The Gentlemen ransomware gang has become the second most prolific threat actor by victim count, leveraging an unusually generous affiliate commission structure to rapidly expand its operational capacity. The group offers affiliates 90 percent of ransom proceeds, a rate significantly higher than competitors, enabling aggressive recruitment of skilled operators into its ecosystem.
The gang's rise reflects a shift in ransomware economics. Traditional operations cap affiliate payouts at 60-70 percent. By inverting this split, The Gentlemen prioritizes speed and volume of attacks over profit maximization per incident. This strategy attracts experienced threat actors dissatisfied with established groups and creates a lower barrier to entry for emerging operators seeking affiliation.
The Gentlemen operates a double-extortion model, encrypting victim data while simultaneously threatening public disclosure of stolen files to maximize pressure for payment. The group targets organizations across multiple sectors, though details on specific compromised entities remain limited in available reporting.
Security researchers at Krebs on Security have identified forensic clues suggesting links between The Gentlemen's administrator and a real-world individual. These connections emerge from operational security lapses, communication patterns, and infrastructure reuse across known accounts. However, formal attribution remains incomplete, with investigators continuing to correlate technical indicators against known threat actor profiles.
The group's emergence underscores ongoing challenges in ransomware defense. Generous affiliate commissions create competitive pressure on ransomware economics, incentivizing more operators to participate in extortion campaigns. Organizations face escalating attack frequency as The Gentlemen scales operations through its recruitment model.
Defenders should prioritize backup segmentation, network monitoring for lateral movement, and threat intelligence consumption regarding The Gentlemen's infection vectors. Incident response teams should prepare for double-extortion scenarios where attackers demand payment to prevent data publication alongside decryption.
The Gentlemen's rapid growth demonstrates that recruitment innovation and financial
