The Gentlemen has claimed over 320 victims since last summer

Check Point Research has published an incident report from a case involving an affiliate of The Gentlemen, a relatively new and widely used ransomware-as-a-service operation. Since starting up around mid-2025 the group has claimed over 320 victims, most of them in early 2026. In this campaign Check Point identified an attempt to deploy the proxy malware SystemBC, a tool several criminal actors have favoured in recent years. The investigation surfaced over 1,750 victims, mostly corporate and organisational environments worldwide, including in Sweden, Denmark, the UK and the Netherlands. Cobalt Strike was observed alongside SystemBC.

What this means for your organisation

Victims in Sweden, Denmark and the Netherlands put Norwegian organisations well inside the blast radius. Ransomware as a service means the number of actors with capability grows faster than their skill, and targeting becomes more indiscriminate; you are hit because you were reachable, not because you were interesting. For the board this comes down to how long the business can run without its core systems, and whether anyone has actually tested the answer.

Berigo recommends

  • Test restoring from backup in practice, with a stopwatch, rather than trusting that the routine exists.
  • Ensure at least one copy cannot be altered or deleted from the ordinary network.
  • Set up detection for Cobalt Strike and similar known tooling inside the network, not only at the perimeter.
  • Exercise the response plan with the management team, assuming operational systems are unavailable for several days.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch