Mesto Celakovice Data Breach

Alleged

Ransomware claim involving Mesto Celakovice

Published: Jul 16, 2026 The Gentlemen
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Mesto Celakovice
Industry
Business Services
Threat Actor
The Gentlemen
Date of Incident
Jul 16, 2026

Executive Summary

Mesto Celakovice, a manufacturing company based in the Czech Republic, has been listed as a victim on The Gentlemen ransomware group’s dark web portal, with the listing published on July 16, 2026. This discovery was made through SOCRadar’s Dark Web Monitoring service. Operating within the Manufacturing sector, Mesto Celakovice is now included among The Gentlemen’s recent leak-site activities, which have impacted various regions and industries. The organization’s presence in the European manufacturing landscape could potentially attract such cybercriminal activities. In the 60 days leading up to this listing, The Gentlemen ransomware group claimed 132 other victims through its leak portal. The group has demonstrated a consistent focus on the Business Services, Manufacturing, and Healthcare sectors, with a significant concentration of victims located in the United States, Germany, and France. Mesto Celakovice’s profile aligns with this pattern, being a manufacturing organization situated in the Czech Republic. Similar recent victims listed by The Gentlemen that share a sector or geographic overlap include Giraudi Group, Tooltec, ALUFE Femszerkezeti Kft, and Dash Door Glass.

Technical Analysis

SOCRadar’s analysis of its stealer-log telemetry revealed a potential credential exposure related to the celakovice.cz domain. Across the queried data, 24 records were identified associated with the organization’s public-facing web properties. These included records for a CMS administration endpoint and a library catalogue system. However, none of these records were classified as corporate employee credentials. The majority of the exposed credentials appear to pose a risk of external user account takeover. The discovered records span a significant period, from June 2024 to April 2026, indicating a persistent, multi-year credential harvesting effort against these public services. The exposure of credentials for the CMS admin path is particularly noteworthy, as compromised accounts with elevated privileges could enable content modification on the website. For ransomware adversaries like The Gentlemen, credentials harvested by infostealers are a well-established method for gaining initial access. Threat actors or initial access brokers frequently acquire fresh credential logs from underground marketplaces. They then validate these credentials and use them to gain unauthorized access to systems such as Microsoft 365, VPNs, or remote-access portals, ultimately leading to the deployment of ransomware. While the current stealer-log evidence does not definitively confirm that these specific credentials were exploited by The Gentlemen, the observed pattern is consistent with the typical intrusion kill chain associated with such incidents. Consequently, the exposed accounts and related endpoints should be considered high-priority targets for immediate credential rotation and thorough security review. The evidence suggests a persistent risk of account takeover and potential unauthorized access to Mesto Celakovice’s digital assets.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.