Argentina in The Gentlemen’s sights
The Gentlemen hit SMBs across Latin America, including a victim in Argentina. The group abused edge devices and targeted manufacturing.
Threat intelligence analysis links The Gentlemen to a double-extortion campaign against small and midsize companies in North America, Europe and Latin America. In the sample reviewed by Security Arsenal, one victim in Argentina, Vemec AR, appears in the manufacturing sector.
A threat intelligence analysis links The Gentlemen to a double-extortion campaign against small and midsize companies in North America, Europe and Latin America. In the sample reviewed by Security Arsenal, one victim in Argentina, Vemec AR, is listed in the manufacturing sector.
Access vector and sector focus
Security Arsenal attributes the activity to opportunistic exploitation of edge devices, including VPN gateways, firewalls and remote access tools. The report names CVE-2026-50751 as the most likely primary vector.
The victims identified in the analysis are concentrated in manufacturing and professional services. That pattern fits a campaign aimed at small and midsize organizations rather than large enterprises.
Ongoing pressure on Argentina
The ransomware.live map for Argentina records 182 victims in the country. At the same time, the Global Secret Group profile on the same platform shows an entry tied to Argentina with the site lasevillanita.com, estimated revenue of $15 million, industry classifications of Freight & Logistics Services and Transportation, and between 11 and 50 employees. That data is attributed to the source, but it has no independent confirmation in the material provided.
The Gentlemen’s activity has also appeared in other recent reports. Infosecurity Magazine, citing a Comparitech analysis, said The Gentlemen and Qilin together accounted for 33% of all ransomware attacks in July 2026, with 135 attacks claimed by The Gentlemen and 125 by Qilin.
ZeroFox identified the group as the most prominent ransomware and extortion collective in July 2026, with at least 125 incidents and close to 34% of the global attacks claimed by the five leading groups.
GalaxyWarden also reported that The Gentlemen posted Intranet Gov Brasil on its leak site, although at that time neither Brazilian authorities nor the organizations responsible for the portal had publicly confirmed the incident.
TechEnet, based on findings from ESET Research, said the group developed its own tools to neutralize EDR products and that its targets were in Western Europe, Southeast Asia and South America, with a visible drop in focus on the United States.
Sources
- Ransomware Surges in July After Q2 Lullinfosecurity-magazine.com· Infosecurity Magazine
- July 2026 Ransomware Wrap-Upzerofox.com· ZeroFox
- Ransomware Victims Tracking | Threat Intelligence Command ...pro.ransomware.live· Ransomware.live
- Grupo de ransomware Gentlemen desenvolve ferramentas para desativar EDRtechenet.com· TechEnetUnverified URL
- Intranet Gov Brasil Listed by The Gentlemen Ransomware Groupgalaxywarden.com· GalaxyWarden
- Group: Global Secret Grouppro.ransomware.live· Ransomware.live
- THEGENTLEMEN Ransomware Gang: 25 New Victims Posted, Sector Targeting Analysis and Detection Rulessecurityarsenal.com· Security Arsenal



