Quick Summary
AllegedExecutive Summary
Kosmos, an energy company based in Germany, was listed as a victim of the TheGentlemen ransomware group on July 7, 2026. This listing was identified by SOCRadar’s Dark Web Monitoring service. The Gentlemen ransomware group has been active, listing numerous victims, and shows a pattern of targeting the business services, manufacturing, and healthcare sectors, with a concentration of victims in the United States, Germany, and India.
Technical Analysis
SOCRadar’s analysis of stealer-log telemetry revealed a potential initial access vector for Kosmos, with 25 credential records targeting kosmos.de and its subdomains recovered. These credentials were primarily associated with consumer email providers or generic handles, suggesting a focus on external or customer accounts rather than high-value corporate credentials. While this specific exposure does not directly confirm a corporate intrusion leading to the ransomware listing, it highlights a common tactic used by ransomware groups like TheGentlemen: sourcing harvested credentials from underground markets to gain access to systems via M365, VPN, or remote-access portals. CTI teams are advised to review corporate credential hygiene and monitor for employee endpoint exposure.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.