Gentlemen RaaS Claims 1TB Exfil from TKMS/Atlas Elektronik; Leaked Samples Show SeaFox Drone and Scout MkII Sonar Schematics
The Gentlemen ransomware group listed ThyssenKrupp Marine Systems (TKMS) and its Atlas Elektronik subsidiary — a NATO navy sonar and combat systems supplier — on its leak portal in late June, claiming over 1TB of exfiltrated data. TKMS confirmed a breach isolated to a North American subsidiary supporting U.S. military work, stating no classified data was compromised, but the group subsequently posted screenshots appearing to show proprietary PCB layouts for the Scout MkII side-scan sonar and technical manuals for the SeaFox mine-disposal UUV. Gentlemen is now the second-most-active RaaS group in 2026 by victim count, behind Qilin, with 330–580 claimed victims across 70+ countries.
Gentlemen is now the second-most-active RaaS group in 2026 by victim count, behind Qilin, with 330–580 claimed victims across 70+ countries.
This intelligence brief has been compiled from open-source reporting and corroborated across multiple threat intelligence sources. Defenders should treat the high severity rating as a guide to prioritization within their environment.
For the latest indicators of compromise, formatted SIEM queries, and unredacted actor intelligence related to this brief, DMZ Operator subscribers receive automated IOC packages via email the moment new advisories are published.