The Gentlemen ransomware: How attackers steal your data and lock you out

683 victims, a 24-hour clock, and no novel malware needed. Sophos maps The Gentlemen's playbook.

Contributed Content

the gentlemen ransomware crew sophos
Sophos published research this week on The Gentlemen, a RaaS operation that only launched in mid-2025. Image generated with our TN:AI workflow for illustration purposes.

Topics: 

Topics: 

Sharing is caring! 

683 victims, one playbook

Sophos’s Counter Threat Unit (CTU) published a detailed breakdown of The Gentlemen, a ransomware-as-a-service (RaaS) operation that went from launch to 683 named victims in roughly a year[1].

The research is based on 15 separate intrusions and maps out a repeatable affiliate method that gets from initial access to full encryption in as little as 24 hours. Yes, really.

The operation is run by a threat group CTU tracks as GOLD SHERWOOD. It launched in mid-2025 on a double-extortion model, meaning affiliates steal data before encrypting files, then threaten to publish what they took if the victim refuses to pay.

By the end of July 2026, 169 of those 683 victim names appeared in that month alone.

How the clock runs

The CTU analysis of 15 intrusions found that some affiliates deployed ransomware in under 24 hours of the first observed post-compromise activity. The median time to deployment was about two days.

That pace is not explained by sophisticated malware. It comes from a well-drilled sequence that affiliates run through systematically.

First, access. Affiliates get in through exposed or weakly protected remote access services, using compromised credentials. In one February intrusion CTU described, an attacker authenticated to a Fortinet SSL VPN using stolen user credentials, with no multi-factor authentication in place.

Within an hour, additional VPN sessions appeared from foreign IP addresses.

From there, the affiliate escalates privileges using native Windows utilities, stages tools in trusted system directories such as C:\PerfLogs, and begins pulling data out.

Steal first, encrypt later

Data exfiltration happens before encryption. CTU observed affiliates using Rclone, Restic and MinIO Client to move data out, switching between tools depending on transfer performance and data volume.

Once the data is out, the affiliates work through a defence-dismantling phase before the ransomware ever runs. Sophos recorded more than 200 variations of backup service disruption commands across the 15 intrusions, targeting services including Veeam, SQL Writer and Backup Exec components.

At the same time, endpoint detection and response (EDR) tools get killed using utilities that abuse vulnerable drivers, Windows Defender exclusions get set through PowerShell, and logs get cleared to complicate incident response.

Only then does the ransomware deploy.

What that means for your organisation

The victimology across the 683 named targets spans a wide range of sectors, which the Sophos report describes as consistent with opportunistic targeting. Affiliates are not hunting specific industries. They are hunting available access.

The practical implication is direct: an exposed VPN service without multi-factor authentication is not a minor configuration gap. In the 15 intrusions CTU analysed, it was the front door.

Sophos recommends organisations prioritise hardening remote access services, enforcing multi-factor authentication, monitoring administrative activity, and watching for anomalous use of data exfiltration tools and unusual execution from staging directories such as C:\PerfLogs.

Sources:
[1] Sophos Counter Threat Unit. “Ungentlemanly behavior: Insights into a ransomware operation.” Sophos, Sept. 1, 2026.

Before you @ us:

No, AI did not “write this article.” Calm down. This piece was produced using our TN:AI newsroom workflow. The opinions and typos belong to a human who has algorithmic side quests. (Hi!) We even wrote an AI policy so nobody panics.

🧠 AI-assisted research + summarisation 📝 Human edited + fact-checked

Sharing is caring! 

Featured reads: