Who Runs the Ransomware Group ‘The Gentlemen?’

2026-06-16T19:23:28Z8ed35fb95531ddb2d259feef898dcf444f681f6a99e4c805efcde6bfc12ba96e
AI social engineeringAWS GovCloudCISACanvas breachDDoSGitHubInstagram account takeoverKimwolfMetaMicrosoft Patch TuesdayRussia-linked activityThe Gentlemenbotnetcredential leakcritical vulnerabilitiesdata extortiondata leakeducation sectorhosting providersinsider leaklaw enforcement arrestspublic exploit coderansomwareserver seizures

What happened

A cluster of high-risk cyber incidents: Microsoft released a record ~200 fixes in June 2026 (nearly three dozen rated critical) with public exploit code available for at least three flaws; a CISA contractor publicly exposed AWS GovCloud keys and internal build/deploy secrets on GitHub, prompting congressional scrutiny and wide operational risk to U.S. government systems; the ransomware group “The Gentlemen” has rapidly expanded via aggressive affiliate recruiting (offering 90% of ransoms) and reporting surfaced clues to the administrator’s real-world identity; attackers abused Meta’s AI “help”

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
8ed35fb95531ddb2d259feef898dcf444f681f6a99e4c805efcde6bfc12ba96e
Enrichment time
2026-06-16T19:23:28Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.