Ransomware’s biggest story in the first half of 2026 was not only about established names maintaining dominance. A newer player, The Gentlemen ransomware group, emerged as one of the most geographically active operators, expanding its reach across Europe, Asia-Pacific, the Middle East & Africa, and the Americas.
According to research from Cyble Research and Intelligence Labs (CRIL), The Gentlemen became one of the top ransomware actors globally, demonstrating how quickly emerging ransomware-as-a-service (RaaS) groups can scale through affiliate-driven operations.
Unlike older ransomware brands that rely on a narrow set of preferred targets, The Gentlemen displayed a broad targeting strategy. The group impacted organizations across Manufacturing, Construction, Healthcare, Government, and IT sectors — industries where operational disruption, sensitive information, and regulatory pressure create strong incentives for victims to respond quickly.
The Gentlemen Ransomware Group Becomes a Regional Threat
The group’s strongest activity was observed in Europe and the UK, where it was responsible for 144 ransomware attacks during H1 2026. The region’s Manufacturing, Construction, Healthcare, and Professional Services sectors were among the most affected, highlighting the group’s preference for organizations with valuable data and limited tolerance for downtime.
In Asia-Pacific, The Gentlemen became the leading ransomware threat, accounting for 114 attacks — nearly one-quarter of the region’s ransomware activity. Manufacturing was among the primary targets, with additional campaigns affecting IT services, Professional Services, Healthcare, and government entities.
The group also gained significant attention in the Middle East & Africa, where it accounted for 56 attacks, representing more than 26% of ransomware incidents in the region. Construction, BFSI, and Government organizations were frequent targets, demonstrating the group’s interest in sectors linked to critical services and economic activity.

South America also saw notable activity, with The Gentlemen responsible for 46 attacks, making it one of the region’s leading ransomware operators.
Also Read: One Country Absorbed Nearly Half of the World’s Ransomware Attacks in Just Six Months – The United States
Double Extortion Remains the Core Strategy
The rise of The Gentlemen reflects a broader ransomware trend: encryption alone is no longer the primary weapon. Like most modern ransomware operations, the group relies on double extortion — stealing sensitive information before encrypting systems and using the threat of public exposure as additional pressure.
This approach allows ransomware groups to target organizations even when companies maintain effective backup and recovery capabilities. Stolen data can be leveraged for financial gain, reputational damage, regulatory pressure, or further attacks.
What Makes The Gentlemen a Growing Concern?
The group’s rapid expansion highlights the resilience of the RaaS ecosystem. Modern ransomware operations no longer depend solely on a single team’s technical capabilities. Instead, affiliates, access brokers, and specialized cybercrime services allow operators to expand quickly across industries and regions.
The Gentlemen’s activity also reinforces a key security challenge: organizations cannot rely only on historical threat rankings. New ransomware groups can rapidly become major players by exploiting exposed systems, purchasing initial access, and adopting proven extortion tactics.
For security teams, monitoring emerging ransomware operators and tracking changes in attacker behavior is becoming as important as defending against established groups.
To explore the complete ransomware landscape, including regional attack trends, targeted industries, and the activity of leading ransomware groups, download the full Cyble H1 2026 Cyber Threat Landscape Report.

