Most ransomware coverage focuses on the biggest single victim of the week. The more useful signal this month is a group whose growth curve nobody is having to round up: TheGentlemen went from a new name a year ago to the busiest ransomware operation on the planet, and it built that growth on tooling that does part of the attacker’s job for them.
From launch to the top of the leaderboard in under a year
TheGentlemen first appeared in August 2025, started by a former affiliate of the Qilin ransomware operation. It posted a 588 percent quarter-over-quarter surge in Q1 2026, claiming 179 victims and taking second place among active ransomware-as-a-service programmes. In Q2 2026 it went further, posting 300 victims to become the most active group of the quarter, narrowly overtaking Qilin itself. Its data leak site now lists claims against organisations in more than 60 countries, led by the United States but including France, alongside education, transportation, healthcare, financial services, energy and government targets across four continents. A breach of the group’s own backend infrastructure in May, which leaked internal chat logs, affiliate details and negotiation transcripts, barely slowed it down. Operators rebuilt, hardened the malware, and kept going.
The technical detail that should change how defenders think about it
Microsoft’s security researchers dissected the group’s Go-based encryptor and found it is built to self-propagate once it lands inside a network, spreading laterally without an operator manually pivoting to each new machine. Combined with the group’s standard double-extortion model, stealing data before encrypting so the leak threat still works even against organisations with solid backups, that makes the initial foothold the point that matters most. Once TheGentlemen’s payload is inside one machine on a flat or under-segmented network, the group’s tooling does a meaningful share of the lateral movement work that a human operator would otherwise have had to do by hand, and do carefully enough to avoid detection.
The victims are not just the ones making headlines
On 14 August, TheGentlemen’s leak site added I.P.S. Srl, an Italian construction and demolition recycling company founded in 2005, and Gfeller Treuhand und Verwaltungs AG, a Swiss real estate and fiduciary firm operating since 1980, with both attacks dated to 13 August. Neither is a defence contractor or a household name, and that is precisely the point. A group posting 300 claims in a single quarter is not being selective about company size or sector. It is running an operation at a volume where mid-sized European firms, the kind without a dedicated security operations centre, are well within its normal targeting range, not an unlucky exception.
Self-propagating malware inside your network is a network segmentation and detection problem as much as an endpoint one, and it is worth testing whether your environment would actually contain a foothold like this before you find out the hard way. If you want a practical review of your ransomware exposure, from network segmentation and backup isolation to incident response readiness, contact Excello Digital. We help European organisations close the gaps that turn one compromised machine into a full-network incident.
