TheGentlemen Ransomware Claims Fresh Attacks on a US 3D Printer and Chilean Mining Giant + Video

Listen to this Post

Featured ImageA New Wave of Ransomware Claims Raises Fresh Questions

Ransomware is no longer confined to conventional office environments. Manufacturing floors, mining operations, industrial machinery, and specialized production systems are increasingly exposed to cybercriminals who understand that shutting down a physical operation can be far more damaging than locking a few corporate laptops.

That concern is now at the center of two fresh ransomware claims attributed to TheGentlemen, a ransomware operation that has rapidly established itself as a significant player in the cybercrime ecosystem.

According to a July 31, 2026 post published by Cybersecurity News Everyday, Additive Manufacturing LLC, a Las Vegas-based 3D-printing provider, reportedly suffered a ransomware attack attributed to TheGentlemen. The report says the incident disrupted operations in the United States.

A second claim concerns Grupo Minero Las Cenizas, a Chilean mining company. The same reporting channel stated that the company experienced a ransomware incident linked to TheGentlemen, allegedly affecting operations in Cabildo, Taltal, and Franke.

These claims should be treated carefully because public reporting does not yet establish that either incident has been independently confirmed by the affected organizations or by law-enforcement agencies. Nevertheless, the targets themselves are significant.

Grupo Minero Las Cenizas confirms that it operates mining activities in Cabildo and Taltal and that its operations include the Franke facilities. The company describes itself as a major player in Chilean medium-scale mining, with operations involving copper production, extraction, concentration, and leaching.

The apparent combination of manufacturing and mining targets also fits a broader ransomware trend: criminals are increasingly attracted to organizations where downtime immediately translates into lost production, delayed deliveries, contractual penalties, and potentially enormous recovery costs.

The Additive Manufacturing Claim

The first reported victim is Additive Manufacturing LLC, described in the July 31 post as a Las Vegas-based 3D-printing provider.

The reported attack allegedly disrupted the

While the publicly available claim provides few technical details, the nature of additive manufacturing makes such an incident particularly interesting from a cybersecurity perspective.

A modern 3D-printing company can depend on far more than printers themselves. Design workstations, engineering software, production-management systems, file servers, cloud services, network storage, authentication infrastructure, customer portals, and specialized manufacturing equipment can all form part of the production chain.

If attackers compromise the digital systems controlling that chain, the consequences can quickly move from the IT department to the factory floor.

Why 3D Printing Is an Attractive Ransomware Target

Additive manufacturing depends heavily on digital information.

A physical product may begin as a computer-aided design file, pass through engineering software, be converted into machine-readable instructions, and eventually reach a printer or other manufacturing system.

That creates an unusually direct relationship between data availability and physical production.

If engineering files become inaccessible, production schedules can stop.

If authentication systems fail, employees may lose access to critical applications.

If network storage is encrypted, production data may become unavailable.

And if manufacturing-management systems are affected, even functioning machines may become difficult to operate safely or efficiently.

This makes ransomware particularly dangerous for smaller specialized manufacturers. They may not have the cybersecurity resources of multinational corporations, yet their operations can depend on highly interconnected digital infrastructure.

The Chilean Mining Claim

The second claim is potentially even more consequential.

Cybersecurity News Everyday reported that TheGentlemen targeted Grupo Minero Las Cenizas in Chile, allegedly affecting operations in Cabildo, Taltal, and Franke.

The

That matters because the ransomware claim is not describing an organization with a single small office.

It potentially involves an interconnected mining organization operating across multiple sites.

Mining Creates a Different Kind of Cyber Risk

Mining companies are especially sensitive to cyber disruption because their technology infrastructure frequently bridges the gap between information technology and operational technology.

Corporate networks may support finance, human resources, procurement, email, and communications.

Operational networks can support industrial controls, monitoring systems, engineering platforms, maintenance systems, production management, and other technologies associated with physical operations.

An attacker does not necessarily need to directly manipulate industrial equipment to cause serious damage.

Sometimes, simply taking away access to supporting systems can force an organization to slow down or stop production.

That is one reason ransomware operators increasingly view industrial companies as valuable victims.

The Gentlemen Is Already a Serious Ransomware Threat

The claims are also notable because TheGentlemen is not an unknown or newly formed ransomware brand.

Threat intelligence reporting describes TheGentlemen as a ransomware-as-a-service operation that emerged around 2025 and subsequently expanded its affiliate model. Halcyon identifies the group as a RaaS operation and describes its origins as connected to a former Qilin affiliate.

Other threat-intelligence reporting describes TheGentlemen as a rapidly scaling operation with hundreds of publicly claimed victims across multiple countries.

The group has therefore evolved beyond the image of a small criminal crew manually attacking individual organizations.

Its RaaS structure potentially allows multiple affiliates to conduct attacks simultaneously.

The Ransomware-as-a-Service Advantage

The RaaS model changes the economics of cybercrime.

Instead of one group having to discover victims, obtain access, conduct intrusion operations, steal information, deploy ransomware, negotiate payments, and manage every technical component itself, an organized ransomware operation can divide those responsibilities.

Operators can maintain malware infrastructure.

Affiliates can pursue victims.

Initial-access brokers can provide compromised credentials or network access.

Other criminals can specialize in data theft.

The result is a distributed criminal ecosystem capable of producing attacks at a much greater scale.

Threat intelligence reporting has specifically associated TheGentlemen with this type of affiliate-driven model.

Double Extortion Makes the Threat Worse

The danger does not necessarily end when ransomware encrypts systems.

Modern ransomware groups frequently combine encryption with data theft.

This creates a second layer of pressure.

A victim may technically recover its systems from backups, but attackers can still threaten to publish stolen corporate information.

That information could include financial documents, employee data, customer records, contracts, engineering files, internal communications, and proprietary business information.

Threat intelligence reporting describes TheGentlemen as using a double-extortion model involving both encryption and threatened publication of stolen information.

For manufacturers, stolen intellectual property can be particularly valuable.

For mining companies, stolen documents may reveal contracts, production information, procurement relationships, geological information, internal communications, or other commercially sensitive material.

Why the Timing Matters

The July 31 claims arrive at a time when TheGentlemen is already being closely monitored by cybersecurity researchers.

Recent threat intelligence has described the group as operationally resilient despite internal leaks and exposure of portions of its infrastructure.

The group has also been associated with tooling designed to interfere with defensive security controls, illustrating how modern ransomware campaigns increasingly resemble sophisticated intrusion operations rather than simple file-encryption attacks.

This means defenders should not think of ransomware as an isolated event that begins when encryption starts.

In many cases, encryption is the final stage of a much longer intrusion.

The Real Battle Happens Before Encryption

By the time ransomware begins encrypting files, attackers may already have spent days or weeks inside an environment.

They may have obtained credentials.

They may have mapped the network.

They may have identified backup infrastructure.

They may have searched for privileged accounts.

They may have stolen data.

They may have disabled security tools.

They may have learned which systems are essential to production.

The encryption event is therefore often the visible explosion after the attackers have quietly prepared the battlefield.

Manufacturing and Mining Share a Dangerous Weakness

At first glance, a 3D-printing provider and a mining company appear completely different.

One produces components using additive manufacturing.

The other extracts and processes minerals.

Yet their cybersecurity problems can overlap significantly.

Both depend on availability.

Both may operate specialized technology.

Both can contain proprietary information.

Both may rely on third-party vendors.

Both can have legacy systems.

Both may have remote-access requirements.

And both can experience significant financial consequences when digital systems become unavailable.

That makes these sectors attractive to financially motivated ransomware operators.

Deep Analysis: Why These Two Claims Matter

  1. The Victim Selection Is the Bigger Story

The most important detail may not be the ransomware name.

It may be the industries reportedly being targeted.

Manufacturing and mining are sectors where cyber disruption can produce physical consequences.

2. Operational Downtime Creates Leverage

Ransomware criminals understand that every hour of downtime can represent lost revenue.

A production line cannot simply be restarted like a home computer.

Industrial recovery can require validation, engineering checks, system restoration, safety testing, and coordination between multiple teams.

  1. Attackers Do Not Need to Destroy Machinery

A common misconception is that ransomware must directly compromise industrial controllers to affect physical production.

That is not necessarily true.

Disrupting supporting systems can be enough to create operational paralysis.

4. Digital Manufacturing Is Increasingly Connected

Modern manufacturing relies heavily on digital workflows.

Design, scheduling, inventory, quality control, production management, and logistics may all communicate through connected systems.

Every connection creates another potential attack path.

5. Mining Is Becoming More Digitized

Mining companies increasingly depend on software and networked technology to manage complex operations.

That creates efficiency.

It also creates cyber dependency.

6. Multi-Site Organizations Face Multiplication Risk

A company operating several facilities may have a larger attack surface than a single-site organization.

A compromised central identity system, VPN, cloud service, or shared administrative environment could potentially affect multiple locations.

7. Credentials Remain Critical

Threat intelligence reporting has associated TheGentlemen campaigns with credential-based access and exploitation of exposed infrastructure.

That reinforces a basic lesson: stolen passwords can become just as dangerous as software vulnerabilities.

8. Remote Access Deserves Special Attention

VPNs, remote desktop services, privileged access tools, and vendor connections can provide attackers with an entry point into organizations.

Industrial companies often require remote access for maintenance and support.

That necessity must be balanced against the security risk.

  1. Backups Are Not Automatically a Safety Net

Backups only help if they remain accessible and trustworthy.

Attackers increasingly attempt to identify backup systems during an intrusion.

Organizations therefore need protected, isolated, and regularly tested recovery mechanisms.

10. Recovery Speed Can Determine the Outcome

Two companies can suffer similar attacks and experience dramatically different consequences.

The difference is often preparation.

The organization that has rehearsed recovery procedures can move much faster than one trying to invent a response during a crisis.

11. Data Theft Changes the Negotiation

Encryption creates an availability crisis.

Data theft creates a confidentiality crisis.

Together, they give attackers multiple forms of leverage.

12. Intellectual Property Is Especially Sensitive

For additive manufacturing companies, engineering designs may represent years of investment.

Losing control of those files can create competitive and commercial risks beyond the immediate ransomware event.

13. Mining Data Can Also Be Valuable

Mining organizations hold substantial commercial information.

Contracts, supplier information, operational documentation, financial records, and technical data can all become targets for extortion.

14. Smaller Companies Can Be Attractive Targets

Attackers do not always prioritize the biggest corporations.

A smaller company with weaker defenses can sometimes provide an easier route to payment.

15. RaaS Makes Scale Possible

TheGentlemen’s reported RaaS model means the organization can potentially expand its victim pool through affiliates rather than relying entirely on a central hacking team.

16. More Affiliates Mean More Unpredictability

Different affiliates may use different access methods.

That makes defending against the group more difficult.

17. The Threat Is International

The two reported victims are geographically separated by thousands of miles.

One is in the United States.

The other is in Chile.

That geographic spread illustrates how ransomware operations can operate across borders without maintaining a physical presence in each country.

18. Industrial Targets Have Strategic Importance

Even when an attack is financially motivated, its consequences can extend beyond the victim.

Production delays can affect suppliers, customers, contractors, and local communities.

19. Supply Chains Can Become Secondary Victims

If a manufacturer stops producing components, downstream businesses may also face delays.

If mining operations slow, customers and logistics partners can be affected.

  1. The Cyber Incident Can Become an Economic Incident

The longer systems remain unavailable, the more an IT security incident can become a business continuity crisis.

This is why executive leadership needs to be involved in ransomware preparation.

  1. Incident Response Cannot Belong Only to IT

Cybersecurity teams may identify the intrusion.

But restoring a mining operation or manufacturing facility requires engineers, executives, legal teams, communications personnel, vendors, and operational managers.

  1. OT and IT Teams Need a Common Language

Industrial organizations sometimes separate cybersecurity and operational technology teams.

Attackers do not respect that organizational boundary.

Security programs therefore need coordinated visibility across both environments.

23. Segmentation Becomes Critical

A compromised office workstation should not automatically provide a pathway toward critical production environments.

Strong segmentation can limit the blast radius.

24. Privileged Accounts Need Extra Protection

Administrative credentials can unlock enormous portions of an enterprise.

Organizations should minimize privileged access and monitor privileged activity closely.

25. MFA Is Important but Not Sufficient

Multi-factor authentication can significantly reduce credential-based attacks.

But organizations must also protect session tokens, endpoints, privileged accounts, and authentication infrastructure.

26. Vulnerability Management Must Be Continuous

Attackers constantly search for exposed systems.

Organizations should prioritize internet-facing infrastructure and vulnerabilities known to be actively exploited.

27. Security Monitoring Must Extend Beyond Endpoints

Endpoint protection is important.

But ransomware investigations increasingly require visibility across identity systems, cloud infrastructure, network traffic, VPNs, email, and administrative tools.

28. Data Exfiltration Should Trigger Alarms

Encryption may be detected quickly.

Data theft can remain invisible for much longer.

Monitoring unusual outbound transfers can therefore provide an earlier warning.

29. Human Behavior Remains Important

Phishing, credential theft, malicious downloads, and social engineering remain common ways to obtain initial access.

Technology alone cannot eliminate the risk.

30. Third-Party Access Needs Scrutiny

Vendors and contractors may require privileged access to industrial environments.

Those connections should be limited, monitored, and removed when unnecessary.

31. Ransomware Groups Exploit Business Pressure

Criminals know that executives care about deadlines, production schedules, customer relationships, and public reputation.

Their extortion strategy is built around that pressure.

32. Public Claims Are Not Proof

This is one of the most important lessons from the current story.

A ransomware

Victim confirmation, technical evidence, regulatory filings, forensic reports, or credible third-party investigation are needed for stronger attribution.

33. The Las Cenizas Claim Needs Confirmation

The

The distinction between a verified fact and an attacker claim is essential.

  1. The Additive Manufacturing Claim Also Needs Confirmation

The July 31 report provides the ransomware allegation, but publicly available information identified in this analysis does not independently verify the incident.

The responsible wording is therefore “reported” or “claimed,” rather than “confirmed.”

35. Attribution Can Also Be Complicated

Even if ransomware is deployed, determining which criminal group was responsible can require forensic evidence.

Attackers can use leaked tools, rented infrastructure, compromised accounts, or techniques associated with other groups.

36.

Despite the uncertainty surrounding individual victim claims, the broader threat posed by TheGentlemen is supported by independent threat-intelligence reporting describing its RaaS operations and international activity.

37. Industrial Cybersecurity Is Becoming Business Security

Cybersecurity is no longer simply about protecting email accounts and employee laptops.

For industrial organizations, it increasingly means protecting production itself.

  1. Ransomware Preparation Should Begin Before an Attack

Organizations should assume that an attacker may eventually obtain an initial foothold.

The goal should be to detect, contain, recover, and continue operating.

  1. Resilience Is More Important Than Perfect Prevention

No security program can guarantee that an organization will never be breached.

A resilient organization is one that can withstand compromise without allowing the incident to become catastrophic.

40. The Real Warning Is the Pattern

The significance of these claims is not simply that two organizations may have been attacked.

It is that ransomware operators continue searching for industries where digital disruption can rapidly become physical and financial disruption.

What Undercode Say:

TheGentlemen Is Becoming a Bigger Problem

The most concerning aspect of these latest claims is the apparent movement toward organizations whose digital infrastructure supports real-world production.

That is exactly where ransomware becomes more dangerous.

A compromised office environment is serious, but a compromised industrial organization can create a much larger chain reaction.

The Claims Should Be Read With Caution

At the same time, we should not confuse a ransomware group’s allegation with forensic confirmation.

The Additive Manufacturing and Las Cenizas incidents should currently be described as reported or claimed attacks, not established facts.

That distinction is especially important in cybersecurity reporting.

Las Cenizas Deserves Particular Attention

The Las Cenizas claim is particularly interesting because the company operates across multiple mining locations.

Its official corporate information confirms operations in Cabildo, Taltal, and Franke, meaning the reported victim profile corresponds to a genuinely distributed industrial organization.

If the reported incident is ultimately confirmed, investigators will need to determine whether the affected locations were compromised through a shared corporate infrastructure or whether the disruption spread through separate pathways.

Manufacturing Is Not an Easy Target by Accident

The additive-manufacturing claim also fits a logical criminal strategy.

A company dependent on digital design files and automated production can face enormous pressure when those systems become unavailable.

That creates exactly the kind of leverage ransomware operators want.

The RaaS Model Changes the Scale

TheGentlemen’s RaaS structure is arguably more important than any individual victim.

A centralized criminal organization supported by affiliates can generate attacks at a scale that would be difficult for a small group of operators working alone.

Independent threat-intelligence sources have described the group as a major and rapidly expanding ransomware operation.

The Threat Is Not Only Encryption

Organizations should also consider the possibility of data theft, credential compromise, persistence, and security-tool interference.

Ransomware campaigns are increasingly full intrusion operations.

The encryption stage is simply the moment when the victim realizes how far the attackers have progressed.

Industrial Organizations Need a Different Security Mindset

Mining and manufacturing companies should treat cybersecurity as part of operational resilience.

A cybersecurity incident can become a production incident.

A production incident can become a supply-chain incident.

And a supply-chain incident can eventually become an economic problem.

The Next Target May Not Look Like a Traditional Enterprise

Ransomware groups have demonstrated that there is value in attacking organizations far outside traditional technology and finance sectors.

Factories, engineering firms, logistics providers, healthcare organizations, construction companies, and mining operations can all become attractive targets.

The Greatest Risk Is Underestimating Downtime

The financial impact of ransomware is not limited to the ransom demand.

There can be lost production, overtime, forensic investigations, legal expenses, customer compensation, equipment recovery, system rebuilding, regulatory costs, and reputational damage.

The ransom may ultimately represent only one part of the bill.

Backups Must Be Treated as Critical Infrastructure

Companies should maintain offline or otherwise strongly isolated backups and regularly test whether those backups can actually restore critical services.

A backup that exists only on paper is not a recovery strategy.

Identity Security Should Be a Priority

Because modern ransomware operations frequently rely on stolen credentials and remote access, identity protection should receive as much attention as endpoint protection.

Strong authentication, privileged-access controls, session monitoring, and rapid credential revocation can significantly reduce the attacker’s freedom of movement.

The Main Lesson From These Claims

Whether both incidents are eventually confirmed or not, the broader warning remains valid.

The ransomware economy is actively searching for organizations where digital systems are tied directly to revenue-producing physical operations.

That makes industrial cybersecurity one of the defining security challenges of the current ransomware era.

❌ The Two Attacks Are Not Independently Confirmed Yet

The supplied report attributes attacks against Additive Manufacturing LLC and Grupo Minero Las Cenizas to TheGentlemen, but the publicly available evidence reviewed here does not independently confirm both incidents. They should therefore be presented as ransomware claims/reports, not proven breaches.

✅ Grupo Minero Las Cenizas Operates in the Reported Locations

Las Cenizas’ own corporate website confirms operations in Cabildo and Taltal and identifies Franke as part of the group’s mining portfolio.

✅ TheGentlemen Is a Documented Ransomware Operation

Independent threat-intelligence sources describe TheGentlemen as a ransomware-as-a-service operation with international activity, supporting the broader characterization of the group as an established ransomware threat.

⚠️ Attribution Requires More Evidence

The appearance of a victim on a ransomware leak site or a social-media report can be an important intelligence indicator, but definitive attribution normally requires technical evidence, victim confirmation, or independent investigation.

Prediction

(+1) TheGentlemen Will Continue Targeting High-Impact Industrial Organizations

The most likely trajectory is continued expansion into manufacturing, mining, logistics, engineering, and other sectors where downtime creates immediate financial pressure.

The RaaS model gives affiliates an incentive to pursue organizations capable of paying significant extortion demands.

(+1) Multi-Site Companies Will Remain Attractive

Organizations with several facilities may become particularly appealing because a single successful intrusion could potentially create broader operational disruption.

(+1) Data Theft Will Remain Central to Extortion

Even if companies maintain reliable backups, stolen information can still give attackers leverage.

(+1) Industrial Cybersecurity Spending Will Increase

Repeated ransomware incidents involving production-oriented organizations will likely push more companies to invest in network segmentation, identity security, incident response, and recovery testing.

(-1) Public Claims Will Continue Creating False Positives

Not every ransomware claim will necessarily correspond to a confirmed or successful intrusion.

Security researchers and journalists will therefore need to distinguish carefully between attacker claims, third-party reports, and verified incidents.

(-1) Smaller Industrial Companies May Struggle With Defense

Specialized manufacturers and mid-sized industrial organizations may face increasing pressure because they often operate complex technology environments without the security budgets of major multinational corporations.

(+1) The Bigger Battle Will Be Resilience

The organizations best positioned against TheGentlemen and similar groups will not necessarily be those that can guarantee perfect prevention.

They will be those capable of detecting intrusions early, isolating compromised systems, protecting backups, restoring critical operations, and continuing business with minimal disruption.

Final Assessment

The July 31 reports surrounding Additive Manufacturing LLC and Grupo Minero Las Cenizas illustrate how ransomware continues moving toward organizations where computers are directly connected to physical production.

The incidents remain claims pending stronger independent confirmation, but the underlying threat is real.

TheGentlemen is an established ransomware operation, and its RaaS model gives it the potential to pursue victims across borders and industries.

For manufacturers and mining companies, the warning is straightforward: the next ransomware crisis may not simply lock files—it may stop production.

▶️ Related Video (80% Match):

🕵️‍📝Let’s dive deep and fact‑check.

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

References:

Reported By: x.com
Extra Source Hub (Possible Sources for article):
https://www.digitaltrends.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube