Who Runs the Ransomware Group ‘The Gentlemen?’
2026-06-18T01:23:31Z•9d02e72c7a350a195033487d1190b6a58a99eaefed585ddd52a57c1d570bb9e7
AI social engineeringAWS GovCloudCISACanvas breachDDoSInstagramKimwolfMetaMicrosoft Patch TuesdayNetherlands seizureRussia-related infrastructureThe Gentlemenaccount takeoveraffiliate-modelbotnetcredential-leakdata-extortiondata-leaklaw-enforcementpublic exploitransomwareransomware-as-a-servicevulnerability managementzero-day
What happened
A set of high-impact security developments: The Gentlemen ransomware gang has rapidly grown via an aggressive affiliate program promising 90% of ransoms and investigators have uncovered clues toward a real-world identity for the group's administrator. Microsoft’s June Patch Tuesday fixed nearly 200 flaws (a record), including ~34 rated critical and at least three with public exploit code. Attackers abused Meta’s AI support assistant to reset Instagram account passwords and briefly deface high-profile accounts. Dutch authorities seized ~800 servers and arrested two people for operating hosting—
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- 9d02e72c7a350a195033487d1190b6a58a99eaefed585ddd52a57c1d570bb9e7
- Enrichment time
- 2026-06-18T01:23:31Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.