-
The Gentlemen ransomware group announced 42 new companies as victims of their attacks on their dark web website.
-
The group claims to have critical information from there including amounts of data that amount to 2 terabytes from Ecopetrol, 1.2 terabytes from Pertamina, and huge data files related to Air Canada.
-
Experts at cyber-security recommend that companies check the accusations of extortion but also maintain security measures on their networks.

A ransomware group, Gentlemen, recently posted a huge list of their attacks on their dark web platform. The gang has allegedly targeted many corporate businesses, with a reported total of 42 victims from countries across the world, including North America, Europe, Asia, and Latin America.
The affected businesses include healthcare facilities, airlines, manufacturing companies, and universities. Cyber threat intelligence analysts emphasize that this release represents one of the largest coordinated extortion claims from the group.
Extortion Gang Targets Critical Energy Infrastructure and Global Aviation Leaders
The cybercrime collective uploaded claims targeting major energy enterprises and international airlines operating in critical economic sectors. State-owned energy companies like Colombia’s Ecopetrol and Indonesia’s Pertamina appear on the leak portal. According to the hackers, they have in their possession up to 2 terabytes of data stolen from the internal corporate systems of Ecopetrol.
Moreover, they claim they took possession of data worth about 1.2 terabytes from Pertamina. Leaked records might include HR data, employee data, and corporate banking data, tax forms, and legal documentation. The criminals also claim access to operational data linked to Supervisory Control and Data Acquisition systems.
In addition, the national airline flag carrier of Canada, Air Canada, was listed as a high-profile corporate victim. The extortion gang claims to hold over 51,000 critical files exfiltrated from internal airline server networks. Therefore, security teams are auditing enterprise connections to verify if network perimeters suffered unauthorized intrusions.
Healthcare Systems and Industrial Producers Face Severe Data Exfiltration Risks
The attack campaign of the group heavily targeted healthcare institutions and medical research facilities across several countries. American healthcare entities like AnMed and Nutex Health appear among the newly listed corporate targets. The criminals claim to have exfiltrated two terabytes of sensitive files directly from the internal networks of AnMed.
Meanwhile, German medical technology provider MedSkin Solutions Dr. Suwelack AG suffered listing on the leak site. Bulgarian pharmacy chain Apteki Mareshki and various regional clinical networks were also targets in this campaign. Thus, medical providers face severe patient privacy risks and regulatory compliance pressures following these public exposures.
Additionally, the threat actors hit industrial manufacturing companies, engineering developers, and commercial food distributors worldwide. Targeted firms include the BGR Energy Systems in India, the US builder CRB Group, and food supplier Wada Farms. Japanese industrial firms Tentac and Sarku Japan also featured on the dark web extortion portal.
Technical Double-Extortion Tactics and Operational Security Defenses
The Gentlemen group utilizes the double-extortion method to successfully carry out ransom attacks and maximize the amount of money they received from the targeted companies. Criminals infect victims with file-encrypting viruses to get access to sensitive data of the organizations.
As a result, if the victims reject the demands from the group, they suffer an additional risk besides the operational downtime. The gang can release confidential information from the victims as well.
Nonetheless, security experts stress that claims in dark web listings need independent verification from forensic investigators. Criminal hacker groups sometimes inflate claims about the number of victims or republish stolen datasets to seem more capable in their acts.
The scale of the campaign has also drawn attention from major security teams. Microsoft has warned that Gentlemen ransomware ranks among the top active threats, highlighting the group’s growing activity and the risks it poses to organizations. Despite unverified claims, affected organizations must launch incident response protocols to isolate compromised corporate servers immediately.
When implementing security measures, organizations should employ multi-factor authentication on all points of entry and remote servers. Besides, it is important for network defenders to monitor the systems continuously to detect any outflow of suspicious data.
This is critical in preventing hackers from utilizing any weakness in the network for their attacks. Keeping offline copies of sensitive data is also crucial in recovering quickly from the damage caused by malicious software.