Senvest Capital Data Breach

Alleged

Ransomware claim involving Senvest Capital.

Published: Aug 19, 2026 TheGentlemen
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Senvest Capital
Industry
Finance
Threat Actor
TheGentlemen
Date of Incident
Aug 19, 2026

Executive Summary

TheGentlemen ransomware group listed Senvest Capital, a publicly traded Canadian investment manager, on its leak site on August 19, 2026. SOCRadar’s analysis of stealer-log data revealed 10 employee credential records associated with senvest[.]com. These credentials showed access to both Microsoft Entra ID and the firm’s ShareFile platform, which Senvest utilizes for securely sharing fund reports and sensitive investor documents with external parties. The financial services industry, particularly firms handling sensitive client data, remains a target for ransomware groups seeking to exfiltrate valuable information for extortion. The listing of Senvest Capital occurred as part of TheGentlemen’s activity on August 19, 2026, which also included victims Babcock (South Africa, Defense), Roadvision Systems (Sweden, Transportation), CRASL (UK), and Euroscreen (Italy, Technology). This diverse range of industries suggests that TheGentlemen’s primary focus is on exploiting available access rather than targeting a specific sector. The presence of multiple victims in a single wave indicates coordinated efforts to maximize impact.

Technical Analysis

SOCRadar’s stealer-log query for senvest[.]com returned 10 employee credential records. These records indicated access to either login.microsoftonline[.]com (Microsoft Entra ID) or senvest.sharefile[.]com. The timestamps of these credentials ranged from September 2025 to May 2026. This means the most recent harvested credential was approximately three months old at the time of the leak-site listing, and the oldest was nearly a year old. This considerable time lag between credential harvesting and potential deployment is more characteristic of an initial access broker holding onto credentials for a period before selling or utilizing them, rather than an immediate intrusion following a fresh compromise. The ShareFile platform, specifically used by Senvest Capital for secure document sharing with external parties, is noteworthy. In the financial services sector, such platforms often contain highly sensitive information, including fund performance reports, investor statements, and legal agreements. The fact that 10 compromised accounts had access to this content raises significant concerns regarding potential data exfiltration. The range of credential freshness suggests that an intrusion may have occurred earlier, and the accessed credentials were only recently leveraged or exposed. Given the nine-month gap between the most recent credential record and the leak-site listing date, attributing the exact intrusion timeline is challenging. It is possible that these were stale credentials that facilitated the initial access, or that a separate, earlier intrusion occurred that predates the stealer-log harvest. Regardless, a thorough review of ShareFile and Entra ID access logs for the entire period from September 2025 to August 2026 is highly recommended. Considering Senvest Capital’s status as a publicly traded entity, an immediate assessment of investor notification obligations under relevant securities and privacy regulations is crucial.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.