Quick Summary
AllegedExecutive Summary
The Gentlemen ransomware group has claimed a data breach affecting Aware, a technology company. The incident, listed on October 3, 2026, involved the exposure of 22 customer credentials that were used to access Aware’s back-office and distributor portals. SOCRadar’s analysis of stealer logs indicates that the threat actor’s initial access and reconnaissance activities were conducted exclusively through compromised customer and distributor accounts, bypassing the need to breach internal employee credentials. This tactic highlights the increasing trend of ransomware groups targeting partner-facing systems to gain an initial foothold. The Gentleman group’s modus operandi often involves exploiting web portal authentication systems to acquire credentials. These credentials then provide access to sensitive organizational data, including client lists, commercial terms, and product configurations. The documented access period for Aware spans three months, from July to September 2026, during which the threat actor gathered intelligence before deploying a ransomware payload. This specific targeting of customer-facing portals and credentials deviates from traditional attacks that focus solely on internal employee accounts, suggesting a sophisticated understanding of a company’s broader attack surface.
Technical Analysis
SOCRadar’s investigation revealed that all 22 identified credential records associated with Aware in their stealer data logs belong to customer and distributor accounts. Crucially, no internal employee credentials were found in the queried datasets. This specific finding does not rule out a compromise of internal employee accounts through other means, but it strongly suggests that the access leveraged by The Gentlemen for their initial reconnaissance and data gathering was customer-facing. The threat actor exploited Aware’s partner-facing portal infrastructure, which includes a back-office login (login.aspx) and a distributor portal, used for product distribution. This type of infrastructure is attractive to ransomware groups as compromised customer or partner credentials can grant access to sensitive information such as client lists, commercial terms, and product configurations. The stealer logs documented access to Aware’s systems for a period of three months, from July through September 2026, indicating a sustained period of reconnaissance before the ransomware group listed the company. Given the nature of the exposed credentials and the potential access gained, Aware should conduct a thorough audit of its distributor and back-office portal access logs for the period of July through September 2026. The company should identify and notify all affected customers and distributors, immediately force-reset all portal credentials, and implement multi-factor authentication (MFA) across all partner-facing authentication systems. Additionally, session anomaly detection should be deployed. Distributor partners are also advised to review their own credential hygiene and monitor for any suspicious activity related to their Aware portal sessions.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.