The Gentlemen ransomware lists Colombia's Ecopetrol and a US Navy command

The Gentlemen, one of the fastest growing ransomware crews of 2026, has added two of its most strategically significant names yet to its extortion site: Colombia's state owned oil company Ecopetrol and the United States Navy's Military Sealift Command. Both organizations were posted to the group's data leak site this week, and IntelFusions has seen no confirmation from either that a breach actually occurred. These are unverified extortion claims, not established facts.

What The Gentlemen posted

Ecopetrol appeared on the leak site on July 19, described by the attackers using text lifted from the company's own corporate profile. Ecopetrol is Colombia's largest company and its national energy champion, and through its subsidiary Cenit it controls most of the country's crude and multi purpose pipelines along with export ports at Coveñas, Cartagena and Tumaco. Two days earlier, on July 17, the crew listed Military Sealift Command, the civilian crewed fleet that fuels, supplies and transports cargo for the U.S. Navy around the world. Neither listing was accompanied by published data samples or technical indicators, so the scope of what, if anything, was taken cannot be assessed.

Part of a wider surge

The two entries sit inside a burst of activity. Between July 16 and July 19 The Gentlemen posted 23 victims across 14 countries, most of them small and mid sized manufacturers, professional services firms and local businesses in Europe, Japan, Taiwan and the Americas. IntelFusions covered the crew's single day dump of nearly 20 victims earlier this week. What sets Ecopetrol and Military Sealift Command apart is target value: a national critical infrastructure operator and a military logistics command are a sharp step up from the group's usual roster.

Why this crew is scaling so fast

The Gentlemen (also tracked as Storm 2697) is a relatively young ransomware as a service operation that has grown quickly by recruiting affiliates with unusually generous terms, including rare 90 percent payout splits that undercut established rivals. That affiliate driven model helps explain both the volume and the geographic spread of its claims. You can follow the group's full activity on its IntelFusions threat actor profile.

What defenders should take from this

Appearing on a leak site names a target but does not prove a breach, its scale, or that any stolen data is genuine, and ransomware crews routinely inflate or recycle claims to pressure victims and attract affiliates. Treat both listings as unverified until the named organizations or their governments say otherwise. Energy operators in Latin America (see our Colombia cyber profile) and defense supply chain organizations should nonetheless read this as a reminder that they sit squarely in scope: harden internet facing systems, keep offline and tested backups, enforce phishing resistant multi factor authentication, and watch leak sites for early mention of their own name so they learn of a claim before their customers do.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions