Cybersecurity Research

The Gentlemen Ransomware Gang Moves Fast: What SMBs Need to Know

Sophos · 1 Sept 2026
Key Takeaway Because these attackers can move from initial access to full ransomware deployment in under a day, SMBs should enforce multi-factor authentication, harden remote access, and actively monitor for unusual administrative activity rather than relying on periodic checks.

Sophos researchers have uncovered a consistent attack pattern used by a ransomware-as-a-service operation known as The Gentlemen, run by a group tracked as GOLD SHERWOOD. The affiliates who use this service move extremely quickly once inside a network, escalating privileges and disabling security tools using legitimate software and stolen credentials, sometimes deploying ransomware within 24 hours of first gaining access.

The operation began in mid-2025 using a double-extortion model, where attackers steal sensitive data before encrypting files, then threaten to leak the data if a ransom is not paid. Victim numbers were relatively low at first, but activity surged in early 2026, with the group naming over 75 victims a month on average, up from fewer than 20 the previous year. By the end of July 2026, 683 organisations had been named on the group's leak site, with July alone accounting for 169 victims. Sophos notes that victims span a wide range of industries, suggesting the attackers target whoever they can access rather than specific sectors.

Sophos observed the first attempted deployment against one of its own customers in early 2026, and its analysis of 15 separate incidents has given researchers insight into the group's methods.

ransomware ransomware-as-a-service double extortion GOLD SHERWOOD Sophos

Summarised by CISO AI from Sophos. We link back to every original so you can read it yourself.