Quick Summary
AllegedExecutive Summary
The ransomware group known as thegentlemen has claimed to have breached Exacta Optech Labcenter, a technology company based in Brazil. The claim was posted on the group’s leak site on August 30, 2026. SOCRadar’s Cyber Threat Intelligence (CTI) team observed that the group asserted unauthorized access to the company’s systems and data. During their analysis, SOCRadar CTI’s stealer-log review identified two customer account-takeover records on Exacta Optech Labcenter’s shop portal, suggesting that attackers may have already been probing the company’s defenses. No independent verification of the breach claims has been completed. Over the preceding 60 days before this claim, thegentlemen had listed 248 victims on its leak site. The group’s primary geographic focus for attacks has been the United States and Great Britain, with a strong sector focus on Manufacturing and Technology. While Exacta Optech Labcenter aligns with the group’s typical targeting of the Technology sector, its location in Brazil falls outside the group’s usual geographic operational areas. This indicates thegentlemen is a highly active threat actor operating at a significant volume.
Technical Analysis
SOCRadar CTI’s stealer-log analysis for Exacta Optech Labcenter yielded a “limited_exposure_in_sample” verdict. The telemetry data identified two customer account-takeover records associated with the organization’s shop portal. Importantly, this analysis did not reveal any timestamps or direct employee credential exposure within the sampled data. The absence of employee credential exposure in this specific sample does not conclusively clear the organization of compromise. Thegentlemen could have gained access through alternative methods such as phishing campaigns, exploitation of exposed remote services, or by utilizing credentials that were not present within the analyzed dataset. The findings on the shop portal suggest potential initial reconnaissance or access vectors targeting customer data, which could indirectly impact the organization’s overall security posture. The identified customer account-takeover records on the shop portal warrant further investigation to understand the scope of potential customer data compromise and its implications. Thegentlemen’s operational pattern often involves exploiting initial access gained through various means, including compromised credentials, to achieve their objectives. Continuous monitoring of dark web forums and stealer-log feeds for any further mentions or data leaks related to Exacta Optech Labcenter is recommended. Proactive credential hygiene checks, including password rotation and multi-factor authentication review for customer-facing portals and internal systems, should be prioritized.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.