07/08/2026
A ransomware group called "The Gentlemen" is one of the fastest-growing names in cybercrime right now. You probably haven't heard of them.
In April 2026, The Gentlemen accounted for roughly 10% of all logged ransomware attacks worldwide and climbed into the top three most active ransomware operations, alongside Qilin and DragonForce. One of their named victims that month was Adaptavist, an Atlassian platinum partner that serves thousands of business customers.
This shift matters because the names you might already know are out of the picture. LockBit, Conti, REvil, and Hive are all gone or rebranded after law enforcement crackdowns and infighting. The replacements use different aliases but the same tactics: phishing, credential theft, vulnerable VPN appliances, and unpatched servers. They encrypt your data and steal a copy to threaten you twice.
The good news is that the defense looks the same regardless of which group is hitting your industry. Five things work against all of them: patching CISA KEV systems within two weeks, MFA with number matching on internet-facing systems, immutable offsite backups that you actually test, security tools that watch for behavior instead of relying on known viruses, and phishing training that covers 2026 forms like QR codes, voice cloning, and fake CAPTCHA pages.
You can't keep up with which ransomware group is hot this month, and you don't have to. The defenses that work today will still work when The Gentlemen rebrand into something else next year.
Every Region Recorded Higher Attack Volumes in April In April 2026, global cyber-attack activity rebounded sharply following the brief moderation observed Global cyberattacks rose 10% in April 2026 as ransomware expanded and GenAI risks persisted. See key trends across sectors, regions, and industri...