The Gentlemen Ransomware Overtakes Qilin as Top Cyber Threat

The ransomware ecosystem has undergone a significant power shift in 2026. A relative newcomer known as The Gentlemen has dethroned the long-dominant Qilin operation to become the most prolific ransomware threat actor tracked by cybersecurity researchers, signaling a new phase in the industrialization of cyber extortion.

According to analysis published on July 16, 2026, by cybersecurity firm ReliaQuest, The Gentlemen ransomware gang was responsible for 300 confirmed incidents between March and May 2026 alone, surpassing Qilin’s 289 incidents during the same period. The findings are based on victim claims tracked across data leak sites operated by eleven distinct ransomware groups.

The Numbers Behind the Shift

The ReliaQuest report paints a picture of a rapidly consolidating and highly competitive ransomware landscape. Key findings from the analysis include:

  • 1,368 total victim claims were tracked across 11 ransomware groups during the three-month window.
  • Victims were spread across 99 countries, underscoring the borderless nature of the threat.
  • The Gentlemen and Qilin accounted for nearly 43 percent of all claimed attacks combined.
  • Other notable groups—DragonForce, Akira, and LockBit—each accounted for between 100 and 150 incidents, well behind the top two.

The significant gap between the top two operators and the rest of the field suggests that ransomware-as-a-service (RaaS) is increasingly a winner-take-most market, where affiliates gravitate toward the operations offering the best tooling, support, and payout structures.

Why The Gentlemen Rose So Fast

The speed at which The Gentlemen overtook established operators like Qilin has drawn attention from defenders and rival criminal groups alike. According to Tristano Di Liberto, security analyst at ReliaQuest, the group’s rapid ascent is driven by three converging factors:

1. Aggressive Affiliate Recruitment

The Gentlemen has actively courted affiliates from competing operations, offering favorable revenue splits and streamlined onboarding. This recruitment strategy has pulled experienced operators away from Qilin and other legacy groups, effectively transferring both talent and attack volume to the new platform.

2. A Pre-Packaged Intrusion Kit

Unlike many RaaS operations that provide only the encryptor and a support channel, The Gentlemen supplies affiliates with a comprehensive intrusion playbook. This resource includes:

  • Guidance on which edge devices to target for initial exploitation.
  • Instructions for deploying lightweight tunneling tools to route traffic through command servers.
  • Procedures for executing single-host Server Message Block (SMB) encryption to maximize damage with minimal noise.
  • A documented attack chain and workflow that lowers the technical bar for new operators.

By commodifying the entire intrusion process, The Gentlemen has dramatically reduced the time and expertise required for a new affiliate to begin conducting successful attacks.

3. AI-Accelerated Development Pipeline

Perhaps the most consequential differentiator is the group’s use of artificial intelligence to accelerate malware development. Leaked chat logs suggest that The Gentlemen harnesses AI tools to speed up the creation of new versions of their ransomware offering, iterating faster than rival groups that have not integrated AI into their build pipelines.

This AI advantage has two compounding effects: it allows the group to ship updates and patches to affiliates faster than competitors, and it enables rapid adaptation to defensive countermeasures deployed by security vendors. As Di Liberto noted, the operation runs proven affiliate throughput, ships tools faster than most rivals through its AI-accelerated build pipeline, and offers a pre-packaged intrusion kit that shortens ramp-up for new operators.

The Broader Ransomware Market in 2026

The Gentlemen’s rise is not an isolated event—it reflects broader structural changes in how ransomware operates as a criminal industry. The division of labor has deepened considerably, with specialized Initial Access Brokers (IABs) selling pre-verified network access to ransomware affiliates, effectively decoupling the breach from the extortion. This compressed pipeline means the window between initial compromise and encryption is now measured in hours rather than weeks.

Simultaneously, the dominant extortion model has evolved beyond simple encryption. Many groups now employ multi-extortion tactics that layer additional pressure on victims:

  • Data theft and public leakage threats: Stolen data is published on shaming sites if ransoms go unpaid.
  • Direct harassment: Affiliates contact a victim’s clients and partners to apply external pressure.
  • DDoS disruption: Distributed denial-of-service attacks crash public-facing services, making the victim’s inability to respond visible to the broader market.

This multi-layered approach makes refusal to pay increasingly costly, even for organizations with robust backup and recovery capabilities.

Defensive Recommendations from Researchers

ReliaQuest has urged cybersecurity leaders to adopt a resilience-first posture in response to the evolving threat. Their specific recommendations include:

  • Restrict RDP and remote access: Limit exposure of remote desktop protocols to only essential users and enforce multi-factor authentication on all remote entry points.
  • Enforce Microsoft’s vulnerable-driver blocklist: Many ransomware operations exploit legitimate but vulnerable signed drivers to escalate privileges and disable security tooling.
  • Monitor blockchain RPC and session messenger egress: Track unusual outbound traffic to blockchain endpoints and encrypted messaging platforms, which are commonly used for command-and-control and ransom negotiation.
  • Harden identity against vishing and Adversary-in-the-Middle (AiTM) attacks: Deploy phishing-resistant authentication methods and monitor for session token theft, which remains a primary initial access vector for ransomware affiliates.

These measures address the most common intrusion paths that affiliates of The Gentlemen and comparable RaaS operations exploit during the initial access and privilege escalation phases of an attack.

What Comes Next

ReliaQuest analysts expect The Gentlemen to maintain pressure through at least the third quarter of 2026, warning that the group’s combination of AI-accelerated tooling and aggressive affiliate recruitment creates a compounding advantage that is difficult for slower-moving rivals to counter. There is also concern that the group’s success could trigger a competitive response from Qilin and other displaced operators, potentially leading to an escalation in attack volume as groups fight to retain affiliate loyalty.

For organizations, the takeaway is clear: the ransomware threat is not static. The groups behind it are actively innovating, leveraging AI, and professionalizing their operations to a degree that rivals legitimate software companies. Defensive postures must evolve at the same pace, shifting from perimeter-focused strategies to identity-centric, resilience-first architectures that assume breach is inevitable and focus on limiting blast radius and accelerating recovery.


Palawan Footer: This article was produced by the QUE.com editorial team in partnership with Palawan. For more insights into the future of digital security and technology, visit our resource center.


Edited by Palawan @QUE.COM
Website: https://QUE.COM Intelligence
Sponsored by: https://MAJ.COM AI Autonomous


Discover more from QUE.com

Subscribe to get the latest posts sent to your email.

Leave a Reply

Discover more from QUE.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from QUE.com

Subscribe now to keep reading and get access to the full archive.

Continue reading