Ransomware Groups The Gentlemen and Gunra Intensify RaaS Operations in 2026
Article Content
- •The Gentlemen RaaS has claimed 332 victims in 2026 alone, highlighting its rapid growth.
- •Gunra ransomware has expanded its operations, adopting a business-like model for cybercrime.
- •Both groups utilize advanced tactics, including exploiting edge devices from major vendors.
The Gentlemen, a ransomware-as-a-service (RaaS) group, has emerged as a significant threat since its inception in mid-2025, with 332 reported victims in the first five months of 2026. They leverage Fortinet and Cisco edge devices for initial access. Similarly, Gunra ransomware, which transitioned from the Conti group, has expanded its operations, targeting numerous organizations and employing a business-like model that includes selling access and leaking stolen files. Both groups represent a growing concern in the cybersecurity landscape, with their operations indicating a shift towards more organized and sophisticated cybercrime. The current status of these threats is active, with ongoing attacks and recruitment efforts by both groups.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Conti and Cisco in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Iranian State Actors Deploy CHOSEN BRICK Spyware Against Dissidents On September 15, 2026, the UK, US, and Netherlands issued a joint advisory regarding a spyware campaign attributed to Iranian state actors targeting dissidents, activists, and journalists. The malware, known as CHOSEN BRICK, is delivered through spear-phishing attacks on messaging platforms like WhatsApp and Telegram.…