Close Menu
  • Home
  • Cybercrime and Ransomware
  • Emerging Tech
  • Threat Intelligence
  • Expert Insights
  • Careers and Learning
  • Compliance

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

What's Hot

Cybersecurity Breakthroughs: Factory Attacks, Encryption Hacks, and Patch Updates

May 14, 2026

The Gentlemen RaaS Boosts Power with Fortinet & Cisco Edge Devices

May 14, 2026

Linux Kernel LPE via Page Cache Corruption Exploit

May 14, 2026
Facebook X (Twitter) Instagram
The CISO Brief
  • Home
  • Cybercrime and Ransomware
  • Emerging Tech
  • Threat Intelligence
  • Expert Insights
  • Careers and Learning
  • Compliance
Home » The Gentlemen RaaS Boosts Power with Fortinet & Cisco Edge Devices
Cybercrime and Ransomware

The Gentlemen RaaS Boosts Power with Fortinet & Cisco Edge Devices

Staff WriterBy Staff WriterMay 14, 2026No Comments3 Mins Read2 Views
Facebook Twitter Pinterest LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest WhatsApp Email

Summary Points

  1. The Gentlemen, a newly emerged ransomware-as-a-service group in mid-2025, rapidly infected around 332 victims in just five months, primarily targeting Fortinet and Cisco edge devices using vulnerabilities and brute-force methods.
  2. The group operates via an affiliate model, with a 90/10 ransom split, attracting coordinated attackers who target perimeter devices, exploit known flaws, and establish long-term access through cloud tunneling before deploying ransomware.
  3. A leak of their internal database exposed operational data, revealing detailed attack workflows, negotiations, and a sophisticated double-extortion strategy involving data theft and weaponization of previous victims.
  4. To defend against The Gentlemen, organizations should focus on patching vulnerabilities, monitoring NTLM relay activity, securing Active Directory, and hardening internet-facing systems against their advanced intrusion tactics.

Key Challenge

In mid-2025, a new ransomware group called The Gentlemen emerged, rapidly transforming the cyber threat landscape. This organization operates as a ransomware-as-a-service (RaaS) platform, recruiting skilled affiliates through underground forums. Notably, its operational model favors a high payout to affiliates—90% of ransom payments—prompting many to join and escalate their attacks. By May 2026, the group’s activities had been extensive, with over 332 victims in just five months. The group primarily targets exposed network edge devices like Fortinet VPNs and Cisco systems, exploiting known vulnerabilities such as CVE-2024-55591 and CVE-2025-32433, to gain initial access. Once inside, they perform sophisticated network infiltration, exfiltrate data for leverage, and deploy custom ransomware. The group’s internal database, which was leaked online, revealed their structured organization, including their administrator, “zeta88,” who manages attacks alongside core members. Interestingly, the leak also exposed their detailed attack strategies, revealing how they coordinate and manipulate victims—sometimes turning earlier victims into leverage against new targets. This attack pattern, combined with their dual approach of data theft and ransomware deployment, signifies a dangerously advanced element in modern cyber threats. Reported by cybersecurity researchers from Check Point Research, these findings highlight the increasing need for organizations to bolster defenses, particularly by patching vulnerabilities and monitoring malicious activities like NTLM relay checks.

Critical Concerns

The issue “The Gentlemen RaaS Leverages Fortinet and Cisco Edge Devices for Initial Access” illustrates how cybercriminals exploit common network devices to break into your business. If attackers target Fortinet or Cisco edge devices, they can bypass defenses, gaining immediate entry. Consequently, your sensitive data becomes vulnerable to theft and damage. This breach not only disrupts operations but also erodes customer trust and invites costly legal repercussions. Therefore, any business relying on these devices must remain vigilant; otherwise, cybercriminals can quickly exploit weak spots, causing substantial harm to your security and reputation.

Possible Remediation Steps

Timely remediation of threats targeting ‘The Gentlemen RaaS Leverages Fortinet and Cisco Edge Devices for Initial Access’ is essential to prevent widespread network compromise, data breaches, and operational disruptions. Rapid response minimizes potential damage and restores security posture swiftly.

Mitigation Steps

  • Implement strict access controls at network boundaries.
  • Conduct regular firmware and software updates on Fortinet and Cisco devices.
  • Enable multi-factor authentication for administrative access.

Remediation Actions

  • Isolate compromised devices from the network immediately.
  • Perform thorough root cause analysis to identify exploited vulnerabilities.
  • Revoke any unauthorized credentials or access permissions.
  • Strengthen security configurations on edge devices based on best practices.
  • Notify relevant stakeholders and update incident response plans accordingly.

Advance Your Cyber Knowledge

Stay informed on the latest Threat Intelligence and Cyberattacks.

Access world-class cyber research and guidance from IEEE.

Disclaimer: The information provided may not always be accurate or up to date. Please do your own research, as the cybersecurity landscape evolves rapidly. Intended for secondary references purposes only.

Cyberattacks-V1

CISO Update cyber risk cybercrime Cybersecurity MX1 risk management
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleLinux Kernel LPE via Page Cache Corruption Exploit
Next Article Cybersecurity Breakthroughs: Factory Attacks, Encryption Hacks, and Patch Updates
Avatar photo
Staff Writer
  • Website

John Marcelli is a staff writer for the CISO Brief, with a passion for exploring and writing about the ever-evolving world of technology. From emerging trends to in-depth reviews of the latest gadgets, John stays at the forefront of innovation, delivering engaging content that informs and inspires readers. When he's not writing, he enjoys experimenting with new tech tools and diving into the digital landscape.

Related Posts

Cybersecurity Breakthroughs: Factory Attacks, Encryption Hacks, and Patch Updates

May 14, 2026

Linux Kernel LPE via Page Cache Corruption Exploit

May 14, 2026

Critical MongoDB Flaw Lets Attackers Execute Arbitrary Code

May 14, 2026

Comments are closed.

Latest Posts

Cybersecurity Breakthroughs: Factory Attacks, Encryption Hacks, and Patch Updates

May 14, 2026

The Gentlemen RaaS Boosts Power with Fortinet & Cisco Edge Devices

May 14, 2026

Critical MongoDB Flaw Lets Attackers Execute Arbitrary Code

May 14, 2026

Cybersecurity Alerts: Critical PAN-OS RCE, Water Systems Hack in Poland, Ivanti EPMM Flaw

May 13, 2026
Don't Miss

Cybersecurity Breakthroughs: Factory Attacks, Encryption Hacks, and Patch Updates

By Staff WriterMay 14, 2026

Quick Takeaways Foxconn’s North American factories were targeted by Nitrogen ransomware, resulting in data theft…

Linux Kernel LPE via Page Cache Corruption Exploit

May 14, 2026

Critical MongoDB Flaw Lets Attackers Execute Arbitrary Code

May 14, 2026

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Recent Posts

  • Cybersecurity Breakthroughs: Factory Attacks, Encryption Hacks, and Patch Updates
  • The Gentlemen RaaS Boosts Power with Fortinet & Cisco Edge Devices
  • Linux Kernel LPE via Page Cache Corruption Exploit
  • Critical MongoDB Flaw Lets Attackers Execute Arbitrary Code
  • FBI Warns of Drone, Cyber, and Real-Time Threats at World Cup
About Us
About Us

Welcome to The CISO Brief, your trusted source for the latest news, expert insights, and developments in the cybersecurity world.

In today’s rapidly evolving digital landscape, staying informed about cyber threats, innovations, and industry trends is critical for professionals and organizations alike. At The CISO Brief, we are committed to providing timely, accurate, and insightful content that helps security leaders navigate the complexities of cybersecurity.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Cybersecurity Breakthroughs: Factory Attacks, Encryption Hacks, and Patch Updates

May 14, 2026

The Gentlemen RaaS Boosts Power with Fortinet & Cisco Edge Devices

May 14, 2026

Linux Kernel LPE via Page Cache Corruption Exploit

May 14, 2026
Most Popular

Protecting MCP Security: Defeating Prompt Injection & Tool Poisoning

January 30, 202632 Views

Unlock the Power of Free WormGPT: Harnessing DeepSeek, Gemini, and Kimi-K2 AI Models

November 27, 202530 Views

The New Face of DDoS is Impacted by AI

August 4, 202527 Views

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025

Categories

  • Compliance
  • Cyber Updates
  • Cybercrime and Ransomware
  • Editor's pick
  • Emerging Tech
  • Events
  • Featured
  • Insights
  • Most Read
  • Threat Intelligence
  • Uncategorized
© 2026 thecisobrief. Designed by thecisobrief.
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions

Type above and press Enter to search. Press Esc to cancel.