Thus Spoke…The Gentlemen

2026-05-14T20:52:31Z590d5800541a7d9947a3a1b76d3977f2a673096d719f2092b0570b58b12f67e2
AI‑assisted malwareChatGPT data leakDFIRDLSOAuth token theftRaaSSystemBCThe GentlemenTrueConfVECTdata breachdata‑leak‑siteincident responseransomwaresupply‑chainwiperzero‑day

What happened

Check Point Research (Apr–May 2026) collection: multiple intelligence and DFIR reports covering a surge in ransomware activity and supply‑chain/credential incidents. Key highlights: The Gentlemen RaaS (new mid‑2025 actor) offering multi‑OS lockers to affiliates and leveraging SystemBC as a proxy; VECT RaaS exhibiting wiper‑like behaviour and partnerships with other crime groups; State of Ransomware Q1 2026 showing ~70 active data‑leak sites and 2,122 new victims; Operation TrueChaos disclosure of a TrueConf zero‑day (CVE‑2026‑3502, CVSS 7.8) exploited against Southeast Asian government targets

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
checkpoint_research
Record identifier
590d5800541a7d9947a3a1b76d3977f2a673096d719f2092b0570b58b12f67e2
Enrichment time
2026-05-14T20:52:31Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.