Tangram Interiors Data Breach

Alleged

Ransomware claim involving Tangram Interiors

Published: Jul 16, 2026 The Gentlemen
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Tangram Interiors
Industry
Business Services
Threat Actor
The Gentlemen
Date of Incident
Jul 16, 2026

Executive Summary

Tangram Interiors, a business services company based in the United Kingdom, has been identified on The Gentlemen ransomware group’s dark web portal, with the listing published on July 16, 2026. This detection was made through SOCRadar’s Dark Web Monitoring service. The organization operates within the Business Services sector, aligning with The Gentlemen’s recent activity targeting various regions and industries. The company’s data may have attracted ransomware activity due to its sector and geographic location. In the 60 days preceding this listing, The Gentlemen claimed 132 victims across its leak portal, demonstrating significant operational tempo. The group exhibits a pronounced targeting pattern within the Business Services, Manufacturing, and Healthcare sectors. Its victims are predominantly located in the United States, Germany, and France. Tangram Interiors’s profile as a UK-based Business Services organization is consistent with the group’s established targeting strategy, and similar recent listings include BRAC, BDO Greece, Lopes Law, and VASBE.

Technical Analysis

SOCRadar’s threat intelligence platform correlates initial access with stealer-log telemetry, revealing a notable exposure for the tangraminteriors.com domain. The query returned 11 records. These records primarily comprised corporate usernames listed on third-party services, rather than direct access to the organization’s internal systems. This pattern suggests potential workstation compromise and credential reuse. One corporate account was found across multiple external platforms with differing passwords, indicating a widespread risk of compromised credentials. The observed data spans from October 2025 to February 2026, suggesting that infected endpoints and unrotated credentials may be present. This timeframe implies that internal system credentials could exist outside the visible data slice, indicating a persistent risk. For ransomware operations targeting organizations like Tangram Interiors, credentials harvested by infostealers represent a well-documented initial access vector. Threat actors or initial access brokers typically source fresh credential logs from underground marketplaces. They then validate the corporate accounts and use them to gain access to systems such as Microsoft 365, VPNs, or remote-access portals, often leading to ransomware deployment. While the stealer-log evidence does not definitively confirm that these specific credentials were used by The Gentlemen, the observed pattern is consistent with the typical attack kill chain associated with these types of incidents. This exposure highlights the need for immediate attention to compromised accounts and endpoints. The observed telemetry suggests that proactive measures involving credential rotation and thorough review are critical to mitigating potential ongoing threats.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.