromised, apparently in an incident involving hosting provider 4VPS. Check Point said it obtained only a portion of the material, so no one can assume that every internal record became public.

The material described in reporting includes:

  • Internal chat messages and organizational rosters.
  • Ransom-negotiation transcripts.
  • Discussions of malware, administration panels and other tooling.
  • Information that may help connect infrastructure and cryptocurrency activity.

The value of such a leak is operational. It can reveal how access is purchased, how affiliates are managed, how victims are pressured and where the criminals depend on third parties. Check Point’s account is available at Check Point Research.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Who The Gentlemen are

“The Gentlemen” is a brand used by a RaaS operation. The brand, its core administrators and the people who carry out individual intrusions are not necessarily the same individuals. Microsoft identifies the financially motivated operator behind the service as Storm-2697.

Microsoft says the operation emerged around mid-2025 and began recruiting affiliates in September 2025. Affiliates conduct intrusions using a platform maintained by the core group, while access brokers can supply stolen credentials or an existing foothold. Microsoft observed activity against education, transportation, healthcare and financial organizations in North America, South America, Europe, Africa and Asia.

Ransomnews, summarizing KELA analysis, described roughly nine recurring core handles, including an apparent administrator and an initial-access-broker role. Those are analyst assessments of pseudonyms, not verified legal identities. A June 13, 2026 Ransomnews count recorded 483 organizations on a victim list; earlier Check Point reporting cited more than 320 victims overall and 240 in 2026. The totals use different dates and counting methods and should not be added together or treated as confirmed intrusions.

A criminal business with specialized jobs

The communications depict a structure resembling a small technology company in its division of labor, although the activity is criminal and the identities remain uncertain.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Apparent role Function
Administrator or platform owner Runs the RaaS operation, manages relationships and oversees the service.
Malware and tooling developers Maintain encryptors, panels and utilities used during intrusions.
Infrastructure staff Operate servers, communication systems and deployment infrastructure.
Access brokers Offer stolen usernames, passwords, browser sessions or network footholds.
Affiliates and intrusion operators Enter target networks, escalate privileges, steal data and deploy the encryptor.
Negotiators and leak-site personnel Contact victims, set deadlines, manage publication threats and handle publicity.

The earlier Conti leak showed a similar pattern. Academic researchers analyzed 168,740 Conti Jabber messages and found specialized departments and concentrated leadership. That continuity matters: dismantling one malware family does not remove the access sellers, negotiators, infrastructure providers or laundering channels that support the wider ecosystem.

Access usually comes before encryption

The exposed material and related investigations point to several entry routes rather than one universal playbook:

  • Username and password databases taken by infostealer malware.
  • Stolen browser session cookies that can bypass a password challenge until the session is revoked.
  • Exploitation of internet-facing vulnerabilities.
  • Compromised email or Outlook Web Access accounts.
  • Phishing, trusted-account abuse and weaknesses in Active Directory.
  • Initial-access brokers selling an already-established foothold to an affiliate.

Ransomnews reported substantial reliance on infostealer-derived credentials and session cookies, but its cross-check of named victims was a limited sample and does not show that every victim entered through that route. Check Point observed Active Directory enumeration, NTLM relay, browser-session harvesting, use of legitimate administration tools, attempts to disable endpoint security, data exfiltration and domain-wide deployment. These are observed behaviors, not a checklist used in every case.

For consumers and finance teams, this makes identity protection central. A stolen session can expose webmail, payroll portals, cloud drives or banking-related correspondence without the attacker first breaking encryption.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

AI accelerated development, not autonomous attacks

Check Point reported that the administrator built the RaaS administration panel in three days with AI-assisted coding and that operators discussed models including DeepSeek and Qwen. The chats also indicate interest in using AI to analyze stolen material or help produce content.

The evidence supports AI-assisted development and analysis. It does not establish that an AI system independently selected victims, conducted intrusions or negotiated ransoms without human direction. The operation still depended on people who obtained access, made judgments, maintained infrastructure and pressured victims.

How the attack chain works

Microsoft’s analysis describes a Go-written encryptor using per-file ephemeral Curve25519 keys with XChaCha20. The program is designed to spread after privileged access is obtained and can combine several lateral-movement and defense-evasion behaviors. Microsoft reports use of scheduled tasks for SYSTEM-level execution, PsExec-based propagation, network enumeration, attempts to weaken endpoint defenses and deletion of recovery or forensic artifacts.

At a high level, the observed workflow is:

  1. Acquire credentials, browser sessions or a perimeter foothold.
  2. Establish persistence and obtain higher privileges.
  3. Map users, computers, shares and domain relationships.
  4. Suppress or evade endpoint monitoring.
  5. Move across the environment.
  6. Copy sensitive data outside the organization.
  7. Encrypt systems and disrupt recovery.
  8. Negotiate while threatening to publish the stolen information.

Microsoft’s technical report contains detections, hunting advice and indicators without requiring readers to reproduce attack commands: Microsoft Threat Intelligence.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Extortion is a managed business process

The chats show negotiation as an organized function rather than an improvised exchange. Double extortion combines file encryption with publication threats. Operators can tailor pressure using employee records, customer information, contracts or other sensitive documents.

Check Point described a case in which data taken from one victim was allegedly used to pressure a client of that victim, a pattern it called chain victimization. That report concerns a specific case, not every ransomware incident. It illustrates why notifying customers, suppliers and financial partners may be necessary even when an organization’s own files are restored.

Decryption therefore does not end the risk. Stolen credentials, copied data, scheduled tasks or remote-access tools can support renewed intrusion, fraud or a second extortion demand.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What Conti and Black Basta leaks add

Leak What it revealed Distinctive lesson
Conti, 2022 Tens of thousands of messages, later source-code material and evidence of specialized roles and leadership patterns. Ransomware crews can organize communications, staffing and work schedules in a corporate-like way.
Black Basta, February 11, 2025 Internal chats, cryptocurrency addresses and links to other actors. Blockchain analysis can connect conversations to ransom payments and cash-out relationships.
The Gentlemen, 2026 Partial backend data, role discussions, negotiation records, access references and AI-assisted development. RaaS scaling increasingly combines infostealer access, session theft, specialized affiliates and rapid tooling development.

Conti reporting is available from Security Magazine, while KELA’s intelligence report is at KELA. Elliptic’s analysis of the Black Basta leak explains the financial-tracing angle at Elliptic.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What organizations should do

  1. Contain carefully. Isolate affected systems using an incident-response plan while preserving evidence.
  2. Re-secure identity first. Reset privileged passwords, revoke sessions and refresh tokens, rotate service-account secrets, and review new MFA registrations and authentication methods.
  3. Hunt for control abuse. Examine PowerShell, remote administration, PsExec, WMI, scheduled-task creation, unusual Group Policy changes and endpoint-security tampering.
  4. Investigate theft separately. Look for archive creation, large outbound transfers, cloud-storage activity and access to email, browser stores or sensitive repositories.
  5. Preserve records. Retain memory and disk images where feasible, plus firewall, VPN, identity, endpoint and cloud logs, ransom notes and attacker messages.
  6. Coordinate externally. Involve incident-response counsel, law enforcement, insurers and regulators as appropriate, and assess notification duties to customers and partners.
  7. Test recovery. Backups should be isolated and restorable; restoration alone is unsafe if credentials or persistence remain.

Microsoft’s human-operated ransomware guidance recommends identity monitoring, credential hygiene, tamper protection, controlled folder access, EDR in block mode, attack-surface-reduction rules and automated investigation: Microsoft Learn.

Do not assume that paying guarantees deletion of stolen data, confidentiality or a working decryptor. Payment decisions require legal, regulatory, insurance and law-enforcement advice.

What the leak cannot prove

  • A handle is not a verified legal identity, and a handle may be shared, sold or impersonated.
  • A chat discussion does not prove that a technique succeeded or that a named victim was compromised.
  • Leak-site totals can include duplicates, inflated claims or organizations listed after negotiations changed.
  • A cryptocurrency address may not belong exclusively to one actor.
  • The partial dataset may omit important personnel, transactions or conversations.
  • The leak does not show that AI autonomously conducted attacks or that The Gentlemen collapsed.

Reporting indicates that victim listings continued after the exposure, suggesting that a leak can force rebranding or infrastructure changes without eliminating the underlying criminal network. The central defensive conclusion is therefore practical: protect identities and sessions, harden Active Directory and remote administration, preserve endpoint visibility, isolate backups and treat customers and suppliers as part of the attack surface.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.