The Gentlemen ransomware gang has become the second most active group by victim count through a recruitment model that offers affiliates 90 percent of ransom proceeds. This unusually high cut incentivizes skilled operators to join the group rather than launch independent attacks or work with competitors offering lower splits.

The group's rapid rise reflects a shift in ransomware economics. Traditional operations like REvil or LockBit took years to scale. The Gentlemen compressed that timeline through aggressive hiring and a transparent profit-sharing structure that appeals to mercenary talent. Security researchers tracking the group have identified patterns in its operational behavior, victim selection, and infrastructure that suggest connections to individuals with prior ransomware experience.

Krebs on Security investigation attempts to identify the administrator running The Gentlemen infrastructure. The group's communication style, targeting preferences, and technical choices leave forensic traces. Operators often reuse pseudonyms, coding patterns, or infrastructure across multiple criminal ventures. The Gentlemen's deployment methods show similarities to other known ransomware families, suggesting the leadership may have operated prior groups or worked as high-level affiliates elsewhere.

The group primarily targets mid-market and enterprise organizations across healthcare, finance, and manufacturing. Victims receive extortion demands ranging from six to eight figures. The Gentlemen maintains a public leak site listing victims who refuse negotiation, applying pressure through data exposure threats alongside encryption attacks.

Law enforcement agencies in the US, UK, and Europe have prioritized ransomware prosecution. Identifying The Gentlemen's administrator creates actionable intelligence for sanctions, arrests, and infrastructure disruption. However, determining true identity from digital forensics remains challenging when operators employ operational security discipline.

The Gentlemen's business model demonstrates ransomware's evolution into a structured criminal enterprise with corporate-style incentives. The 90 percent affiliate payout creates a sustainability problem. As more groups adopt similar revenue