Quick Summary
AllegedExecutive Summary
Angel Hotel, a hospitality business located in the United Kingdom, was listed as a victim by the ransomware group The Gentlemen on July 30, 2026. SOCRadar’s Dark Web Monitoring identified the listing on the group’s leak site. The hospitality sector is often targeted by extortion gangs due to the sensitive nature of guest data and booking systems, which present customer-facing infrastructure that can be leveraged for attacks. In the 60 days preceding this listing, The Gentlemen claimed 175 other victims, indicating significant operational activity. The group’s targeted industries typically include Manufacturing, Business Services, and Healthcare, with a primary focus on victims in the United States, India, and France. While Angel Hotel does not align with the group’s frequent manufacturing targets, it fits a pattern of targeting businesses within the United Kingdom, similar to recent victims such as Tangram Interiors, Fortray, LogiQuip, and Integrated Distribution.
Technical Analysis
SOCRadar’s stealer-log telemetry provided a limited and ambiguous signal for the domain angelpershore[.]co[.]uk. A single credential record was found associated with the root domain. This record contained a masked username that could not be resolved to a known corporate mailbox or identity provider. The telemetry did not reveal any high-value Single Sign-On (SSO), administrative, or mail endpoints within the queried sample. Consequently, the record was classified as unclear, with the overall profile indicating insufficient data. The presence of a single, masked credential record does not allow for definitive conclusions regarding an internal compromise at Angel Hotel. Infostealer-harvested credentials are a common initial access vector for ransomware groups like The Gentlemen. Threat actors or access brokers frequently purchase such logs, validate the corporate credentials, and then attempt to gain access to systems such as Microsoft 365, VPNs, or remote-access portals before deploying ransomware. However, this isolated record neither confirms nor excludes this specific attack path for Angel Hotel. It should be treated as a potential lead requiring further investigation rather than definitive proof of exposure. Assessment: A single masked record recovered from stealer logs provides insufficient evidence to determine an internal compromise. While infostealer-harvested credentials are a known method for initial access by groups like The Gentlemen, this lone record does not confirm or deny such an intrusion at Angel Hotel. It indicates a potential lead that warrants further investigation rather than confirmed exposure. Organizations should continue monitoring for any signs of unauthorized access or credential misuse.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.