London / Tel Aviv: A highly sophisticated new cybercriminal network known as “The Gentlemen” has officially become the fastest-growing ransomware-as-a-service (RaaS) group in recorded history, terrifying global IT administrators and corporate boards alike.
According to a joint threat-intelligence report released this week by Check Point Research and Microsoft Security, the group successfully executed 182 major corporate attacks in the first quarter of 2026 alone—a staggering 420% increase from the previous quarter. The group’s success is driven by its aggressive business model, offering rogue hackers (“affiliates”) an unprecedented 90% share of extorted ransom revenues.
🔴 Exploiting the Governance Gap
Unlike previous state-sponsored groups that relied on complex, zero-day code, “The Gentlemen” are thriving by exploiting basic corporate negligence.
Recent investigations reveal the group is successfully breaching massive enterprise networks by targeting infrastructure that companies simply forgot to patch:
- Legacy Vulnerabilities: The group is actively exploiting a two-year-old flaw in Oracle WebLogic servers (CVE-2024-21182), taking advantage of the fact that many massive corporations simply haven’t updated their middleware since 2024.
- The Return of USB Drives: In a shocking twist, hackers affiliated with Russian state-sponsored groups are successfully using infected USB drives and outdated WinRAR software to bypass modern cloud-security perimeters, proving that physical security protocols are failing globally.
DuniKa Times Takeaway: The cybersecurity threat landscape is evolving faster than corporate defenses. Companies can no longer rely purely on automated firewalls; they must urgently audit their legacy systems, personal employee devices, and physical hardware policies before they become the next victims of “The Gentlemen.”