The Gentlemen Targets Edge Devices
The Gentlemen hit LATAM companies, with confirmed victims in Brazil and new reports pointing to edge device abuse.
The Gentlemen ran a double-extortion campaign against small and midsize companies in North America, Europe and Latin America, with a notable concentration in Germany, the United States and Italy. The sample analyzed by Security Arsenal also shows which sectors were most exposed in that activity.
Update August 21, 2026: Help Net Security added that The Gentlemen has been focusing its intrusions on edge devices as the initial entry vector before moving laterally inside corporate networks. That finding reinforces the earlier hypothesis that the group has been abusing VPN gateways, firewalls and remote access tools, with a marked impact on industrial and manufacturing environments.
The Gentlemen ran a double-extortion campaign against small and midsize companies in North America, Europe and Latin America, with a notable concentration in Germany, the United States and Italy. The sample analyzed by Security Arsenal also shows which sectors were most exposed in that activity.
Which sectors were most exposed?
In the victim set reviewed by Security Arsenal, manufacturing and professional services were the most represented sectors. Technology and SaaS, agriculture and food, government and defense, retail, healthcare and uncategorized cases also appeared. That distribution points to a campaign that was not limited to a single vertical, although production and services companies stood out more clearly.
How did the attackers get in?
Security Arsenal attributed the most likely primary vector to abuse of edge devices, including VPN gateways, firewalls and remote access tools. It also flagged a likely vector tied to a CVE in Check Point Security Gateway. Taken together, those elements suggest the attackers were looking for internet-exposed entry points before moving on with extortion.
Help Net Security went further and said The Gentlemen has centered its intrusions on edge devices as the initial foothold, before laterally moving through corporate networks. The outlet distinguished that approach from other ransomware groups, such as Akira, which mainly rely on compromised VPNs. That pattern reinforces the importance of edge-exposed systems as a key TTP for the group.
What signals appeared in Latin America?
In the public maps on Ransomware.live, Mexico recorded 283 victims and Argentina 182 victims. The public dashboard from Global Secret Group also shows victims in Brazil. In that same panel, the five most common sectors are technology, retail and e-commerce, professional services, manufacturing and financial services. The presence of these cases in public dashboards places the region within the monitoring scope of several ransomware families, with a sector mix that partially matches what was seen in The Gentlemen's campaign.
Sources
- THEGENTLEMEN Ransomware Gang: 25 New Victims Posted, Sector Targeting Analysis and Detection Rulessecurityarsenal.com· Security Arsenal
- CISA, FBI and Partners Detail Gunra Ransomware Tacticsexecutivegov.com· ExecutiveGov
- Ransomware.live 👀pro.ransomware.live· Ransomware.live
- US and South Korea warn of Gunra ransomware attacks against govt agenciesbleepingcomputer.com· BleepingComputer
- Bitdefender Threat Debrief | August 2026bitdefender.com· Bitdefender
- Group: Global Secret Grouppro.ransomware.live· Ransomware.live
- Ransomware gangs don't need control system access to disrupt industrial operationshelpnetsecurity.com· Help Net Security
- Ransomware.live 👀pro.ransomware.live· Ransomware.live
- «The Gentlemen»: Kaspersky alerta sobre su expansión en ransomwareinfosertecla.com· Infosertecla



