Quick Summary
AllegedExecutive Summary
The Gentlemen ransomware group has listed VPC Group (Custom Foam), a U.S.-based manufacturer, on its dark web leak site on July 23, 2026. SOCRadar’s Dark Web Monitoring service identified this listing on the same day. VPC Group operates in the manufacturing sector, a segment that frequently attracts ransomware and extortion attacks due to its critical infrastructure and potentially sensitive operational data. In the preceding 60 days, The Gentlemen claimed responsibility for attacks on 164 other entities. The group’s primary targets are the manufacturing, business services, and healthcare industries, with a predominant focus on victims located in the United States, France, and Germany. VPC Group aligns with the manufacturing industry, falling into the same category as other recent victims claimed by The Gentlemen, including MatTek, Optiforms, Henry Frerk Sons, and Compagnie des Caoutchoucs du Pakidie.
Technical Analysis
SOCRadar’s analysis of stealer-log telemetry did not yield any records associated with the domain customfoam[.]com. It is important to note that this query encompassed a limited, paginated sample of data. Therefore, the absence of records in this specific dataset does not definitively confirm the absence of exposed credentials. Credentials could potentially exist under alternate corporate domains or be associated with employee personal email aliases that were not included in the query. The outcome should be interpreted as a lack of direct evidence rather than a clean bill of health. Infostealer logs often serve as an initial access vector for ransomware groups like The Gentlemen. Threat actors or access brokers may acquire these logs to validate corporate credentials, which are then used to breach systems through platforms such as Microsoft 365, VPNs, or remote-access portals before deploying ransomware. While this specific listing for VPC Group did not surface any such indicators within the analyzed stealer-log data, the negative result does not rule out the possibility of credential compromise through other channels. Continued monitoring of VPC Group’s credentials across various stealer-log feeds and related domains is recommended. Additionally, performing a comprehensive credential hygiene review, including mandatory password rotation and strengthening multi-factor authentication coverage for all remote access points, is advisable as long as the threat actor’s listing remains active.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.