A fast-growing ransomware operation called the Gentlemen ransomware gang has claimed more than 750 victims worldwide and is still adding new ones, according to cybersecurity firm Barracuda, which describes it as running “a professional service that rewards affiliates generously” and giving criminals multiple routes from initial access to full network disruption.
Barracuda’s research team has attributed more than 750 victims worldwide to The Gentlemen, a ransomware-as-a-service (RaaS) group in which the people who write the malware rent it out to “affiliates” who carry out the actual break-ins. It launched as an independent operation in September 2025, grew out of an earlier affiliate crew known as ArmCorp, and remained active as of 14 August 2026.
Why this matters for small businesses
The Gentlemen’s growth has not come from clever new malware. Barracuda’s analysis points to something more mundane and, for smaller firms, more relevant: exploiting unpatched or exposed edge devices, especially Fortinet VPN appliances, and using stolen or purchased login credentials to walk straight in the front door, a risk compounded by the poor scam awareness detailed in Egress’s report on staff and scam detection.
That is the same weak spot flagged in guidance on protecting a small business from automated attacks, where the advice is consistently to patch internet-facing kit promptly and never leave admin interfaces open to the public internet, alongside training staff, since research shows staff are worse at spotting scams than they think. Many SMEs run VPN appliances for remote staff access and rarely update them once they are working, a gap that IT management platforms for remote teams are designed to close.
Once inside a network, affiliates use legitimate admin tools such as PowerShell and Windows Management Instrumentation, alongside file-transfer software including WinSCP and remote-access tools such as AnyDesk, to move around and steal data before encrypting it. If your business outsources IT support, our piece on what to check when your managed IT provider is acquired covers questions worth asking about who is watching your network. Microsoft tracks the same group under the name Storm-2697. Stolen data is used for a second layer of extortion, threatening to publish it even if a ransom is paid to unlock files, a tactic known as double extortion, a risk compounded by findings that staff often overestimate their ability to spot scams. Staff awareness remains a weak link too, as shown by research into how well staff actually spot scams.
What Barracuda recommends
Barracuda’s practical advice, set out in its full write-up, is worth reading in full, but the core points for a resource-stretched SME are:
- Patch or replace ageing firewall and VPN appliances, and restrict who can reach admin interfaces.
- Turn on phishing-resistant multi-factor authentication (MFA) for remote and privileged access, and switch off dormant accounts.
- Watch for unusual use of everyday admin tools like PowerShell or remote desktop, which is often how attackers move once they are inside.
- Keep backups offline or immutable, meaning they cannot be altered or deleted, and actually test that they restore.
None of this requires enterprise budgets. It is broadly the same discipline covered in Smart SME’s operations guidance for smaller firms, and it is the kind of basic hygiene that cyber insurers increasingly ask about before they will offer cover.
What to do next
If your business runs a Fortinet VPN, a remote desktop tool, or any internet-facing admin login, check this week whether it is patched, whether MFA is switched on, and who still has access. That single review costs nothing and closes the exact door The Gentlemen has been using to get in.





