What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
An affiliate of The Gentlemen ransomware-as-a-service (RaaS) group allegedly ran a parallel leak site while extorting victims, cutting the group’s operator out of the proceeds. The available summaries attribute the allegation to cybersecurity firm CloudSEK, but the original news report and CloudSEK’s report were not available for direct review, so the payment diversion and its mechanics remain unverified.
What the reporting says happened
Infosecurity Magazine reported on October 6, 2026, that an affiliate of The Gentlemen operated a parallel leak site while extorting victims. Security Intel Hub’s summary describes two dozen victims; a Muck Rack listing for Infosecurity Magazine attributes the findings to CloudSEK and says the affiliate made off with funds extorted from over two dozen global victims. The accounts are secondary summaries and use different wording for the count, so they do not establish a more precise total. Security Intel Hub’s summary and Infosecurity Magazine’s Muck Rack listing identify the reporting and its attribution.
The Muck Rack listing names the underlying CloudSEK report as The Gentlemen Files, dated October 5, 2026, and identifies journalist Phil Muncaster as the Infosecurity Magazine author. Neither the original article nor CloudSEK report was accessible for direct inspection. Available reporting does not establish the affiliate’s identity, the precise payment flow, how the parallel site was operated, or a detailed victim list. Treat the double-cross as an allegation attributed to CloudSEK, not an independently verified account.
How an affiliate can conflict with a RaaS operator
RaaS separates the people who provide ransomware and supporting infrastructure from affiliates who use those tools to attack victims. That division can create competing interests: both parties take part in the extortion operation, while control over victim contact, data publication, and proceeds may depend on the group’s arrangements. In this case, the reported parallel leak site and diversion of funds suggest an alleged conflict, but the available summaries do not explain who controlled each step.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
A U.S. Department of Justice account of the separate LockBit case illustrates the model, not The Gentlemen’s terms. DOJ alleged that LockBit developer Dimitry Khoroshev typically received 20% of each ransom and the affiliate responsible for the attack received 80%. Those figures are specific to the LockBit allegation and cannot be applied to The Gentlemen. DOJ also said seized LockBit infrastructure allegedly showed that Khoroshev kept copies of data from victims who had paid—an example of distrust within a different operation, not corroboration of this incident. The DOJ’s May 7, 2024 release describes those allegations.
What the incident does—and does not—show
If CloudSEK’s account is accurate, the episode would show an affiliate allegedly using a parallel publication channel to pursue extortion while bypassing the RaaS operator’s interests. It does not, on the information available, establish the technical method, whether victims paid through that channel, how funds were routed, or what happened to victims’ data. Nor does it confirm that every aspect of the alleged operation followed a standard RaaS arrangement.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Ransomware groups and tactics differ. A joint advisory from the Australian Cyber Security Centre, CERT Tonga, and New Zealand’s NCSC describes INC Ransom affiliates stealing sensitive data, encrypting files, and threatening publication to pressure victims. That provides broader context for affiliate-led double extortion, but it concerns another group and does not prove The Gentlemen used the same tactics. The March 6, 2026 advisory covers INC Ransom and its recommended mitigations.
What organizations can take from the report
The reported dispute is a reminder that the criminal organizations behind an extortion attempt may not act as a unified party. For a victim, the practical priority is to preserve evidence and report the attack rather than assume that a threat, payment demand, or claimed agreement represents a stable arrangement among criminals. The available coverage does not establish incident-specific guidance from CloudSEK, so organizations should use established reporting channels and their incident-response procedures.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
In the 2024 LockBit case release, then-Deputy Attorney General Lisa Monaco urged victims to report ransomware attacks to the FBI, adding that reporting could help prevent the next attack. That is general reporting guidance, not a finding about The Gentlemen incident. The DOJ release contains her statement.
Quick Recap
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

