Quick Summary
AllegedExecutive Summary
Shamrock Holdings Inc. has been identified as a victim by the TheGentlemen ransomware group, as published on their dark web portal on July 7, 2026. The listing was detected through SOCRadar’s Dark Web Monitoring. While the specific industry of Shamrock Holdings Inc. is not detailed in the provided information, it is noted as a US-based entity. TheGentlemen ransomware group has been notably active, claiming a significant number of victims in the 60 days leading up to this listing, with a prevalent targeting of the business services, manufacturing, and healthcare sectors, primarily in the United States, Germany, and India.
Technical Analysis
Initial analysis correlating with SOCRadar’s stealer-log telemetry revealed limited exposure, however, it was determined that the queried domain was zoominfo.com, a third-party data services domain, not a corporate domain belonging to Shamrock Holdings Inc. The 25 external/consumer credentials returned from this lookup cannot be attributed to Shamrock’s own infrastructure, therefore, it provides no direct signal regarding the victim organization itself. No corporate credentials from zoominfo.com were observed. TheGentlemen group commonly uses credentials harvested by infostealers as an initial access vector. Threat actors typically source logs from underground marketplaces, validate corporate credentials, and then use them to access systems via Microsoft 365, VPNs, or remote access portals before deploying ransomware. Given that the queried domain was not Shamrock’s corporate domain, this finding does not offer a usable initial-access signal. CTI teams are advised to re-run correlations against Shamrock Holdings Inc.’s verified corporate domain and continue credential hygiene monitoring.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.