Skip to content
Automated Ransomware Pipeline Exposed Amid Vexy Ransomware Attack

Automated Ransomware Pipeline Exposed Amid Vexy Ransomware Attack

First seen 15 Sep 2026, 14:26 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 15, 2026 at 14:27 UTC

An exposed server linked to The Gentlemen ransomware group revealed an automated extortion pipeline affecting around 30 companies, with 3.1TB of data exfiltrated. The AI-driven system drafted ransom demands, with costs ranging from 40 cents to four dollars per victim. The server was discovered on July 22, 2026, and was designed to exploit misconfigured GitLab instances. Meanwhile, on September 12, 2026, the Vexy Ransomware group targeted Strad Solutions, threatening to release sensitive data unless negotiations were successful. This incident highlights the growing threat of ransomware attacks on critical infrastructure providers. The attacks utilize advanced AI tools for exploitation and ransom calculations, posing significant risks to enterprise and mid-sized organizations.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2021-04-23
CVE-2021-22205 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2021-06-08
CVE-2021-22214 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2023-05-25
Public exploit for CVE-2023-2825 released
A proof-of-concept exploit appeared on GitHub, lowering the barrier for opportunistic attackers.
GitHub
2024-01-12
CVE-2023-7028 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-22
Exposed server discovered
Cybernews found a server linked to The Gentlemen ransomware group, hosting tools for automated extortion.
Idm.Au
2026-09-11
Analysis published
Cybernews published findings on the automated extortion pipeline and AI-driven ransom demands.
Idm.Au
2026-09-12
Vexy Ransomware attacks Strad Solutions
The Vexy Ransomware group claimed responsibility for a cyberattack on Strad Solutions, threatening data release.
Dexpose
2026-09-15
Current date
Ongoing negotiations are expected as Strad Solutions responds to the Vexy Ransomware threat.
Dexpose

More articles in this cluster (2)

Following this threat?

Track The Gentlemen, Strad Solutions and CVE-2021-22205 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed