Quick Summary
AllegedExecutive Summary
The Gentlemen ransomware group has claimed MatTek, a manufacturing company based in the United States, as a victim. The listing appeared on the group’s dark web leak site on July 23, 2026, and was detected by SOCRadar’s Dark Web Monitoring on the same day. MatTek operates within the manufacturing sector, an industry frequently targeted by ransomware operations, potentially due to the critical nature of its operations and the potential for significant disruption. In the preceding 60 days, The Gentlemen group has listed 164 other victims, with a significant concentration in the manufacturing, business services, and healthcare sectors. The ransom group’s targeting geographically spans the United States, France, and Germany. MatTek aligns with the dominant manufacturing sector targeted by the group, joining other recent victims such as Optiforms, VPC Group (Custom Foam), Henry Frerk Sons, and Compagnie des Caoutchoucs du Pakidie, indicating a consistent pattern of targeting within this industry.
Technical Analysis
A query targeting the domain “mattek[.]com” returned no stealer-log records within the sampled data. However, it is crucial to note that this observation does not confirm the absence of a compromise. The queried data slice was limited and paginated, meaning that credentials could still exist under alternate corporate domains or through staff personal aliases that fall outside the corporate namespace of the queried domain. Therefore, the absence of evidence in this specific sample is not conclusive proof that no compromise has occurred. The typical intrusion chain for The Gentlemen ransomware involves acquiring infostealer logs to obtain fresh credentials. These credentials are then used to authenticate to various corporate access points, including Microsoft 365, VPNs, or remote-access endpoints. Following successful authentication, the ransomware is staged for deployment. While no direct evidence of this process was found for MatTek in the sampled stealer-log data, the group’s established methodology highlights a potential attack vector. Given the lack of positive signals in the immediate stealer-log telemetry and the known intrusion patterns of The Gentlemen, recommended actions include continued monitoring of stealer-log feeds for any emerging signs related to MatTek, and a thorough review of credential hygiene. This review should encompass all remote-access surfaces to ensure robust security practices are in place and to mitigate potential future threats.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.