SYS::ONLINE
Wasteland.
Briefs1666
Issues21
SinceFeb 2026
LIVE
█ Ransomware PERTAMINA-THEGENTL 2026-08-02

Pertamina: TheGentlemen Ransomware Leak Site Claim

"On July 31, 2026, the ransomware-as-a-service operation TheGentlemen (tracked by Microsoft as Storm-2697) added Indonesian state-owned energy major Pertamina to its dark web leak site, claiming to have exfiltrated more…"

On July 31, 2026, the ransomware-as-a-service operation TheGentlemen (tracked by Microsoft as Storm-2697) added Indonesian state-owned energy major Pertamina to its dark web leak site, claiming to have exfiltrated more than 1.2TB of internal corporate data. The listing includes screenshots and a partial file tree but no proof of the full dataset. Pertamina has not publicly confirmed an intrusion, issued a breach notification, or acknowledged the claim as of this writing, per GalaxyWarden. At this stage the incident rests entirely on the threat actor's own assertions, and readers should treat volume and content claims accordingly.

What Happened

Threat intelligence monitoring picked up the listing on July 31. UnderCode News, citing observations by the ThreatMon Threat Intelligence Team, reports that TheGentlemen posted Pertamina and US-based Peachtree Group to its leak portal within minutes of each other that day. DeXpose logged the same listing with a July 31 report date and reproduced the actor's full statement verbatim.

Accounts differ on one basic detail. DeXpose's incident table lists Pertamina's country as Singapore, while the actor statement quoted inside that same DeXpose entry describes Pertamina as "Indonesia's state-owned integrated energy corporation," and GalaxyWarden identifies the victim as Indonesian state-owned. The weight of evidence, including the actor's own text, points to Indonesia; the Singapore field appears to be an error in the aggregator's metadata.

On volume, the two sources that quote the listing directly both say more than 1.2TB (roughly 1,200GB), which is consistent with, though larger than, the "over 1TB" figure circulating in early summaries. The listing does not specify when the intrusion occurred or how initial access was obtained, and no independently verified technical evidence confirming the scope of compromise has been published.

What Was Taken

According to the leak site text reproduced by DeXpose and GalaxyWarden, TheGentlemen claims to hold:

The actor also cites Pertamina's $23.2 billion revenue figure and links to a ZoomInfo company profile, a boilerplate pressure tactic used across its listings to signal ability to pay.

The SCADA reference is the line that matters most. If genuine, documentation describing industrial control system architecture at an integrated energy operator spanning upstream, downstream, gas, and renewables is materially more dangerous than a conventional HR dump. It is also exactly the kind of claim a double-extortion crew has an incentive to inflate. Neither source has verified the SCADA claim independently, and no sample has been reviewed publicly.

Why It Matters

TheGentlemen is not a fringe actor. Kaspersky's Securelist team assesses that the group ranks among the top 10 ransomware actors by victim announcements in the first half of 2026, and has been tracking it since February 2026 as it targets large corporations and critical infrastructure worldwide.

Reported victim totals vary widely by source and by counting method. Palo Alto Unit 42 counts 580 claimed victims across 77 countries through July 3, 2026, with 103 in manufacturing, and reports a "slightly more than 6x" increase from H2 2025 to H1 2026 (via CTIPilot's summary of the Unit 42 profile). ShellCodeX's tracker puts the figure at over 320 victims across 17-plus countries, and notes that a compromised C2 server in 2026 revealed more than 1,570 linked victims, a number that likely includes intrusions never posted publicly. IntelFusions documented a single-day batch of 41 organizations across 18 countries on July 1, 2026, including Spanish technology group Indra and Taiwanese retailer Pou Sheng International.

Origin dating also varies: Unit 42 puts activity "since at least July 2025," ShellCodeX says July-August 2025, and Securelist notes its initial assessment of mid-2025 but says the group only truly ramped up at the start of 2026.

The economics explain the pace. Unit 42 assesses that roughly 20 operators shifted from a private crew to a RaaS model around September 2025, having previously worked as "ArmCorp," an affiliate of Qilin. They now offer affiliates an unprecedented 90% cut of paid ransoms against a typical 70-80%, and in May 2026 announced a recruiting partnership with HasanBroker's BreachForums to pull in more affiliates and initial access brokers. That payout is a talent magnet, and the July 1 mass listing suggests recent public exposure has done nothing to slow the group down.

The Attack Technique

No source describes how Pertamina specifically was breached. The group's established playbook, however, is well documented by two primary-tier vendor sources.

Unit 42 and Securelist both report that initial access typically comes from exploiting internet-exposed edge infrastructure, especially hardware VPNs and firewalls, alongside brute force, leaked or default credentials, and collaboration with initial access brokers. CTIPilot's summary of the Unit 42 profile notes the access set now explicitly includes Erlang/OTP SSH server and Windows SMB client flaws alongside the previously tracked FortiOS and FortiProxy path.

For tooling, the group runs encryptors written in both C and Go, covering Windows, Linux, NAS, and BSD systems and virtual infrastructure. Unit 42 documents a custom Go-based backdoor, an EDR killer framework dubbed "GentleKiller," and a suspected zero-day used specifically to disable EDR agents, distinct from the BYOVD-based GentleKiller tooling. Securelist has published previously undescribed reconnaissance and network sniffing techniques used by the group.

One nuance from Securelist is worth carrying: while the group often deploys ransomware within hours of gaining access, analysis of several attacks found cases where access predated deployment by a long stretch, using tactics atypical for the group. Kaspersky's assessment is that in those cases the original breach may have been executed by a separate actor or broker, and TheGentlemen simply bought the way in.

ShellCodeX maps the group's ATT&CK coverage to include Valid Accounts and Exploit Public-Facing Application for initial access, PowerShell and WMI for execution, Group Policy modification and Impair Defenses for evasion, OS Credential Dumping and Brute Force for credential access, and RDP, SMB, and SSH for lateral movement.

What Organizations Should Do

  1. Audit and patch internet-facing edge devices first. FortiOS and FortiProxy, Erlang/OTP SSH servers, and any VPN or firewall management interface exposed to the internet are the group's documented entry points. Confirm no admin plane is reachable from the public internet.
  2. Eliminate default and reused credentials on edge infrastructure, and enforce phishing-resistant MFA on all remote access. Valid Accounts is the group's most-used initial access technique.
  3. Instrument for EDR tampering, not just EDR alerts. Given GentleKiller and the suspected EDR-disabling zero-day, treat an agent going silent as a high-severity detection in its own right. Alert on driver loads, service stops, and unexpected Group Policy changes.
  4. Segment IT from OT and inventory where ICS and SCADA documentation lives. Engineering drawings and control system documents stored on general-purpose file shares are the reason a corporate-side intrusion becomes an operational risk.
  5. Hunt for dwell time, not just deployment. Because access is often brokered well before encryption, retrospective hunts for RDP, SMB, and SSH lateral movement, credential dumping, and domain trust discovery may surface a foothold that predates any ransom note.
  6. Monitor leak sites and criminal forums for your own name and credentials. A listing is often the first public indication of a larger event, and early notice buys time for containment and regulatory preparation.
  7. Prepare communications in advance. Pertamina's silence is a reminder that unconfirmed claims still create reputational and regulatory pressure from day one.

A leak site listing is a claim, not a confirmed breach, as IntelFusions notes in its own coverage of the group. Some listings reflect real intrusions, others recycle old data or overstate access. Until Pertamina responds or files are published, the correct posture is heightened alert, not conclusion.

Sources: TheGentlemen Ransomware Attack on Pertamina: Significant Data Breac... | No Manners Here: The Ruthless Rise of The Gentlemen Ransomware | The Gentlemen RaaS: rapid growth and a new ransomware variant Secu... | Pertamina Listed by thegentlemen Ransomware Group | TheGentlemen Ransomware Expands Its Reach, Pertamina and Peachtree... | Thegentlemen Ransomware Group: Victims, TTPs and Activity ShellCodeX | The Gentlemen (Storm-2697) status update — Unit 42's full profile:... | Gentlemen ransomware crew names 41 victims in a single day IntelFu...