Optiforms Data Breach

Alleged

Ransomware claim involving Optiforms

Published: Jul 23, 2026 The Gentlemen
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Optiforms
Industry
Business Services
Threat Actor
The Gentlemen
Date of Incident
Jul 23, 2026

Executive Summary

The Gentlemen ransomware group has claimed Optiforms, a U.S.-based manufacturing company, as a victim. The listing appeared on the group’s dark web leak site on July 23, 2026, and was flagged by SOCRadar’s Dark Web Monitoring on the same day. This incident places Optiforms within a broad pattern of criminal activity that has impacted numerous organizations. This incident is one of 164 victims attributed to The Gentlemen over the last 60 days. The ransomware group frequently targets the manufacturing, business services, and healthcare sectors, with a majority of their victims located in the United States, France, and Germany. Optiforms aligns with the group’s typical targeting of the manufacturing industry, appearing alongside other recent victims such as MatTek, VPC Group (Custom Foam), Henry Frerk Sons, and Compagnie des Caoutchoucs du Pakidie.

Technical Analysis

SOCRadar’s analysis of stealer-log telemetry did not yield any positive records for optiforms[.]com. It is crucial to note that a lack of positive findings does not definitively indicate that an organization is unaffected. The performed query was based on a bounded, paginated sample, and there is a possibility that credentials could exist under alternative corporate domains or be associated with staff personal email aliases that do not directly resolve to the primary corporate domain. Therefore, the absence of matching records should be interpreted as no positive signal rather than confirmation of no compromise. The Gentlemen, like many other ransomware operations, commonly leverages infostealer logs as a vector for initial access. The typical workflow involves purchasing recent logs, validating corporate credentials, and then gaining access to systems via platforms such as Microsoft 365, VPNs, or remote-access portals, from which ransomware is deployed. The current telemetry does not directly link Optiforms to this specific initial access pathway. Given the findings, the recommended course of action includes continued monitoring of the dark web and stealer-log feeds, alongside proactive credential hygiene reviews. This proactive approach can help mitigate potential risks and provide early indicators of further compromise attempts.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.