Glassdoor Data Breach

Alleged

Ransomware claim involving Glassdoor

Published: Aug 30, 2026 TheGentlemen
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Glassdoor
Industry
Technology
Threat Actor
TheGentlemen
Date of Incident
Aug 30, 2026

Executive Summary

The ransomware group known as thegentlemen has claimed Glassdoor, a prominent US-based technology platform, as a victim. The claim, which appeared on the group’s leak site on August 30, 2026, alleges unauthorized access to Glassdoor’s systems and data. While SOCRadar’s CTI analysis has been initiated, no independent verification of the breach has been completed at this time. The nature of Glassdoor’s operations, involving extensive user data and a significant online presence, potentially makes it an attractive target for ransomware and extortion campaigns. The thegentlemen group has been exceptionally active, listing 248 victims in the preceding 60 days, placing it among the most prolific ransomware operators currently tracked. Their primary targeting has been concentrated in the United States and the United Kingdom, with a strong focus on the Manufacturing and Technology sectors. Glassdoor’s profile as a major technology platform aligns directly with the group’s established sector and geographic focus, suggesting a pattern consistent with their typical operational strategy.

Technical Analysis

SOCRadar CTI’s stealer-log analysis returned a “limited_exposure_in_sample” verdict for Glassdoor. The analysis identified 25 records that consisted entirely of consumer email addresses. This suggests a potential profile of customer account takeovers rather than employee credential exposure. Crucially, no timestamps were found to place these records within a specific compromise window, and no direct employee credentials were observed in the analyzed data. It is important to note that this limited result does not definitively clear Glassdoor of a compromise. The thegentlemen group may have obtained unauthorized access through alternative methods not captured by this specific stealer-log analysis. These methods could include phishing campaigns or the exploitation of exposed remote services, such as VPNs or other access portals, which would not be reflected in the stealer-log data. Continued dark web and stealer-log monitoring is recommended, along with proactive credential hygiene checks, password rotation, and multi-factor authentication review for all corporate accounts.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.