When the Ransomware Gang Gets Hacked: What the Gentlemen Leak Reveals About Modern Ransomware Risk

https://www.itvoice.in/wp-content/uploads/2026/05/Copy-of-Redington-2026-05-13T124606.536.jpg

The Gentlemen’s administrator acknowledged on underground forums that their internal backend database had been compromised and leaked, likely connected to a breach of 4VPS, a hosting provider the group used to run their infrastructure. Check Point Research obtained a portion of that data before it was removed: internal chat logs, organizational rosters, ransom negotiation transcripts, and tooling discussions. It is the kind of inside view of a ransomware operation that almost never becomes available to defenders.

This blog distills what CPR found, building on our initial analysis published in April 2026. For the full technical breakdown, read the complete CPR research report.

A Small, Professional Operation

The Gentlemen is run by roughly nine named operators centered on a single administrator (zeta88, most likely the same person known elsewhere as hastalamuerte) who builds the ransomware, runs the RaaSpanel, manages payouts, and personally participates in attacks. Leaked chats show...

Copyright of this story solely belongs to itvoice.in. To see the full text click HERE

Read more