Listen to this Post

A New Warning From the Dark Web
The ransomware landscape is becoming increasingly aggressive, and the latest activity attributed to The Gentlemen ransomware group offers another reminder that no industry should assume it is too specialized, too technical, or too small to attract cybercriminal attention.
On July 31, 2026, threat intelligence monitoring attributed two new victim listings to The Gentlemen. The organizations named in the reports are Additive Manufacturing and Orsima. The claims were reported through activity monitored by the ThreatMon Threat Intelligence Team, which tracks ransomware and dark web activity.
At this stage, the reports should be treated as ransomware claims rather than independently confirmed breaches. A listing on a ransomware leak site or a threat-intelligence alert does not, by itself, prove that an organization was successfully compromised, that data was stolen, or that the attacker possesses the volume of information being claimed.
That distinction matters. Ransomware groups have a financial incentive to exaggerate or manipulate victim listings, while organizations may delay public confirmation while conducting forensic investigations, assessing legal obligations, and determining whether sensitive information was actually accessed.
Nevertheless, the appearance of two additional names is significant because The Gentlemen has already demonstrated an unusually rapid expansion across industries and geographic regions.
The Two Latest Victim Claims
According to the information supplied in the ThreatMon alert, Additive Manufacturing was listed as a victim at approximately 21:30 UTC+3 on July 31, 2026.
Only a few minutes earlier, at approximately 21:25 UTC+3, Orsima was also reported as having been added to the group’s victim list.
The short interval between the two reported additions is noteworthy. It may indicate that the group was updating its leak infrastructure in batches, publishing several victims during the same operational window, or simply that ThreatMon detected multiple changes close together.
However, the timestamps alone cannot establish when either intrusion actually occurred.
Why Additive Manufacturing Is an Important Target
The reference to Additive Manufacturing is particularly interesting because advanced manufacturing organizations can possess valuable intellectual property, engineering documentation, production designs, supplier information, customer records, and proprietary research.
For an attacker, such information can potentially have value beyond the immediate ransom demand.
Manufacturing companies increasingly depend on interconnected environments that combine traditional enterprise IT with engineering systems, production networks, cloud platforms, remote access technologies, third-party suppliers, and specialized industrial software.
That complexity creates opportunities for attackers.
The more interconnected the organization becomes, the more pathways may exist between an initial compromise and the systems that contain commercially valuable information.
The Hidden Value of Manufacturing Data
Ransomware is often described as a simple encryption problem, but modern extortion campaigns are increasingly focused on information.
Engineering drawings, product specifications, CAD files, production schedules, supplier contracts, customer lists, research documents, and internal communications can all become bargaining chips.
A company may be able to restore its systems from backups, but that does not automatically solve the problem if attackers have already copied confidential information.
This is why modern ransomware has evolved toward double extortion, where criminals combine encryption with data theft and threaten to publish the stolen information.
Microsoft has documented The Gentlemen as a ransomware-as-a-service operation using double-extortion tactics. Its research also describes the malware as capable of aggressive self-propagation and rapid lateral movement once attackers gain access to an environment.
Who Are The Gentlemen?
The Gentlemen is not an old ransomware brand that suddenly became famous. It emerged relatively recently and expanded extraordinarily quickly.
Microsoft describes the operation as a Ransomware-as-a-Service platform that emerged around mid-2025 and expanded into an affiliate model in September 2025. The company tracks the operators behind the platform as Storm-2697.
The RaaS model is one of the most important developments in modern cybercrime.
Instead of requiring a small group of criminals to perform every stage of an attack, the operators can provide infrastructure, malware, negotiation systems, leak-site capabilities, and other services while affiliates conduct individual intrusions.
That dramatically increases the number of potential attackers using the same ransomware ecosystem.
The Affiliate Model Changes the Threat
The
An experienced ransomware developer can build the platform once, while multiple affiliates independently search for vulnerable organizations.
This creates an industrialized cybercrime model.
The operators do not necessarily need to personally compromise every victim. Their platform can function more like a criminal business ecosystem in which different participants specialize in access, intrusion, deployment, negotiation, data theft, or infrastructure.
Research published earlier this year indicated that The Gentlemen had already become one of the most active ransomware operations by victim count. Check Point reported more than 400 publicly listed victims and described the group as one of the world’s most active ransomware operations in 2026.
The
The speed of the
Earlier reporting showed that The Gentlemen had accumulated hundreds of claimed victims in a relatively short period. Ransomnews reported 483 claimed victims by June, including 380 attributed to activity during 2026.
Other security researchers have also highlighted the
The result is a ransomware operation that cannot be dismissed as a temporary or isolated criminal campaign.
Its infrastructure, affiliates, malware, and operational knowledge have created a scalable threat.
A Technical Threat, Not Just a Leak Site
The
Microsoft’s analysis found that the malware is written in Go and uses obfuscation while combining encryption with several mechanisms for lateral movement.
The ransomware uses per-file ephemeral Curve25519 keys together with XChaCha20 encryption, while attempting to move through compromised networks using multiple techniques simultaneously.
This matters because rapid lateral movement can reduce the amount of time defenders have to isolate compromised machines.
An attacker who reaches one workstation is potentially much more dangerous if the ransomware can quickly move toward file servers, administrative systems, and other network resources.
Why Manufacturing Networks Face Special Pressure
Manufacturing environments are particularly complicated from a defensive perspective.
A typical organization may have office computers, engineering workstations, production equipment, specialized applications, remote maintenance connections, vendor access, cloud services, identity infrastructure, and legacy systems operating simultaneously.
Some of these systems cannot simply be taken offline.
Production downtime can cost enormous amounts of money, which creates additional pressure during an extortion event.
Attackers understand this economic reality.
A criminal does not necessarily need to steal the most valuable intellectual property in the world. Sometimes the most valuable asset is the organization’s ability to continue operating.
The Business Impact Can Outlive Encryption
A ransomware attack can create several simultaneous crises.
There is the immediate operational disruption.
There is the cost of incident response.
There may be legal and regulatory obligations.
Customers and suppliers may demand answers.
Cybersecurity teams may need to rebuild infrastructure.
Executives may need to manage public relations.
And if data was stolen, the organization may face long-term consequences even after systems are restored.
For manufacturers, there can also be delays in production, shipping, procurement, engineering, quality assurance, and customer delivery.
The ransom itself can therefore become only one component of the total financial damage.
Orsima Adds Another Layer of Uncertainty
The second reported victim, Orsima, deserves the same cautious treatment.
The supplied ThreatMon alert identifies Orsima as a newly listed victim, but the information provided does not establish the nature of the alleged compromise, the amount of data involved, the affected systems, or whether Orsima has publicly confirmed the incident.
Those details should not be invented.
Until additional evidence becomes available, the most accurate description is that The Gentlemen has reportedly claimed Orsima as a victim.
This distinction protects readers from turning an unverified threat-intelligence claim into an established fact.
Dark Web Claims Require Careful Verification
Dark web ransomware reporting presents a difficult problem for cybersecurity journalists.
Threat actors can publish company names without immediately providing enough evidence for independent verification.
Some claims are legitimate.
Some may involve old incidents.
Some may exaggerate the amount of stolen information.
Others may be completely false.
Security researchers therefore generally treat leak-site listings as intelligence leads that require additional validation.
In this case, the ThreatMon alert provides an important early warning, but further confirmation from the affected organizations, law enforcement, cybersecurity researchers, or additional technical evidence would strengthen the claims.
The Bigger Ransomware Trend
The timing of these listings is important because The Gentlemen is appearing during a broader period of intense ransomware activity.
Recent reporting has identified The Gentlemen as one of the leading ransomware operations of 2026. TechRadar reported that the group was responsible for hundreds of attacks in the second quarter and saw substantial growth compared with the previous quarter.
The group is therefore not operating in isolation.
It is part of a wider criminal ecosystem in which ransomware operators continuously recruit affiliates, purchase stolen credentials, exploit exposed systems, and adapt their tools.
Credentials Remain a Critical Weakness
One of the most important lessons from research into The Gentlemen is that organizations do not necessarily need an exotic zero-day vulnerability to become victims.
Compromised credentials and exposed internet-facing infrastructure can provide attackers with the first step into an environment.
Kaspersky has reported that The Gentlemen and its affiliates primarily rely on exploited internet-facing services and compromised credentials for initial access.
That means basic security controls remain extremely important.
Strong multifactor authentication, credential monitoring, timely patching, privileged-access management, and careful control of externally exposed systems can make a substantial difference.
The Attack Often Begins Before the Ransomware
The visible ransomware event is frequently the final stage of a much longer intrusion.
Attackers may spend days or weeks inside an environment before encryption begins.
During that time, they can identify valuable systems, compromise additional accounts, establish persistence, steal information, and map network relationships.
By the time employees see encrypted files, the most important damage may already have occurred.
That is why modern ransomware defense must focus on detecting the intrusion rather than simply detecting the encryption.
Detection Speed Is Everything
The difference between detecting an attacker after ten minutes and detecting them after ten days can be enormous.
Early detection gives defenders an opportunity to disable accounts, isolate endpoints, revoke credentials, terminate sessions, block malicious infrastructure, and investigate suspicious activity.
Delayed detection gives attackers more time to move laterally and steal data.
For this reason, endpoint detection and response, identity monitoring, network telemetry, and centralized logging should be considered core ransomware defenses rather than optional security enhancements.
Backups Still Matter, But They Are Not Enough
Offline and immutable backups remain essential.
They can significantly reduce the leverage attackers gain from encryption.
But backups do not solve data theft.
If an attacker steals confidential engineering files before encrypting the network, restoring from a backup does not make those files disappear from the attacker’s possession.
Organizations therefore need two separate defensive strategies: one focused on recoverability and another focused on data protection.
Data Loss Prevention Becomes More Important
Manufacturing organizations should pay close attention to abnormal data transfers.
Large outbound transfers from engineering workstations, unusual cloud uploads, unexpected archive creation, suspicious compression activity, and unusual access to sensitive project directories can all become important warning signals.
No single signal necessarily proves an attack.
But several anomalies occurring together can reveal that an attacker is preparing an extortion operation.
Network Segmentation Can Limit the Blast Radius
One of the most effective ways to reduce ransomware damage is to prevent attackers from moving freely between systems.
Critical production systems should not automatically trust ordinary corporate workstations.
Engineering environments should receive additional protection.
Administrative accounts should be tightly controlled.
Remote vendor access should be restricted and monitored.
Backup infrastructure should be separated from normal user networks.
Segmentation cannot guarantee that ransomware will be stopped, but it can prevent one compromised account or endpoint from becoming a catastrophe across the entire organization.
The AI Factor Is Also Worth Watching
The broader ransomware ecosystem is increasingly benefiting from automation and AI-assisted development.
Check Point’s research into The Gentlemen found evidence that the group’s operators used AI coding assistants while developing parts of their infrastructure.
This does not mean AI independently launches ransomware attacks.
The more important point is that criminals can use modern development tools to accelerate coding, automate repetitive tasks, improve infrastructure, and potentially reduce the technical barrier for new affiliates.
Cybercrime is becoming more industrialized, and AI may contribute to that efficiency.
The Gentlemen Has Already Shown Resilience
Perhaps one of the most unusual developments surrounding the group was that its own infrastructure was reportedly compromised.
Check Point reported that The
Yet the group continued operating.
That resilience is important.
A criminal organization can lose infrastructure, suffer an internal leak, or experience operational disruption and still return because its affiliates, tooling, access sources, and financial incentives remain.
What This Means for Victims
For organizations appearing on a ransomware leak-site listing, the first priority should not be negotiating with criminals.
The priority should be determining what actually happened.
That means preserving evidence, isolating compromised systems, investigating identity activity, reviewing endpoint telemetry, identifying data-access patterns, and determining whether information was exfiltrated.
Organizations should also activate their incident-response plans and involve appropriate legal, cybersecurity, insurance, and regulatory teams.
What This Means for Defenders
Security teams should assume that ransomware prevention is a continuous process.
Every externally exposed service should be reviewed.
Every privileged account should be examined.
Every remote-access pathway should be monitored.
Every backup should be tested.
Every critical network dependency should be documented.
And every organization should know what happens during the first hour of a ransomware incident.
Preparation is often the difference between a contained security incident and a business-wide crisis.
What Undercode Say:
The Victim Listings Are a Warning, Not a Verdict
The latest reports involving Additive Manufacturing and Orsima should be considered credible intelligence leads, but not automatically treated as confirmed breaches.
The distinction between claimed victim and confirmed victim is essential in responsible cybersecurity reporting.
The Timing Is Significant
Two reported additions within minutes suggest heightened activity around the group’s leak infrastructure.
It does not prove that both attacks occurred simultaneously.
However, it demonstrates that monitoring dark web activity can provide early visibility into developing incidents.
The Gentlemen Is No Longer an Emerging Curiosity
The group has moved beyond the stage where security teams could dismiss it as a new ransomware experiment.
Multiple security researchers now identify The Gentlemen as one of the most active ransomware operations of 2026.
Its scale makes every new victim listing more relevant.
Manufacturing Is Becoming a High-Value Cyber Target
Advanced manufacturing combines intellectual property with operational dependency.
That makes it attractive from both an espionage perspective and an extortion perspective.
Attackers can potentially pressure companies using production disruption and stolen intellectual property at the same time.
The Real Target May Be Intellectual Property
Ransomware criminals do not always need to destroy a company’s data to make money from it.
Engineering information can have value on underground markets.
Customer information can create regulatory exposure.
Supplier information can reveal business relationships.
Internal documents can create reputational pressure.
The theft component can therefore become more valuable than encryption.
Double Extortion Has Changed the Economics
Traditional ransomware relied heavily on encryption.
Modern ransomware increasingly combines encryption with data theft.
That gives attackers multiple pressure points.
Even companies with excellent backups can still face extortion if confidential information has been copied.
RaaS Makes the Problem Scalable
The
Affiliates become the force multiplier.
This is one of the biggest reasons ransomware continues to spread across industries.
Affiliates Create Unpredictability
Different affiliates may have different technical skills.
One may prefer exposed remote services.
Another may rely on stolen credentials.
Another may specialize in social engineering.
This diversity makes defensive prediction harder.
The Initial Access Problem Remains Critical
The sophisticated ransomware executable gets most of the attention.
But the first stolen credential or vulnerable service may be the event that makes the entire attack possible.
Defenders should therefore spend as much time securing entry points as they spend analyzing malware.
Internet-Facing Assets Need Constant Monitoring
An
New cloud services appear.
Old VPN systems remain forgotten.
Temporary remote-access systems become permanent.
Unused accounts survive employee departures.
Attackers actively search for these weaknesses.
Identity Security Is Now Ransomware Security
A compromised identity can provide attackers with legitimate-looking access.
That makes identity monitoring increasingly important.
MFA, privileged access management, conditional access, credential rotation, and suspicious-login detection should all be part of the ransomware defense strategy.
Lateral Movement Is the Critical Phase
Once inside, attackers want to turn one compromised machine into access to many.
The
Network segmentation can therefore dramatically influence the final impact.
Manufacturing Needs Stronger IT-OT Separation
Companies operating industrial environments should carefully separate enterprise IT from operational technology.
A compromised employee workstation should not automatically provide a route into production systems.
This is one of the most important architectural defenses against ransomware.
Backup Isolation Is Essential
Backups that remain connected to the production environment can become targets.
Attackers increasingly understand that destroying recovery options increases ransom pressure.
Immutable and logically separated backups reduce this risk.
Recovery Testing Is Often Neglected
Having backups is not the same as having a working recovery strategy.
Organizations need to know how long restoration actually takes.
They need to know which systems must return first.
They need to identify dependencies.
They need to test recovery before an attacker forces them to learn these lessons during a crisis.
Data Exfiltration Requires Equal Attention
Encryption telemetry alone cannot reveal the entire attack.
Security teams should monitor suspicious outbound traffic and abnormal access to sensitive repositories.
The goal is to identify theft before criminals can use it as leverage.
Threat Intelligence Can Buy Time
Threat intelligence monitoring is valuable because ransomware leak sites can sometimes reveal attacks before organizations publicly disclose them.
Early warning gives defenders an opportunity to investigate.
But intelligence should always be validated.
A dark web claim is a lead, not automatically proof.
Journalism Has a Responsibility Here
Cybersecurity reporting can unintentionally cause harm when unverified claims are presented as confirmed breaches.
Victim organizations may still be investigating.
Employees and customers may panic.
Investors may react.
Therefore, reporting language matters.
“Claimed victim” is not the same as “confirmed breach.”
The
The individual Additive Manufacturing and Orsima claims are important, but the broader trend is more concerning.
The Gentlemen continues to demonstrate the ability to maintain a growing victim pipeline.
That indicates that the underlying criminal infrastructure remains operational.
Criminal Infrastructure Is Becoming More Professional
Ransomware groups increasingly operate like technology companies, except their business model is criminal extortion.
They develop malware.
They operate dashboards.
They recruit affiliates.
They manage negotiations.
They maintain leak infrastructure.
They source initial access.
This professionalism increases the threat.
AI Could Accelerate That Model
The use of AI-assisted development documented in research into The Gentlemen suggests that modern cybercriminals can also benefit from the same productivity technologies used by legitimate developers.
The important concern is acceleration.
Even small improvements in development speed can matter when a criminal organization operates at scale.
The Threat Is Not Limited to Large Corporations
Ransomware groups need victims who can pay.
But they also need victims whose systems are vulnerable.
That means smaller organizations can become attractive targets when they have valuable data and weaker security controls.
Size alone does not provide protection.
Specialized Industries Can Be Attractive
A company does not need to be a household name to possess valuable information.
A small engineering firm can hold commercially sensitive designs.
A specialized manufacturer can control important supplier information.
A software company can possess customer credentials.
A logistics provider can have operational data.
The value is often hidden in the
Supply Chains Increase the Risk
Attackers may also see smaller suppliers as stepping stones toward larger customers.
A compromised company can potentially expose credentials, documents, connections, or information belonging to its partners.
That makes third-party cybersecurity increasingly important.
The Best Defense Is Layered
There is no single control that defeats ransomware.
Organizations need multiple layers.
MFA reduces account compromise.
Patching reduces exploitation.
EDR improves detection.
Segmentation limits movement.
DLP helps identify theft.
Backups improve recovery.
Threat intelligence provides external visibility.
Incident response reduces confusion.
The First Hour Can Decide the Outcome
When ransomware is detected, hesitation can be expensive.
Security teams need predetermined procedures for isolating endpoints, disabling accounts, protecting backups, collecting evidence, and escalating the incident.
A plan created during an attack is rarely as effective as one rehearsed beforehand.
Organizations Should Assume Attackers Will Adapt
Security controls that work today may not be sufficient tomorrow.
Ransomware operators continuously modify infrastructure, malware, access methods, and extortion techniques.
Defenders must therefore treat cybersecurity as an evolving process.
The Gentlemen Deserves Continued Monitoring
The group’s rapid growth, RaaS structure, technical capabilities, and expanding victim list make it a threat that should remain on security teams’ radar.
The latest reported claims are another reminder that the campaign remains active.
The Most Important Lesson
The real lesson from the Additive Manufacturing and Orsima claims is not that two companies may have been attacked.
It is that ransomware has become a scalable criminal industry capable of moving quickly across sectors.
The organizations that survive these attacks most effectively will not necessarily be those with the most expensive security products.
They will be the organizations that understand their attack surface, protect identities, segment critical systems, monitor data movement, maintain reliable backups, and know exactly what to do when something goes wrong.
✅ The Gentlemen Is an Active Ransomware Operation
Microsoft and multiple cybersecurity researchers independently document The Gentlemen as an active Ransomware-as-a-Service operation with double-extortion capabilities and significant victim activity.
⚠️ The Additive Manufacturing and Orsima Claims Remain Unconfirmed
The supplied ThreatMon reports identify both organizations as victims, but the information provided does not establish independent confirmation from either organization or forensic evidence proving the alleged compromises. They should therefore be described as claimed victims, not confirmed breaches.
✅ The Group Has Demonstrated Advanced Ransomware Capabilities
Microsoft has documented The Gentlemen
Deep Analysis
Command 1: Treat the Listings as Early-Warning Intelligence
Security teams should immediately investigate a credible victim listing while avoiding the assumption that the claim is already proven.
Command 2: Validate Every Identity Connection
Review suspicious authentication events, privileged-account activity, impossible-travel alerts, new MFA registrations, and unexpected password changes.
Command 3: Search for Lateral Movement
Investigate unusual administrative connections between workstations, servers, domain controllers, file servers, and engineering systems.
Command 4: Hunt for Data Exfiltration
Look for abnormal outbound transfers, unusual archive creation, cloud uploads, and access to repositories that normally receive little traffic.
Command 5: Protect Manufacturing Networks
Where industrial or engineering environments exist, separate them from ordinary corporate systems and strictly control pathways between the two.
Command 6: Verify Backup Integrity
Backups should be tested regularly and protected from unauthorized deletion, modification, or encryption.
Command 7: Reduce External Exposure
Internet-facing services should be inventoried continuously and patched rapidly, especially VPN, remote-access, identity, and edge-security systems.
Command 8: Strengthen MFA
MFA should protect administrator accounts, remote access, cloud services, and other high-value authentication pathways.
Command 9: Monitor Privileged Accounts
Unexpected privilege escalation can be an important indicator that attackers are moving from initial access toward broader control.
Command 10: Prepare for Data Theft
Incident-response plans should include both ransomware recovery and stolen-data scenarios.
Command 11: Separate Recovery From Negotiation
Technical recovery decisions should not depend entirely on whether criminals demand or receive payment.
Command 12: Preserve Evidence
Forensic evidence can help determine the attack path, identify compromised accounts, understand what information was accessed, and support legal or regulatory requirements.
Command 13: Monitor the Threat Actor
Organizations should continuously track new intelligence concerning The Gentlemen, its affiliates, infrastructure, malware variants, and victim claims.
Command 14: Do Not Trust a Single Security Layer
Endpoint protection alone is insufficient.
Network segmentation alone is insufficient.
Backups alone are insufficient.
The strongest defense is a combination of controls that force attackers to overcome multiple barriers.
Prediction
(+1) Defensive Awareness Will Continue to Improve
The growing visibility around The Gentlemen is likely to push more organizations toward stronger identity controls, network segmentation, immutable backups, and continuous threat monitoring.
(+1) Threat Intelligence Will Become More Valuable
As ransomware groups publish victims rapidly, organizations will increasingly rely on external intelligence to discover possible incidents before traditional public disclosures.
(+1) Manufacturing Security Will Receive More Attention
If additional manufacturing and engineering organizations appear in ransomware campaigns, security leaders are likely to increase investment in protecting intellectual property and separating IT environments from production systems.
(-1) The Gentlemen Is Likely to Continue Adding Victims
Given the
(-1) Data Extortion Will Remain a Major Problem
Even organizations capable of restoring encrypted systems may continue facing pressure if attackers successfully steal sensitive information.
(-1) Smaller Specialized Companies Could Face Increasing Risk
The expansion of ransomware-as-a-service means attackers do not need to concentrate exclusively on global corporations. Smaller companies with valuable data, weak defenses, or strategic supply-chain positions can also become attractive targets.
(+1) The Biggest Advantage Will Belong to Prepared Organizations
The organizations most likely to limit the damage will be those that discover intrusions early, isolate compromised systems quickly, protect their backups, and understand where their most valuable information is stored.
The reported additions of Additive Manufacturing and Orsima therefore deserve attention, but they should remain labeled as ransomware claims until independently confirmed. The larger story is the continued expansion of The Gentlemen into a mature and highly scalable criminal operation, demonstrating once again that modern ransomware is no longer simply about locking files. It is about controlling access, stealing information, disrupting operations, and creating enough uncertainty that victims feel they have no safe option.
▶️ Related Video (72% Match):
🕵️📝Let’s dive deep and fact‑check.
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
References:
Reported By: x.com
Extra Source Hub (Possible Sources for article):
https://www.reddit.com/r/AskReddit
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube




