CiberLATAMbywhalemate

Argentina in The Gentlemen’s sights

The Gentlemen hit SMBs across Latin America, including a victim in Argentina. The group abused edge devices and targeted manufacturing.

Whalemate Labs · AI-assisted researchPublished:Updated 3 min read

Threat intelligence analysis links The Gentlemen to a double-extortion campaign against small and midsize companies in North America, Europe and Latin America. In the sample reviewed by Security Arsenal, one victim in Argentina, Vemec AR, appears in the manufacturing sector.

A threat intelligence analysis links The Gentlemen to a double-extortion campaign against small and midsize companies in North America, Europe and Latin America, with one victim in Argentina, Vemec AR, which Security Arsenal classifies in the manufacturing sector.

What access vector did the campaign use?

Security Arsenal attributes the activity to opportunistic exploitation of perimeter devices, including VPN gateways, firewalls and remote access tools.

The report cites CVE-2026-50751 as the most likely primary vector.

Which sectors were hit most often?

The victims observed in the analysis are concentrated in manufacturing and professional services.

That pattern matches a campaign aimed at small and midsize organizations rather than large corporations.

What does the monitoring show about Argentina and the regional scope?

The ransomware.live map for Argentina records 182 victims in the country.

At the same time, the Global Secret Group profile on the same platform shows an entry tied to Argentina with the site lasevillanita.com, estimated revenue of $15 million, the Freight & Logistics Services and Transportation industries, and between 11 and 50 employees.

That data is attributed by the source, but it is not independently confirmed in the material provided.

The Gentlemen’s activity has also appeared in other recent reports.

Infosecurity Magazine, citing a Comparitech analysis, said The Gentlemen and Qilin together accounted for 33% of all ransomware attacks in July 2026, with 135 attacks claimed by The Gentlemen and 125 by Qilin.

ZeroFox identified the group as July 2026’s most prominent ransomware and extortion collective, with at least 125 incidents and about 34% of attacks worldwide among the five leading groups.

GalaxyWarden also reported that The Gentlemen posted Intranet Gov Brasil on its leak site, although Brazilian authorities and the organizations responsible for the portal had not publicly confirmed the incident at that time.

TechEnet, based on findings from ESET Research, said the group developed its own tools to disable EDR products and that its targets were in Western Europe, Southeast Asia and South America, with a visible decline in focus on the United States.

Sources

View all