Gentlemen ransomware ends Qilin's 13-month reign on top

A ransomware crew calling itself The Gentlemen named 178 organizations on its leak site during July, more than any other extortion gang IntelFusions tracks, and enough to end a 13 month run in which Qilin had been the busiest crew every single month.

Qilin, which has led leak site volume without interruption since June 2025, posted 127 claims over the same period. The gap itself is not enormous. The trajectory is what matters: The Gentlemen more than doubled its own output from June, when it named 76 victims, and it spread further across the map than Qilin did. The crew's July victims sat in 46 different countries, against 35 for Qilin.

An important caveat before the numbers go any further. These are claims, not confirmed breaches. Every figure here comes from posts the gangs publish on their own extortion sites, collected by ransomware.live. Crews inflate their lists, recycle old data, and sometimes invent entries outright to pressure targets into paying. A listing is not evidence that data was stolen or that anything was encrypted, and some of the organizations named will dispute the claim.

What the crew is hitting

The Gentlemen's July list looks like a spray rather than a hunt. Manufacturing was the largest single sector with 28 claims, followed by business services with 16, technology with 15 and healthcare with 12. The rest scattered thinly across agriculture, transport, construction, finance and the public sector, which is the signature of a crew taking whatever access it can buy or find rather than picking targets for leverage.

The tail end of the month brought the crew's most attention-grabbing names. Across 30 and 31 July it posted the Malaysian Nuclear Agency, Indonesia's state energy company Pertamina, Philippine Savings Bank, a US county sheriff's office in Garfield County, and municipal governments in Brazil and Peru, alongside dozens of small manufacturers and consultancies. Government, energy and banking entries sitting next to a woodwork shop is exactly what an indiscriminate affiliate operation produces.

Why the volume jumped

The most likely explanation is recruitment. The Gentlemen has been advertising unusually generous affiliate splits, reportedly as high as 90 percent, which we covered in our earlier report on the crew's affiliate terms. A better cut attracts more affiliates, and more affiliates means more victims posted. The leak site data on its own cannot confirm that causal link, but the timing fits, and a doubling of monthly output is more consistent with new people joining than with the same operators suddenly working twice as hard.

The crew's rise has already drawn official attention. Colombia's national CERT issued a public alert about the group in late July after it posted 30 victims in a single day, which we reported in our coverage of the colCERT advisory. Since IntelFusions began tracking its leak site in mid March, the crew has posted 456 claims in total.

What this means for defenders

Rankings on extortion leak sites are noisy and easy to over-read, and one strong month does not make The Gentlemen the most dangerous ransomware operation in the world. Qilin remains far larger over any longer window. What the July numbers do signal is where the affiliate labour is currently flowing, and affiliates bring their own access, their own initial intrusion habits and their own tooling with them.

Practically, that argues for the unglamorous basics rather than crew-specific detection. Mid sized manufacturers and professional services firms, the bulk of this crew's list, should assume they are in scope: enforce phishing-resistant multi-factor authentication on remote access and administrative accounts, patch internet-facing appliances and VPN gateways promptly, and keep backups offline and tested. Monitoring leak sites for your own name or your suppliers' names is worth doing, but treat a listing as the start of an investigation rather than a verdict.

Full profiles for both crews, including their tracked victim histories, are on the The Gentlemen and Qilin pages.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions