THEGENTLEMEN adds victims in Mexico
Security Arsenal logged 16 THEGENTLEMEN victims in 24 hours, with cases in Mexico, Brazil and Argentina and 31% in Latin America.
Security Arsenal said THEGENTLEMEN posted 16 organizations in a single 24-hour window, with victims in Mexico, Brazil and Argentina. The firm estimated that Latin America accounted for about 31% of those listings, while other leak-site monitoring confirmed regional cases in late August 2026, including Nutrypollo, Tecno Acción and ESB Puerto Rico.
Security Arsenal reported that THEGENTLEMEN posted 16 organizations in a single 24-hour window, with victims in Mexico, Brazil and Argentina. The firm also estimated that Latin America made up about 31% of those listings. Other leak-site monitoring confirmed regional victims in late August 2026, including Nutrypollo, Tecno Acción and ESB Puerto Rico.
What sectors appeared in THEGENTLEMEN’s campaign?
Security Arsenal said THEGENTLEMEN’s victim pool included technology, manufacturing, transportation, healthcare, energy and utilities, professional services, agriculture and food production, as well as retail and e-commerce. DarkWebSonar added more detail for some cases in the broader Latin America and Caribbean region, classifying Nutrypollo under agriculture and farming, Tecno Acción under professional technology services, and ESB Puerto Rico under automotive and industrial distribution.
What cases were confirmed in the region?
Confirmed listings in Latin America included Nutrypollo in Mexico and Tecno Acción in Argentina, with discovery or filing dates around August 28 and 29, 2026. In the case of ESB Puerto Rico, third-party coverage said the organization was listed on August 29, 2026, and that the group claimed exposure of personal data from an undisclosed number of people, without a detailed public confirmation from the company at the time of the report.
Ransomware.live also recorded Nutrypollo, Tecno Acción and Servicios Aéreos Estrella as discovered around August 30, 2026, although it estimated the attacks took place around August 28. That timeline places the ransomware execution before the leak site publication.
How does this compare with other recent campaigns?
During the same period, Security Arsenal also identified a coordinated surge by KRYBIT, which added 14 new victims in 24 hours across more than eight sectors and nine countries, including two cases in Mexico. The firm also said INCRANSOM added five new victims in 72 hours, with cases in Mexico, the United States and South Africa.
In INCRANSOM’s case, the focus was concentrated in manufacturing, energy and utilities, professional services and technology. Security Arsenal said the documented entry vector was perimeter VPN compromise through CVE-2026-50751 in Check Point Security Gateway.
Sources
- THEGENTLEMEN Ransomware Gang: 16 Victims Posted in 48 Hours, Sector Targeting Analysis and Detection Rulessecurityarsenal.com· Security Arsenal
- INCRANSOM Ransomware Gang: 5 New Victims Posted in 72 Hours, Manufacturing and Energy Targeting Analysis with Detection Rulessecurityarsenal.com· Security Arsenal
- Victim: Nutrypollo – thegentlemenransomware.live· ransomware.live
- Nutrypollo Listed by The Gentlemen Ransomware Groupgalaxywarden.com· GalaxyWarden
- Adkisson Group Listed by The Gentlemen Ransomware Groupgalaxywarden.com· GalaxyWarden
- Dark Web Most Wanted 2026: The Gentlemen Ransomwaredarkwebsonar.io· DarkWebSonar
- Victim: Tecno Accion – thegentlemenransomware.live· ransomware.live
- KRYBIT Ransomware Gang: 14 Victims Posted in Single-Day Surge, Cross-Sector Campaign Analysis and Detection Engineeringsecurityarsenal.com· Security Arsenal
- Known Exploited Vulnerabilities Catalog entry for CVE-2026-50751cisa.gov· CISA
- ESB Puerto Rico Ransomware Claim (2026) — What’s Alleged & Am I Affected?recentbreaches.com· RecentBreaches



