The Gentlemen, one of the two busiest ransomware operations of 2026, has added Charles & Keith to its data-leak site. The Singapore-born shoe and handbag brand is one of the best-known Asian fashion names internationally, so a confirmed breach there could reach customers well beyond Singapore.
The listing was first recorded on 26 September 2026 at 08:43 UTC by the independent tracker ransomware.live, which logs posts on extortion sites. Its victim page for the claim gives an estimated attack date of 24 September, two days before the post appeared.
A claim, not a confirmed breach
Everything here comes from the attackers. Ransomware crews post victims to pressure them into paying, and they sometimes exaggerate, recycle old data, or name companies they only touched at the edges. The Charles & Keith entry carries a profile of the company and its domain, charleskeith.com, but the tracker records no stated data volume and no sample files. IntelFusions found no public statement from Charles & Keith about a cyber incident at the time of writing, so none of this should be read as proof that customer data was taken.
What the listing does show is that the gang has chosen to name the brand publicly, a step crews typically take when negotiations have stalled or never started.
The Gentlemen keeps returning to Singapore
This is not a one-off for the city-state. Our own incident data counts 34 leak-site claims against Singapore-based organizations in the last 90 days, and The Gentlemen and Qilin account for seven each, more than any other crew. The Gentlemen's earlier Singapore entries were mostly small technology and services firms, among them aZaaS, Pro-Tech Technology and Technical Asia, plus an alumni club. Charles & Keith is by far the most recognisable name it has posted from the country.
The crew itself has been prolific, with 97 claims across all countries in our data over the past 30 days. Researchers at Sophos have described affiliates that move from break-in to encryption within about two days, and earlier this month the same leak site carried a claim of 51,409 stolen Air Canada files. The group's profile is on our The Gentlemen actor page, and Singapore's wider threat picture is on the Singapore country page.
Infostealer exposure sits in the background
The same ransomware.live page carries infostealer data from Hudson Rock. It counts 129 employees and 3,486 users linked to the brand's domain whose credentials have turned up in infostealer logs, the troves of passwords and session cookies harvested from infected personal and work computers. Stolen logins like these are a common way into corporate networks, but the numbers describe exposure over time. They do not show how, or whether, this particular intrusion began.
Change reused passwords and watch for fake Charles & Keith messages
Until the company says more, customers with a Charles & Keith online account should change that password, and change it anywhere else it was reused. Be wary of emails, texts or calls that mention an order, a refund or a data incident and ask you to click a link or confirm payment details, since publicised leak claims are routinely followed by phishing that borrows the brand's name. For the company, the immediate question is whether the claim reflects a real intrusion, and if personal data was involved, Singapore's Personal Data Protection Act requires notifying the regulator of breaches that are likely to cause significant harm or that affect 500 or more people.
Whether this listing proves to be a serious breach or an overstated boast, it marks a shift in who The Gentlemen is willing to name in Singapore, from firms few readers would recognise to a household retail brand.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.