Upanal CNC Solutions Data Breach

Alleged

Ransomware claim involving Upanal CNC Solutions.

Published: Jul 30, 2026 The Gentlemen
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Upanal CNC Solutions
Industry
Business Services
Threat Actor
The Gentlemen
Date of Incident
Jul 30, 2026

Executive Summary

The Gentlemen ransomware group has added Upanal CNC Solutions, a Peruvian manufacturing company, to its leak site on July 30, 2026. This listing places Upanal CNC Solutions in an ongoing wave of extortion attacks that have predominantly targeted organizations in the United States and India. SOCRadar’s Dark Web Monitoring service flagged this addition to the threat actor’s victim list. While the listing indicates Upanal CNC Solutions is claimed as a victim rather than a confirmed breach, such an appearance on a ransomware leak site is a significant event for any manufacturing organization, highlighting immediate risks of data disclosure and potential operational disruptions. In the 60 days leading up to this listing, The Gentlemen claimed an average of approximately 175 victims, positioning it as one of the most active ransomware operations currently tracked. The group’s typical targets are predominantly in the Manufacturing, Business Services, and Healthcare sectors, with a geographical focus on the United States, India, and France. Upanal CNC Solutions aligns with the group’s favored manufacturing sector, joining recent victims such as Delkart Industries Pvt, Buck Knives, MatTek, and Optiforms. However, the victim’s Peruvian origin represents an unusual deviation from The Gentlemen’s typical targeting pattern, which has largely concentrated on North America and South Asia.

Technical Analysis

SOCRadar’s analysis of The Gentlemen’s activity, correlated with stealer-log telemetry, uncovered a notable credential exposure linked to the domain upanalcnc[.]com. Infostealer malware captured multiple corporate usernames associated with the @upanalcnc[.]com domain from various third-party services, including Google Workspace, Zoho, job boards, and CRM platforms. This type of exposure is indicative of credential harvesting from one or more compromised employee endpoints. Although no direct identity provider or internal administrative URLs were present in the analyzed data slice, the nature of the findings, particularly that it was from a later page of a paginated response, strongly suggests workstation compromise with reused corporate credentials across multiple Software-as-a-Service (SaaS) platforms. The captured data’s freshness window extends into late July 2026, indicating recent compromise activity. The observed credential exposure presents a significant risk signal, as infostealer-harvested credentials are a common entry vector for ransomware groups like The Gentlemen. Threat actors or initial access brokers often acquire these logs from underground markets, validate the credentials, and subsequently use them to gain unauthorized access to corporate networks through platforms such as Microsoft 365, VPNs, or remote access portals, before deploying ransomware. While this specific telemetry does not confirm that The Gentlemen leveraged these compromised credentials, the widespread exposure of corporate accounts across multiple SaaS applications is a classic precursor to such attacks. The decision to address this risk is critical. Three essential, non-optional actions are recommended: first, affected corporate accounts must be immediately rotated; second, Multi-Factor Authentication (MFA) must be enforced on all associated tenants, including Google Workspace; and third, the workstations associated with these credentials should be imaged to ensure complete removal of any potential malware or backdoors. Continued dark web monitoring and credential hygiene checks are also advised.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.