CiberLATAMbywhalemate

Mercado Libre listed by The Gentlemen in July 2026

The Gentlemen listed Mercado Libre on its leak site in July 2026. Exfiltration signs emerged, but no public proof of operational impact.

Whalemate Labs · AI-assisted researchJul 20, 202638 min read

On July 6 and 7, 2026, multiple monitoring services and cybersecurity outlets recorded Mercado Libre’s inclusion on the The Gentlemen leak site. The most repeated timeline places the initial posting on July 6 and the public discovery on July 7, with references to internal files allegedly exfiltrated and threats to release sensitive data if negotiations did not follow. At the same time, several reports said the company had not publicly confirmed an intrusion, there was no public evidence of large-scale impact, and Mercado Libre, Mercado Pago, and other services were still operating normally at least through July 9.

The available material lets us map the case timeline fairly well, but not its full technical scope. No public disclosure identified the ransomware family used, the initial access vector, the affected systems, or a set of samples or forensic indicators that would independently validate the true volume of the leak. Even so, the activity fits a broader pattern already seen in other victims attributed to The Gentlemen: leak site publication, extortion pressure, little or no public proof, and a narrative centered on data theft more than visible encryption.

The actor profile is better documented than the specific incident. Ransomware.live describes The Gentlemen as a ransomware-as-a-service operation that emerged in 2025, with affiliate revenue shares of up to 90 percent and a Go-based locker capable of affecting Windows, Linux, NAS, and BSD. In 2026, several public investigations also said the group suffered a leak of its Rocket backend, including thousands of internal messages, operator accounts, victim details, infrastructure data, and EDR evasion tools. That matters because it suggests the operation remained active despite the exposure of its own infrastructure.

For the region, the case matters because Mercado Libre is a dominant commerce, payments, and logistics platform across Latin America. Even without a public confirmation of severe operational impact, the appearance of a company of that size on a leak site creates reputational pressure, forces reviews of access controls, segmentation, monitoring, and exfiltration response, and shows that extortion crews still target companies with large attack surfaces and deep dependence on digital services.

Executive summary

Mercado Libre was added by The Gentlemen to its leak site between July 6 and July 7, 2026, according to multiple monitoring services and specialized coverage. The most consistent sequence is this, the actor posts or claims the case on its leak site on July 6, and on July 7 different automated platforms record it as a victim while the public narrative of internal file exfiltration and extortion spreads.

The strongest element in the record is not a forensic confirmation of intrusion, but the overlap among independent monitors that tracked Mercado Libre’s appearance on the group’s portal. Ransomware.live sets an estimated attack date of July 6 and discovery on July 7. Breach House, RecentBreaches, Galaxy Warden, and Dexpose all match on the company name being published by The Gentlemen and on the group’s threat to leak sensitive data if negotiations did not happen. That timing convergence supports the existence of an extortion campaign aimed at the company, even if it does not answer the main technical question about the real scope.

At the same time, several threat intelligence reports and news outlets said there was no public evidence of service disruption or of a fully verified successful intrusion, at least through July 9, 2026. Fortuna y Poder, Rankiteo, WCYB Digital Radio, and other reports said Mercado Libre, Mercado Pago, and related services were still operating normally, and that the company itself had not issued a public statement confirming a ransomware breach or leak. The material attributes to Mercado Libre an initial assessment saying passwords, balances, investments, financial information, and credit card data would not have been compromised, but that claim appears through secondary coverage rather than an independent published forensic audit.

The lack of public samples, hashes, access vectors, or a confirmed malware family limits any categorical claim about the type of intrusion. Samithota.com summed it up clearly on July 10, neither The Gentlemen nor Mercado Libre had disclosed key technical details about the alleged attack. In other words, what can be verified is the leak site listing, the extortion threat, and the group’s continued public activity, not the full anatomy of the initial access.

The context matters because The Gentlemen is not a marginal actor. Ransomware.live describes it as a RaaS operation born in 2025, with revenue shares of up to 90 percent for affiliates and a Go locker capable of encrypting Windows, Linux, NAS, and BSD environments. In 2026, public research also documented the leak of its Rocket backend, including thousands of internal messages, operator accounts, victim records, and evasion tools such as EDRStartupHinder and gfreeze. That points to an active group that can still sustain large-scale campaigns and relies on data extortion as an operational model.

For Latin America, the case stands out because of Mercado Libre’s profile, described in the material as the region’s leading e-commerce and fintech platform, with Mercado Pago and Mercado Envíos as key ecosystem components. Even without a public confirmation of severe operational impact, exposing an actor of that size on a leak site raises reputational risk, increases the chance of brand fraud and credential reuse, and signals that extortion crews continue to aim at companies with large attack surfaces and cross-service dependence.

Cronología del caso Mercado LibreHitos entre mayo y julio de 2026 sobre The Gentlemen y Mercado Libre.Mercado Libre case timeline2026-05-04LeakedbackendRocketinternal2026-06-22CSA publishestechnicaldetails2026-07-06Mercado Libreenters the leak2026-07-07Monitoringconfirms listing2026-07-09They continueserviceswithoutoutages

Mercado Libre case timeline — From The Gentlemen's backend leak to the victim's posting and lingering technical questions.

Context and background

The Gentlemen appears in the material as a ransomware-as-a-service operation that emerged between July and August 2025. Ransomware.live attributes to it an affiliate model with revenue sharing of up to 90 percent, a Go-written locker, and the ability to operate across multiple platforms, Windows, Linux, NAS, and BSD. That combination does not describe an improvised actor, but a structure trying to scale quickly through affiliates and tooling that can adapt to heterogeneous corporate environments.

The group’s own infrastructure suffered a major exposure in May 2026. Mallory.ai, Cloud Security Alliance Labs, Privacy Insight Solutions, InCyber, and Cybersecurity News all agree that the internal Rocket backend and its chats were leaked. The numbers vary by source, but the overall picture is consistent, internal messages, operator accounts, affiliate IDs, victim records, bitcoin wallets, technical tools, and operational artifacts were exposed. At the broadest level, that means the campaign against Mercado Libre happened after the group had already lost significant secrecy and still continued to operate publicly.

That point is central to interpreting the case. Cybersecurity News and other sources explain that, despite the Rocket leak, The Gentlemen kept operating and even announced improvements to its locker to make detection harder, including NTDLL unlinking, hardware breakpoint removal, and ETW patching. InCyber adds that in 2026 the group promoted data-theft-only extortion, offering affiliates up to 97 percent of revenues without needing to encrypt systems. That fits a trend in which attacker value comes from both theft and reputational pressure, not necessarily from visible endpoint encryption.

Mercado Libre is, for its part, an obvious target surface for an extortion operation. Galaxy Warden describes it as the leading e-commerce platform in Latin America, founded in 1999 and backed by an ecosystem that includes Mercado Pago and Mercado Envíos. Breach House reinforces that characterization and presents it as an Argentine company leading regional e-commerce and fintech. From the attacker’s standpoint, an organization with multiple business lines, strong public exposure, and broad operational dependence is a valuable target for extortion pressure, even if no deep operational compromise has been publicly demonstrated.

The case also has to be read against the group’s public behavior. IntelFusions reported that The Gentlemen named 41 organizations in a single day on its leak site, without any of them publicly confirming an incident at the time. That points to an aggressive publication strategy, with volume and visibility as core goals. In that frame, the Mercado Libre listing can be seen as another piece of a broader campaign, where the portal post serves as pressure, signaling, and possible monetization of exfiltrated data.

The geographic reach of the activity widens the context further. Ransomware.live says the group had claimed more than 320 victims across at least 17 countries by mid-2026, and more than 1,570 victims linked through compromise of its C2. Scrutex also identified The Gentlemen as the most active actor in the week under review in mid-July, with 40 posts in four days. Mercado Libre therefore appears not as an isolated event, but as part of a wider and more mature offensive.

Perfil operativo de The GentlemenMatriz con rasgos confirmados del grupo The Gentlemen.Operational profile of The GentlemenModelRaaS with affiliatesUp to 90% of revenueEmerged in 2025PlatformsWindows, LinuxNAS and BSDGo-based lockerTechniquesGentleKiller EDRETW, NTDLLHW breakpointsEscalation320+ victims1,570+ linked40 posts / 4 days

Operational profile of The Gentlemen — Condensed view of the actor, its RaaS model, tooling, and extortion pattern.

Key facts table

Date Event Source Confidence
2026-07-06 The Gentlemen adds Mercado Libre to its leak site and threatens to release sensitive data if there is no negotiation. Dexpose Confirmed
2026-07-06 Breach House lists the case as a ransomware attack against Mercado Libre. Breach House Confirmed
2026-07-06 RecentBreaches and Galaxy Warden record Mercado Libre’s inclusion and the claim of internal file exfiltration. RecentBreaches, Galaxy Warden Confirmed
2026-07-06 BreachSense classifies the incident as a data breach against mercadolibre.com.ar. BreachSense Confirmed
2026-07-06 HookPhish and HackerFeeds assign a breach date to the case, with automated discovery on July 7. HookPhish, HackerFeeds Attributed by source as uncertain
2026-07-07 Ransomware.live sets discovery of the listing and an estimated attack date of July 6. Ransomware.live Confirmed
2026-07-07 Scrutex says Mercado Libre was listed without sample data. Scrutex Confirmed
2026-07-07 PwdFortress says, citing coverage and initial claims, that the exposure reached about 300,000 users. PwdFortress Attributed by source as uncertain
2026-07-08 Rankiteo reports that MercadoLibre.com remained operational with no visible interruptions. Rankiteo Confirmed
2026-07-09 Fortuna y Poder reports no public evidence of a successful intrusion or operational impact. Fortuna y Poder Confirmed
2026-07-09 WCYB Digital Radio says Mercado Libre had not publicly confirmed the breach. WCYB Digital Radio Confirmed
2026-07-10 Samithota notes that key technical details of the attack had not been disclosed. Samithota Confirmed
2026-07-13 IntelFusions reports 41 victims named by The Gentlemen in a single day. IntelFusions Confirmed
2026-07-13 Ransomware.live describes The Gentlemen as RaaS with more than 320 claimed victims and more than 1,570 linked victims. Ransomware.live Confirmed
2026-07-16 InCyber and Galaxy Warden show the prior exfiltration-first pattern in other cases attributed to the group. InCyber, Galaxy Warden Confirmed

Operation timeline

Date Event Actor/vector Verified source
2026-05-04 The Gentlemen’s internal Rocket backend is leaked, including chats, accounts, and operational artifacts. Group infrastructure compromise Mallory.ai, Cloud Security Alliance Labs
2026-05-08 Privacy Insight Solutions reports free publication of the leaked dataset after an earlier sale. Internal communications exposure Privacy Insight Solutions
2026-06-20 NetSecOps describes the use of GentleKiller to weaken defenses before encryption. EDR killer and security evasion NetSecOps
2026-06-22 Cloud Security Alliance Labs publishes details of the Rocket dump and GentleKiller. Defensive intelligence on the group Cloud Security Alliance Labs
2026-06-28 The Gentlemen claims a case against TKMS/Atlas Elektronik with a large volume of exfiltrated data. Leak site, exfiltration pressure Dataminr
2026-07-06 The Gentlemen lists Mercado Libre and threatens to publish sensitive data. Leak site, public extortion Dexpose, Breach House, Galaxy Warden
2026-07-06 Monitoring services record Mercado Libre’s inclusion and describe it as a data breach or ransomware attack. Breach monitoring BreachSense, HookPhish, RecentBreaches
2026-07-07 Ransomware.live marks discovery of the listing and estimates the attack date. Victim aggregator Ransomware.live
2026-07-07 Scrutex reports that the entry did not include sample data. Campaign tracking Scrutex
2026-07-08 Rankiteo observes that MercadoLibre.com continues operating without visible interruption. Secondary coverage Rankiteo
2026-07-09 Fortuna y Poder and WCYB say there was no public confirmation of the breach and that service continued. Regional and broadcast coverage Fortuna y Poder, WCYB Digital Radio
2026-07-10 Samithota confirms the lack of key public technical data. Technical advisory Samithota
2026-07-13 Ransomware.live and Scrutex contextualize the scale of The Gentlemen’s campaign. Threat intelligence Ransomware.live, Scrutex
2026-07-16 Parallel cases such as Brac reinforce the exfiltration and extortion pattern. Operational comparison Galaxy Warden

Attack chain and TTPs

The technical chain visible in the material is incomplete, but enough to infer an operational pattern. The first block is publication or claim on the leak site, paired with a threat to disclose sensitive data. That already places the case in data extortion territory, even if there is no public evidence of effective encryption. The second block, when it appears, is the claim of exfiltrated internal files. That detail repeats across several reports on Mercado Libre and other cases attributed to the same group.

What does not appear, at least not publicly and in verifiable form, is the initial access vector. There is no confirmation of phishing, exploitation of a vulnerability, stolen credentials, third-party access, or lateral movement documented for this case. Nor is there a ransomware family attributed with independent validation. Any reading of the full sequence therefore has to stay at the level of hypotheses supported by the actor’s broader behavior, not proven fact.

The material does support the view that The Gentlemen operates with a double or single extortion model centered on data theft. InCyber says the group promoted 2026 campaigns offering affiliates up to 97 percent of revenues without needing to encrypt systems. That is consistent with the absence of public evidence of operational disruption at Mercado Libre. In other words, the incident may have been focused on theft and pressure rather than visible technical unavailability.

The group’s defensive infrastructure also forms part of its TTPs. NetSecOps and Cybersecurity News describe GentleKiller as a module used to terminate EDR and antivirus processes, weaken detection, and blind security tools before the encryption and extortion phase. Cybersecurity News adds that the group announced technical improvements to its locker, including NTDLL unlinking, hardware breakpoint removal, and ETW patching. There is no published forensic link showing that those capabilities were used specifically against Mercado Libre, but they help explain the adversary’s maturity.

At the target level, the pattern is aggressive and high volume. Ransomware.live and Scrutex show a campaign with more than 320 claimed victims, more than 1,570 linked through a compromised C2, and 40 posts in four days during the week of July 12. That suggests a high-cadence operation with heavy reliance on the leak site as a mechanism for validation, negotiation, and coercion.

TTP Description Source
Leak-site extortion Publishing the victim’s name and threatening to release sensitive data. Dexpose, RecentBreaches
Prior exfiltration Internal files are reported to have left before the public pressure. Galaxy Warden, RecentBreaches
Pressure without samples Several reports note no sample data was posted. Scrutex, Rankiteo
RaaS with affiliates The group shares revenue with affiliates and scales through distributed operations. Ransomware.live
Go-based locker Multi-environment capability across Windows, Linux, NAS, and BSD. Ransomware.live
EDR killer GentleKiller aims to terminate EDR and antivirus before encryption. NetSecOps, CSA Labs
Advanced evasion Techniques such as NTDLL unlinking, ETW patching, and breakpoint removal. Cybersecurity News
Data-based extortion The group pushes campaigns without needing visible encryption. InCyber
Cadena probable de presiónFlujo de extorsión observado para Mercado Libre y el patrón de The Gentlemen.Likely coercion chainUnverified accessNon-public vectorExfiltrationInternal filesLeak sitePosting and pressureNegotiationThreat of leakingImpactReputation
Likely coercion chain — Observed flow in the case and the group’s operating pattern, with limits due to lack of primary forensics.

Regional impact

Regional picture

Mercado Libre is a highly central asset in the Latin American digital ecosystem. The material describes it as the region’s leading e-commerce and fintech platform, integrated with payments and logistics. For that reason, the appearance of the case on The Gentlemen’s leak site goes beyond a possible isolated breach and becomes an event of regional interest. Even without public confirmation of service outage, the mere labeling of a company of that size affects risk perception in Argentina and in markets where the brand operates across multiple business lines.

The most important regional point is not a service outage, but the combination of three elements, first, the victim’s publication on the group’s site, second, the lack of public samples that would let analysts measure the scope, and third, Mercado Libre, Mercado Pago, and other services appearing to continue operating in the following days. That triangle suggests an operation aimed at extraction and pressure, with possible impact on reputation, trust, and incident handling rather than visible platform continuity.

It is also relevant that the case received coverage from Latin American and international outlets with different emphases. Some stress the leak site listing and internal file exfiltration. Others stress the absence of public proof of a successful intrusion. PwdFortress, meanwhile, introduces figures attributed to specialized coverage about possible source code access and data tied to about 300,000 users, but those figures still depend on secondary reporting rather than a primary forensic publication. The correct regional reading is therefore cautious, there is a claim of breach and extortion pressure, but no strong public validation of the full damage.

Argentina

Argentina is where the case is most firmly anchored. Ransomware.live, Breach House, RecentBreaches, Galaxy Warden, Dexpose, HackerFeeds, BreachSense, Rankiteo, Fortuna y Poder, WCYB Digital Radio, and Samithota all converge on Mercado Libre being listed by The Gentlemen between July 6 and July 7, 2026. The cited domain is mercadolibre.com.ar and the business context is clear, an Argentine company with continental reach and deeply integrated payments, commerce, and logistics services.

The tension between the public claim and the lack of operational verification is the key feature of the case in Argentina. Fortuna y Poder reported that as of July 9 there was no public evidence of a successful intrusion or operational impact, and that the company had not issued an official statement confirming ransomware or a leak. Rankiteo reinforced the same idea by saying the website was still operating without visible disruption. That does not rule out access or exfiltration, but it does lower the likelihood of a broad and visible disruptive impact in the short term.

At the same time, the historical profile of the case in RecentBreaches classifies it as high severity and describes it as internal file exfiltration. That classification, while not forensic proof, reflects how the breach monitoring ecosystem was treating the event in real time. The mix of leak site activity, no public samples, continued service, and possible partial source code leakage sketches a risk scenario where confidentiality and reputational pressure matter more than visible downtime.

Mercado Libre, Mercado Pago, and Mercado Envíos are especially sensitive because a partial intrusion can enable fraud, social engineering, abuse of operational information, or reuse of internal artifacts in later campaigns. The material does not show that this happened, but it does show that the actor was trying to monetize the exposure of high-value assets.

United States

In the United States section of the material, there is no new U.S. victim tied to the Mercado Libre case. What does appear are multiple sources, including Breach House, RecentBreaches, Ransomware.live, Galaxy Warden, PwdFortress, Fortuna y Poder, Rankiteo, Scrutex, Cybersecurity News, and WCYB Digital Radio, all with international circulation or reach, that help reconstruct the chronology and framing of the incident. That matters because the case did not stay in local media, it was quickly absorbed by global threat intelligence aggregators and outlets.

The U.S. ecosystem also contributes the broader victimology narrative around The Gentlemen. IntelFusions reported 41 victims in a single day. Cybersecurity News described 1,570 victims linked through the compromised C2. Dataminr, although covering TKMS/Atlas Elektronik, shows the same operational pattern of leak-site claims, high-volume exfiltration, and then a contrast with the victim’s response. All of that reinforces the reading of Mercado Libre as part of an international pressure campaign, not a standalone local-market case.

No additional verifiable facts were identified for Chile, Paraguay, Bolivia, Peru, Colombia, Brazil, or Mexico in the material provided.

Technical indicators

No verifiable technical IOCs were published for this case in the consolidated material. There are no hashes, IPs, command-and-control domains, malware paths, samples, or specific signatures tied to the Mercado Libre incident that were confirmed by a primary source in the research. That absence is also an operational finding, because it limits retrospective detection based on indicators and pushes defenders toward behavior-based telemetry, access logs, and exfiltration correlation.

The closest thing to an indicator is the affected domain, mercadolibre.com.ar, but that identifies the victim and is not a usable IOC for defense. As a result, any hunting or detection effort should rely on actor behavior patterns, such as leak-site posts, extortion threats, possible presence of EDR evasion tooling in affected environments, and unusual outbound data events.

Evidencia pública disponibleComparación de elementos confirmados y no confirmados para Mercado Libre.Public evidence availableItemLevel of public confirmationListed on leak siteConfirmed by multiple sourcesInternal exfiltrationReported, no primary forensicsInitial vectorNot disclosedEffective encryptionUnconfirmedOperational impactNo visible outages

Public evidence available — What is publicly confirmed and what remains unverified by independent forensics.

Analysis for security teams

The case leaves a fairly concrete technical lesson, when a ransomware group posts a victim on its leak site without backing the claim with public samples, the event should not be dismissed as noise, but it also should not be treated as proof of total compromise. The right response is to assume an intermediate scenario, possible partial or full exfiltration, verify unauthorized access, review authentication logs, correlate endpoint activity, and validate data egress during windows close to July 6 and 7, 2026.

In an organization like Mercado Libre, or in companies with a similar footprint, the focus should be on three layers. The first is identity, reviewing privileged accounts, tokens, sessions, remote access, MFA, and service credentials. The second is exfiltration detection, with monitoring for anomalous egress, after-hours compression and transfer, unusual channels, and correlation with file activity. The third is operational resilience, segmentation, the ability to isolate environments, pipeline integrity checks, and protection of secrets, source code, and internal repositories.

The material also points to a reading of the actor. The Gentlemen seems to favor data extortion and public victim visibility more than destruction or visible mass encryption. That means impact should not be measured only by availability. A company can keep operating normally and still have suffered exposure of code, internal chats, user records, or operational artifacts. That is exactly the gray zone these groups exploit.

The Rocket backend leak from the group itself is a useful defensive input. The volume of messages, the exposure of tools such as EDRStartupHinder and gfreeze, and the description of GentleKiller as an EDR killer can be used to strengthen behavioral hypotheses, not as literal IOCs but as guidance for technique-based detection. In corporate environments, teams should review alerts for abnormal security process termination, ETW tampering, NTDLL manipulation, suspicious process creation, and sudden changes in endpoint visibility.

From a prioritization standpoint, the threat ranks high for reputational impact and high for secondary abuse if internal data or source code were actually exfiltrated. If the information cited by PwdFortress and other outlets about roughly 300,000 users were confirmed, the risk of fraud, targeted phishing, and abuse of support information would be material. But until that is validated by a primary source or forensic investigation, the most responsible posture is to work from the minimum verifiable assumption, there was a public leak site listing, extortion pressure, and no official technical details.

Material limitations

The main limitation is the lack of an independent forensic confirmation of the intrusion’s scope and vector. The material does not provide a validated technical chain showing how entry occurred, which systems were compromised, how long the attackers stayed inside, or what data was actually exfiltrated. The public evidence centers on the leak site and breach aggregators, not on a post-incident investigation published by the victim.

There are also no data samples, hashes, command-and-control domains, IP addresses, file names, or exploitable artifacts. That prevents the building of concrete IOCs. Likewise, claims about source code access, user data, and possible impact on about 300,000 users appear in secondary articles and are marked in the material itself as derived from press reports and initial statements, not from an independent forensic audit.

The timeline is highly consistent across sources, but not all timestamps mean the same thing. Ransomware.live, Breach House, RecentBreaches, HookPhish, and HackerFeeds work with discovery and publication windows, not the forensics time of initial compromise. That difference matters, because the date a victim appears on a leak site does not prove the exact moment of access or the size of the theft.

Finally, the available material does not let us confirm whether there was encryption, whether the incident was limited to exfiltration, or whether it involved both. The absence of sample data and the apparent continuity of services suggest a pressure-and-leak event more than a visible operational disruption, but that inference remains provisional.

Sources

View all