18 Mai

The Gentlemen ransomware gang got breached and the details are wild

A ransomware group that published 332 victims in five months just had its own insides dumped on the internet. The Gentlemen, a Russian RaaS operation that shot to the number two spot among active ransomware groups in early 2026, acknowledged on May 4 that its internal backend database had been compromised. Someone is now selling 16GB of the group’s internal chats, tools, and operational data for $10,000 in Bitcoin.

Check Point Research obtained a 44MB sample of the leak before it was pulled from underground forums. It is a rare full-length look at how a top-tier ransomware operation actually runs.

The admin goes by zeta88 (also known as hastalamuerte). Zeta88 builds the locker malware, runs all infrastructure, manages payouts, and picks targets. According to the leaked chats, they also personally participate in attacks. They came up as an affiliate before running the program, which Check Point says gave them a head start in scaling the operation fast.

The payment split is aggressive: 90% to the attacking crew, 10% to zeta88. That generous cut is what attracted affiliates in bulk. One leaked negotiation screenshot shows a successful payment of $190,000 from an initial anchor demand of $250,000.

The group’s TTPs are opportunistic rather than novel. They favor Fortinet FortiGate VPN appliances and Cisco edge devices as initial access paths. They also use NTLM relay attacks and harvested OWA and M365 credential logs. Check Point found them actively tracking CVEs like CVE-2024-55591, CVE-2025-32433, and CVE-2025-33073. The toolset includes roughly 30 different utilities, from scanners and VPN tools to EDR kill packages and bring-your-own-vulnerable-driver techniques. Check Point calls the toolkit mature, if not particularly unique.

The organizational structure is surprisingly corporate. Zeta88 runs operations with two key operators: qbit handles scanning and persistence, quant specializes in credential-based access. Below them sit seven more people including red teamers, an access broker, and an advertising specialist. Eight distinct affiliate TOX IDs turned up in the ransomware samples, including the admin’s own.

One detail that stands out: the group reused stolen data from a UK software consultancy to attack a company in Turkey. During negotiations, they told the Turkish company the UK firm was the access broker and encouraged them to consider legal action against their own business partner. Dual-pressure extortion at its most cynical.

The leaked chats also reveal the group was experimenting with an in-house LLM-based tool for unspecified malicious purposes. They had already used ChatGPT to help write exploit-related code, according to the conversations.

The breach of The Gentlemen’s backend was likely tied to the compromise of their hosting provider, 4VPS. The group acknowledged the leak on an underground forum, a rare moment of public embarrassment for an operation that relies entirely on its reputation to attract affiliates.

Check Point’s Eli Smadja does not expect the leak to significantly disrupt operations. The group is still active, still listing victims, and still growing. But the reputational damage is real. When your entire business model depends on trust between anonymous criminals, having your internal communications published makes it harder to recruit the next wave of affiliates.

The data also creates complications for past victims. If the leaked internal discussions contradict any public breach disclosures from affected companies, those organizations may need to file amended reports with regulators.

Mots-cles

the gentlemen raas ransomware data leak check point fortinet