Quick Summary
AllegedExecutive Summary
TheGentlemen ransomware has listed The Sole, a UK-based footwear and lifestyle retailer, on its dark web portal on September 1, 2026. SOCRadar Dark Web Monitoring identified this listing. The company operates both online and through physical stores, making it a potential target for ransomware operations. TheGentlemen has been highly active, claiming 253 other victims in the preceding 60 days. Their targeting spans multiple sectors, including Manufacturing, Technology, and Others. The group shows a geographic preference for the United States, United Kingdom, and Germany, with The Sole’s presence in the UK aligning with this pattern. The group has previously targeted other UK-based retail and e-commerce entities, including Retail Business Management Systems, Clear Vision Signs, Northwest Trophy, and The Coffee Bean.
Technical Analysis
A query of stealer-log data for thesole[.]com returned no records within the queried dataset. It is important to note that a null result from this specific query does not confirm that the organization is unaffected by credential compromise. Exposed credentials may exist under alternate corporate domains, utilize personal email aliases, or may not have been indexed by the queried feeds yet. It is crucial to maintain vigilance. The absence of evidence in one dataset is not definitive proof of an absence of compromise. Continued monitoring of the dark web and stealer-log feeds is recommended. Furthermore, organizations should conduct proactive credential hygiene checks, including reviewing and rotating passwords, verifying multi-factor authentication configurations, and auditing logs for anomalous activity across remote access portals and Microsoft 365 services.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.