Colombia warns on Gentlemen ransomware as 30 victims land in a day

Colombia's national cyber incident response centre, colCERT, has put its highest risk rating on The Gentlemen, a ransomware-as-a-service crew that has grown in twelve months into one of the busiest extortion brands on the internet. Days after the alert went out, the group dumped roughly 30 fresh victims onto its leak site in a single day, spread across 15 countries and ranging from an Argentine crude oil pipeline operator to a fertility clinic in Austria and the Czech Philharmonic.

The warning matters beyond Colombia. The Gentlemen sells access to its encryptor to affiliates who do the breaking in, which means the volume and the targeting are effectively uncapped. colCERT's assessment is blunt: the group can go from a foothold to domain-wide encryption in minutes once it has administrator rights.

What Colombia's alert says

In its July 19 bulletin, colCERT traces the crew to July 2025 and counts more than 200 claimed victims across over 50 countries by April 2026, which research cited in the alert puts at roughly 10 percent of global ransomware volume, second only to Qilin. Some of that intelligence points to The Gentlemen having split off from Qilin itself. Affiliates reportedly keep 90 percent of each ransom, an unusually generous cut that explains how quickly the brand spread, and access to one affiliate command server is said to have exposed traces of more than 1,570 compromised organisations.

colCERT links operator aliases "hastalamuerte" and "zeta88" to the operation and notes that the group avoids targets in Russia and the Commonwealth of Independent States, a pattern that usually points to an Eastern European base. The agency is careful on attribution, flagging that the widely repeated Russian origin of a support entity called The Gentlemen Data has no independent public confirmation. The alert follows the crew's listing of Colombian state oil company Ecopetrol and a US Navy command earlier this month, covered in our report on that batch.

What the leak site showed this week

IntelFusions tracking of the group's leak site recorded about 30 entries dated July 23 and 32 over three days. Manufacturing took the heaviest hit, in line with the sector profile colCERT describes, but the spread was indiscriminate: a radiology practice in Australia, Polish logistics operator Raben Group, French food and agriculture firms, insurers in Portugal, and Argentine pipeline operator Oldelval (Oleoductos del Valle) in the energy bracket.

Treat every one of these as an unverified claim. Leak-site posts are marketing by the attackers, published to pressure a victim into paying, and only a fraction are ever confirmed by the organisations named.

How the crew gets in

The route in is almost always the edge of the network. colCERT documents systematic exploitation of Fortinet FortiGate VPNs through CVE-2024-55591, alongside stolen credentials bought from access brokers or harvested by infostealers, and brute-force attempts against SSL VPN and RDP.

Once inside, affiliates disable security software using bring-your-own-vulnerable-driver, a technique that loads a legitimately signed but flawed driver so the attacker can switch off protection from the kernel, where most defences cannot see them. The alert also records SharpADWS for Active Directory reconnaissance, credential theft from LSASS memory, SystemBC for proxying, and AnyDesk for hands-on access. The final payload is a Go encryptor using Curve25519 and XChaCha20 that runs on Windows, Linux, network storage and VMware ESXi, after volume shadow copies are deleted and database and backup services are stopped.

What you should do

Patch internet-facing Fortinet devices and treat any unpatched FortiGate as already compromised. Enforce phishing-resistant multi-factor authentication on every VPN and remote desktop entry point. Turn on Microsoft's vulnerable driver blocklist and EDR tamper protection, since the kernel-level kill is this crew's signature move. Alert on SharpADWS, SystemBC and unexpected AnyDesk installs, watch for Group Policy changes pushed through NETLOGON, and keep at least one backup copy offline and tested, because ESXi and NAS encryption is explicitly in scope.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions