The Gentlemen Is the Ransomware Group for Small Businesses to Watch
- Jun 27
- 2 min read
Updated: Jul 27
Opportunistic Targeting of Small Businesses
The Gentlemen is currently the most active ransomware operation affecting Small and Medium sized Businesses (SMB). In the last seven days Balck Cat has identified, 20 SMB-size organisation listings, compared with 8 for the next group and 6 for the third. The pattern is not a single-sector spike, the 30-day SMB-size set spans manufacturing, healthcare, construction, retail, finance, technology, engineering and real estate.

Over the last 30 days, Black Cat identified 208 attacks in the SMB employee-size bands. The centre of gravity is the 51-200 employee band, followed by 201-500 employees. Often organisations of this size are large enough to require VPNs, RDP, domain services and third-party management tooling, but not always large enough to run mature identity governance, exposure management and around-the-clock detection.

The vertical mix is broad with the strongest concentrations in manufacturing, healthcare and construction, with smaller clusters in retail, finance, technology, engineering and real estate. That spread points to opportunistic access: organisations with exposed services, weak credential controls, or exploitable internet-facing systems are attractive regardless of vertical.
How they operate as a Ransomware group
Recent reporting describes The Gentlemen as an enterprise-focused ransomware operation that begins with vulnerable internet-facing services or stolen credentials. The same reporting says operators can manipulate Group Policy, compromise privileged accounts, and use custom methods to bypass endpoint protections.
The more important point for defenders is timing. The useful defensive opportunities are before encryption: internet exposure, identity, privileged access and defence-evasion preparation. Once EDR killers, event-log clearing, Defender tampering and encryption are visible, the incident has already moved into a much harder phase.
Source-backed TTPs now include:
T1133 External Remote Services
T1078 Valid Accounts
T1078.002 Domain Accounts
T1484.001 Group Policy Modification
T1562.001 Disable or Modify Tools
T1068 Exploitation for Privilege Escalation, including BYOVD-style EDR bypass
T1070.001 Clear Windows event logs
T1486 Data Encrypted for Impact

Action Required by Small Businesses
The good news is that this group along with many that prey on SMBs are often relying on low hanging fruit that can be easily prevented. Focus on the identified initial access vectors 1st, prevent lateral movement, protect privileged access, test and verify your EDR can stop bypass attempts. We have more details in our latest weekly threat report including questions to help your IT team / provider.
Sign up now for a 30 day trial including access to the last 2 weeks reports.



Comments