Quick Summary
AllegedExecutive Summary
The Gentlemen ransomware group listed Gerrity Stone on its leak site on October 3, 2026, claiming the exfiltration of corporate data. Gerrity Stone, a company operating within the building materials and stone supply sector, has become a recent target within the construction industry for this threat actor. SOCRadar’s analysis of stealer-log intelligence reveals a significant exposure of credentials spanning from June 2024 to February 2026, a 20-month period that provided threat actors ample time for reconnaissance and preparation before the public listing. This extended window suggests a carefully planned operation aimed at maximizing the impact of the eventual ransomware deployment. The Gentlemen group typically engages in double extortion, combining data theft with encryption. Their primary method for initial access is through the exploitation of stolen credentials, often obtained via infostealer malware. Their targeting is diverse, frequently including the construction, manufacturing, healthcare, and professional services sectors. Prior to deploying ransomware, the group is known to conduct extensive reconnaissance, a strategy that allows them to maximize both the volume of exfiltrated data and the disruptive impact of their encryption activities. Gerrity Stone’s listing aligns with this pattern, as the group appears to have leveraged credential compromise to gain access and exfiltrate sensitive information.
Technical Analysis
SOCRadar’s investigation identified exposed credentials belonging to Gerrity Stone across two key platforms: the site’s administrator panel, accessible at gerritystone[.]com/administrator/, and DispatchTrack, the company’s Software-as-a-Service (SaaS) solution for logistics and delivery management. Access to the admin panel could potentially allow threat actors to perform reconnaissance on the Content Management System (CMS), inject malicious code, or utilize the interface as a staging ground for lateral movement within the victim’s network. The compromise of DispatchTrack credentials exposes commercially sensitive information, including delivery scheduling, customer order details, and logistics coordination records, which are particularly valuable for a building materials supplier that interacts with numerous contractors and developers. The exposure of these credentials, documented in stealer logs from June 2024 through February 2026, provides a substantial timeframe for threat actors to gain a foothold and exfiltrate data. The ability to access administrative functions and critical logistics software significantly increases the risk of a full-scale ransomware attack. This credential exposure does not definitively confirm that Gerrity Stone has been compromised by The Gentlemen ransomware; however, it strongly suggests a pathway for such an attack, as the group often leverages stolen credentials for initial access. Immediate actions recommended for Gerrity Stone include the urgent rotation of all administrator and DispatchTrack credentials. A comprehensive audit of access logs for both platforms, dating back to June 2024, is crucial for identifying any unauthorized activity. The company should also assess whether the exposed DispatchTrack data necessitates breach notification obligations to affected customers or partners. Furthermore, restricting access to the CMS admin panel to trusted networks, such as through a VPN or specific IP ranges, and enforcing Multi-Factor Authentication (MFA) on all administrative web interfaces and SaaS platforms are critical steps to mitigate future risks.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.