ESB Puerto Rico Corp Data Breach

Alleged

Ransomware claim involving ESB Puerto Rico Corp

Published: Aug 30, 2026 TheGentlemen
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
ESB Puerto Rico Corp
Industry
Energy & Utilities
Threat Actor
TheGentlemen
Date of Incident
Aug 30, 2026

Executive Summary

On August 30, 2026, the ransomware group known as thegentlemen claimed to have compromised ESB Puerto Rico Corp, an energy and utilities organization operating in Puerto Rico. The group asserted unauthorized access to the company’s systems and data. SOCRadar’s CTI analysis identified stealer-log telemetry indicating a mixed exposure profile, including one employee credential, eight external records on organizational portals, and one corporate third-party credential, with timestamps ranging from August 15, 2025, to July 1, 2026. Currently, there has been no independent verification of these claims. The energy and utilities sector, along with its critical infrastructure, often presents attractive targets for ransomware operations due to the potential for significant disruption. Over the preceding 60 days prior to the claim, thegentlemen had listed 248 victims on its leak site. The group’s primary geographic targets have been the United States and the United Kingdom, with a sector focus on Manufacturing and Technology. The targeting of ESB Puerto Rico Corp, an entity within the energy and utilities sector in Puerto Rico, indicates the group’s continued expansion beyond its typical operational focus. This incident highlights the ongoing high-volume activity of thegentlemen.

Technical Analysis

SOCRadar CTI’s stealer-log analysis returned a “severe_exposure_in_sample” verdict for ESB Puerto Rico Corp. The telemetry flagged one employee credential, eight external records on organizational portals, and one corporate third-party credential. These records have timestamps spanning from August 15, 2025, to July 1, 2026, indicating a period of approximately 11 months where credential data was potentially available before the group’s public claim on August 30, 2026. The exposure of these credentials could potentially facilitate initial access for ransomware operations. The presence of employee and third-party corporate credentials suggests a risk of unauthorized access to organizational systems, potentially including Microsoft 365, VPNs, or other remote access portals. While this telemetry does not confirm a successful intrusion or data exfiltration, it establishes a clear vector for potential compromise. Given the observed credential exposure, continued dark web and stealer-log monitoring for ESB Puerto Rico Corp is recommended. Proactive credential hygiene checks, including password rotation and multi-factor authentication review, are also advised. Monitoring of alternate corporate domains and associated Microsoft 365 and VPN access logs can help detect any suspicious activity.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.