Who Runs the Ransomware Group ‘The Gentlemen?’
Krebs on Security traces clues linking the fast-growing ransomware group The Gentlemen to a Russian forum user and alleged administrator.
Intelligence analysis by GPT-5.4 Mini

The article says The Gentlemen has become one of the most active ransomware gangs by victim count, helped by a 90/10 affiliate split that lures skilled operators. It then walks through forum, phone, and account data that point to one person as the likely administrator behind the group.
The story is about detectives following digital footprints to guess who runs a bad online gang. Like finding the same muddy shoes at different crime scenes, they connect usernames, phone numbers, and accounts to one likely person.
Analysis
What the article says
Krebs on Security reports that The Gentlemen has emerged as the second most active ransomware gang by victim count, with at least 332 published victims since mid-2025 and more than 240 in 2026 alone. Check Point researchers say the group uses a ransomware-as-a-service model and offers affiliates a 90/10 revenue split, which is more generous than the usual industry split and appears to be pulling in experienced operators.
The article says the group typically gains access through internet-facing systems such as VPNs and firewalls, then moves quickly to encrypt networks within hours. Check Point also says a backend breach made it clear that the user known as Hastalamuerte, later linked to Zeta88, is the person assembling the locker and panel, handling payments, and running the program.
Identity clues
The rest of the story follows a chain of forum registrations, usernames, email addresses, phone numbers, and account pivots. Intel 471 and other intelligence services connect Hastalamuerte/Zeta88 to activity across multiple cybercrime forums over several years, including registrations from Izhevsk in western Russia. The article says those records point to a Russian man named Alexander Andreevich Yapaev, including a LinkedIn profile that lists him as head of B2B marketing at Uralenergo Udmurtia.
Krebs notes that Yapaev did not respond to requests for comment. The article is careful to present this as a set of clues and correlations rather than a courtroom-level identification, but it argues the evidence strongly suggests the same person is behind the aliases.
Key points
- The Gentlemen is described as the second most active ransomware gang by victim count.
- Check Point says its 90/10 affiliate split is helping it recruit experienced operators.
- The group reportedly targets internet-facing devices and encrypts networks within hours.
- The article links the aliases Hastalamuerte and Zeta88 to a possible real identity using forum, email, phone, and account records.
- The person identified in the article did not respond to requests for comment.
If the attribution is correct, investigators and defenders get a clearer picture of who is behind The Gentlemen and how the group operates. That can help security teams spot their tactics earlier and may make it harder for the gang to recruit and keep affiliates.
The group is already described as fast-growing and aggressive, so even if one operator is identified, the ransomware operation may keep running or split into new identities. The article also suggests the wider affiliate model makes the threat resilient because many operators can keep attacking even if one administrator is exposed.



