Quick Summary
AllegedExecutive Summary
BRAC, a business services company based in Bangladesh, has been listed as a victim on The Gentlemen ransomware group’s dark web portal, with the listing published on July 16, 2026. This information was identified through SOCRadar’s Dark Web Monitoring service. Operating within the Business Services sector, BRAC’s inclusion on the leak site places it amongst the recent targeting activities of The Gentlemen across various regions and industries. In the 60 days leading up to this listing, The Gentlemen claimed 132 other victims. The group predominantly targets the Business Services, Manufacturing, and Healthcare sectors, with a significant concentration of victims located in the United States, Germany, and France. BRAC’s profile aligns with this pattern as a Business Services organization in Bangladesh, a situation also reflected in recent listings involving Tangram Interiors, BDO Greece, Lopes Law, and VASBE, which have similar industry and geographical overlaps.
Technical Analysis
SOCRadar’s analysis of stealer-log telemetry revealed a notable exposure for the brac.net domain, with 25 records identified against the organization’s subdomains. These records were predominantly linked to a public careers portal, but also included credentials for an SSO/identity endpoint and internal ERP systems. While no corporate email usernames were present, indicating external user accounts, the inclusion of SSO and ERP login credentials elevates the potential internal access risk beyond that of a standard customer portal compromise. The incident profile points towards customer account takeover or supplier risk, with a shared recent log date in mid-July 2026. The presence of an SSO credential, in particular, warrants further investigation to determine if the numeric handle corresponds to an employee or a privileged account. For ransomware groups like The Gentlemen, credentials harvested by infostealers serve as a well-documented initial access vector. Threat actors or initial access brokers acquire these logs from underground marketplaces, validate the corporate credentials, and then leverage them to gain access to systems such as Microsoft 365, VPNs, or remote-access portals before deploying ransomware. Although the stealer-log evidence does not definitively confirm that The Gentlemen used these specific credentials, the observed pattern is consistent with the typical kill chain for such incidents. Consequently, the exposed accounts and affected endpoints should be prioritized for immediate rotation and comprehensive review.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.