A leaked backend database tied to the ransomware group “The Gentlemen” has given researchers a rare look inside the opaque operations of an active ransomware-as-a-service crew — and handed defenders an unusually detailed map of how a modern criminal operation recruits, equips and coordinates attacks.
Researchers with Check Point Research said an internal backend system known as “Rocket” was leaked and briefly posted on underground forums in May, exposing the group’s infrastructure, affiliate roster and attack methods. For security teams, the data documents the specific vulnerabilities The Gentlemen exploit, the tools they deploy once inside a network, and the communication patterns defenders can monitor for early warning.
What made the episode unusual was what happened after the breach became public. Rather than go quiet, The Gentlemen responded the way a confident criminal enterprise would — by expanding. The group signed on as an official partner of BreachForums, a prominent cybercriminal marketplace where threat actors trade stolen data, buy network access and recruit collaborators. Researchers at Check Point interpreted the move as a signal to prospective affiliates: the operation is stable, open for business, and unbothered.
The partnership was announced May 16, less than two weeks after the group’s administrator publicly acknowledged on May 4 that Rocket had been compromised.
“It is a reputational hit, but we do not expect it to significantly disrupt their operations or reduce their effectiveness,” wrote Check Point group manager for product R&D Eli Smadja.
The leaked data revealed less a sprawling criminal enterprise than a tight, professionally run crew. Check Point researchers identified nine named core operators organized around a single administrator using the handles “zeta88” and “hastalamuerte” — a former affiliate of the Qilin ransomware group who is believed to have honed their tradecraft under an established operation before building a competing one.
Check Point said the overlap between the administrator’s activity and affiliate operations suggests the administrator participates directly in attacks, pointing to a centralized structure that belies the group’s affiliate-facing presentation.
Sizing up The Gentlemen RaaS group
The Gentlemen emerged around mid-2025 and has accumulated approximately 332 publicly disclosed victims in the first five months of 2026 alone — a figure that places it as the second most productive ransomware operation globally this year, trailing only Qilin, according to Check Point Research. The group’s data leak site lists 412 victims overall.
But both figures substantially undercount the group’s actual reach. During a prior incident response engagement, Check Point investigators accessed a live SystemBC command-and-control server tied to a Gentlemen affiliate and found a botnet of more than 1,570 likely corporate victims. As Check Point noted, publicly posted victims represent only organizations that refused to pay — the true number of compromised organizations is believed to be higher.
The group’s growth rate is equally striking. Check Point’s Q1 2026 ransomware report tracked a 315% increase in victim volume quarter-over-quarter, from 40 claimed victims in Q4 2025 to 166 in Q1 2026 — a pace that rivals the early growth of LockBit 3, widely considered the most scaled ransomware operation in the ecosystem’s history.
That growth is not incidental. According to Check Point, The Gentlemen recruits affiliates by offering a 90/10 revenue split, compared to the ransomware industry’s standard 80/20 arrangement. The more favorable payout has reportedly pulled experienced operators away from competing programs, including affiliates previously linked to Qilin. The administrator’s own career arc — from Qilin affiliate to competing operator — is a template the recruiting pitch implicitly references.
Breached internal chats cast light on TTPs
The Rocket database and accompanying internal communications exposed the group’s operational playbook. Initial access relies primarily on internet-facing edge infrastructure: VPN gateways, firewalls and management interfaces from vendors including Cisco and Fortinet. Researchers identified active discussions around CVE-2024-55591, CVE-2025-32433 and CVE-2025-33073, though Check Point noted it could not independently verify whether all compromised systems were vulnerable to those specific flaws.
Once inside a network, the group moves quickly through a documented sequence: Active Directory enumeration, NTLM relay attacks, EDR disablement, lateral movement via legitimate administrative tools, browser session harvesting targeting Microsoft 365 and Okta credentials, and data exfiltration — all before a domain-wide ransomware deployment pushed via Group Policy. Leaked screenshots from ransom negotiations showed at least one successful outcome of $190,000 after an opening demand of $250,000.
The toolset spans roughly 30 utilities. Check Point described it as mature, if not technically novel: scanners, remote access tools, bring-your-own-vulnerable-driver techniques for EDR evasion, and logging suppression via Event Tracing for Windows patching. Members have discussed more experimental applications of AI — including developing an in-house LLM-based capability for as-yet-undefined purposes — though practical limitations have slowed that work.
What is not experimental: the administrator built the group’s entire RaaS management panel in three days using AI coding assistants, specifically Chinese models DeepSeek and Qwen. The speed of that development cycle illustrates a broader trend in ransomware tooling: AI is compressing the time between concept and deployment for criminal operators as much as for defenders.
Supply chain as attack vector
Among the most significant operational findings is a documented supply chain victimization tactic with an added layer of deliberate manipulation. In April 2026, The Gentlemen breached a UK-based software consultancy, then used data stolen in that intrusion — infrastructure documentation, credentials and client access information — to conduct a follow-on attack against one of the consultancy’s clients in Turkey.
According to Check Point, the group then told the Turkish victim that the UK consultancy was the original “access broker” responsible for the intrusion, and encouraged it to pursue legal action against its own vendor. The tactic converts a single compromise into both a secondary attack and an extortion accelerant — using the victim’s own supplier as a pressure point.
Operational resilience
The breach itself appears to have prompted upgrades rather than retreat. In the same underground forum post acknowledging the Rocket leak, the administrator announced a full overhaul of the group’s communication structure, deployment of a new NAS server with expanded storage, and technical improvements to the locker, including hardware breakpoint removal, NTDLL unhooking and ETW patching.
The BreachForums partnership that followed amplifies distribution reach for leaked victim data and signals to potential affiliates that the operation is stable enough to expand its criminal business relationships under pressure.
Check Point said the group’s internal chats showed members actively studying the playbook of predecessor operations. In one exchange, members discussed ways to benefit from last year’s Black Basta leak, with particular interest in their rivals’ approach to code signing. The irony of now generating their own operational leak — and largely shrugging it off — is not lost on the researchers who analyzed it.
“A small, well-organized set of operators, supported by curated tooling, structured communication channels and up-to-date exploit knowledge, can generate substantial impact in a short time,” the Check Point team wrote.
For security teams, the behind-the-scenes look at The Gentlemen’s playbook offers a direct hardening checklist: patch internet-facing services against recently disclosed edge vulnerabilities, close known NTLM relay paths, monitor for the group’s documented tooling signatures, and treat supply chain access paths as first-order attack surfaces rather than residual risk.
The full technical analysis, including indicators of compromise, YARA detection rules and the complete affiliate TOX ID list, is available in the Check Point Research report.

Shaun Nichols is an IT news journalist. He has spent nearly 20 years covering the industry with a specialty in the cybersecurity