CiberLATAMbywhalemate

THEGENTLEMEN adds victims in Mexico

Security Arsenal logged 16 THEGENTLEMEN victims in 24 hours, with cases in Mexico, Brazil and Argentina and 31% in Latin America.

Whalemate Labs · AI-assisted researchPublished:2 min read

Security Arsenal said THEGENTLEMEN posted 16 organizations in a single 24-hour window, with victims in Mexico, Brazil and Argentina. The firm estimated that Latin America accounted for about 31% of those listings, while other leak-site monitoring confirmed regional cases in late August 2026, including Nutrypollo, Tecno Acción and ESB Puerto Rico.

Security Arsenal reported that THEGENTLEMEN posted 16 organizations in a single 24-hour window, with victims in Mexico, Brazil and Argentina. The firm also estimated that Latin America made up about 31% of those listings. Other leak-site monitoring confirmed regional victims in late August 2026, including Nutrypollo, Tecno Acción and ESB Puerto Rico.

What sectors appeared in THEGENTLEMEN’s campaign?

Security Arsenal said THEGENTLEMEN’s victim pool included technology, manufacturing, transportation, healthcare, energy and utilities, professional services, agriculture and food production, as well as retail and e-commerce. DarkWebSonar added more detail for some cases in the broader Latin America and Caribbean region, classifying Nutrypollo under agriculture and farming, Tecno Acción under professional technology services, and ESB Puerto Rico under automotive and industrial distribution.

What cases were confirmed in the region?

Confirmed listings in Latin America included Nutrypollo in Mexico and Tecno Acción in Argentina, with discovery or filing dates around August 28 and 29, 2026. In the case of ESB Puerto Rico, third-party coverage said the organization was listed on August 29, 2026, and that the group claimed exposure of personal data from an undisclosed number of people, without a detailed public confirmation from the company at the time of the report.

Ransomware.live also recorded Nutrypollo, Tecno Acción and Servicios Aéreos Estrella as discovered around August 30, 2026, although it estimated the attacks took place around August 28. That timeline places the ransomware execution before the leak site publication.

How does this compare with other recent campaigns?

During the same period, Security Arsenal also identified a coordinated surge by KRYBIT, which added 14 new victims in 24 hours across more than eight sectors and nine countries, including two cases in Mexico. The firm also said INCRANSOM added five new victims in 72 hours, with cases in Mexico, the United States and South Africa.

In INCRANSOM’s case, the focus was concentrated in manufacturing, energy and utilities, professional services and technology. Security Arsenal said the documented entry vector was perimeter VPN compromise through CVE-2026-50751 in Check Point Security Gateway.

Sources

View all