Quick Summary
AllegedExecutive Summary
The Gentlemen ransomware group has claimed Optiforms, a U.S.-based manufacturing company, as a victim. The listing appeared on the group’s dark web leak site on July 23, 2026, and was flagged by SOCRadar’s Dark Web Monitoring on the same day. This incident places Optiforms within a broad pattern of criminal activity that has impacted numerous organizations. This incident is one of 164 victims attributed to The Gentlemen over the last 60 days. The ransomware group frequently targets the manufacturing, business services, and healthcare sectors, with a majority of their victims located in the United States, France, and Germany. Optiforms aligns with the group’s typical targeting of the manufacturing industry, appearing alongside other recent victims such as MatTek, VPC Group (Custom Foam), Henry Frerk Sons, and Compagnie des Caoutchoucs du Pakidie.
Technical Analysis
SOCRadar’s analysis of stealer-log telemetry did not yield any positive records for optiforms[.]com. It is crucial to note that a lack of positive findings does not definitively indicate that an organization is unaffected. The performed query was based on a bounded, paginated sample, and there is a possibility that credentials could exist under alternative corporate domains or be associated with staff personal email aliases that do not directly resolve to the primary corporate domain. Therefore, the absence of matching records should be interpreted as no positive signal rather than confirmation of no compromise. The Gentlemen, like many other ransomware operations, commonly leverages infostealer logs as a vector for initial access. The typical workflow involves purchasing recent logs, validating corporate credentials, and then gaining access to systems via platforms such as Microsoft 365, VPNs, or remote-access portals, from which ransomware is deployed. The current telemetry does not directly link Optiforms to this specific initial access pathway. Given the findings, the recommended course of action includes continued monitoring of the dark web and stealer-log feeds, alongside proactive credential hygiene reviews. This proactive approach can help mitigate potential risks and provide early indicators of further compromise attempts.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.