CiberLATAMbywhalemate

The Gentlemen Hits LATAM, Brazil Victims Reported

The Gentlemen hit companies in Latin America, with confirmed victims in Brazil and public panels showing cases in Mexico.

Whalemate Labs · AI-assisted researchAug 11, 20262 min read

The Gentlemen carried out a double-extortion campaign against small and medium-sized businesses in North America, Europe and Latin America, with a notable concentration in Germany, the United States and Italy. In the region, public Ransomware.live panels record victims in Mexico, Argentina and Brazil.

The Gentlemen carried out a double-extortion campaign against small and medium-sized businesses in North America, Europe and Latin America, with a notable concentration in Germany, the United States and Italy. The sample reviewed by Security Arsenal also shows which sectors were most exposed in the activity.

Most affected sectors

Among the victim set reviewed by Security Arsenal, manufacturing and professional services were the most represented sectors. Technology and SaaS, agriculture and food, government and defense, retail, health care and uncategorized cases also appeared. That mix suggests a campaign that was not limited to a single vertical, although production and services stood out more visibly.

Likely intrusion vectors

Security Arsenal identified the most likely primary vector as abuse of perimeter devices, including VPN gateways, firewalls and remote access tools. It also pointed to a probable CVE in Check Point Security Gateway. Taken together, those elements suggest the attackers were likely looking for internet-exposed entry points before moving on to extortion.

Signals in Latin America

In Ransomware.live's public maps, Mexico recorded 283 victims and Argentina 182 victims. Global Secret Group's public dashboard also shows victims in Brazil. In that same panel, the five most common sectors are technology, retail and e-commerce, professional services, manufacturing and financial services. The presence of these cases in public dashboards places the region on the monitoring radar of several ransomware families, with a sector distribution that partially matches what was observed in The Gentlemen's campaign.

Sources

View all