# TheGentlemen ransomware claims Skyplan Services

Published: 2026-10-09 · Severity: high · Sectors: transportation, technology
Canonical: https://vorant.io/reports/a20c44db-2e5f-58e7-b032-1c8a6b7afe8d/thegentlemen-ransomware-claims-skyplan-services

> Ransomware group TheGentlemen lists Calgary-based aviation flight-planning firm Skyplan Services as a victim, with credential exposure also reported.

Ransomware.live has indexed a new claimed victim entry from the ransomware group operating under the name "TheGentlemen," targeting Skyplan Services Limited, a Calgary-based private aviation flight planning and dispatch provider operating its Aurora Flight Planning SaaS platform globally (Canada, UAE, China, Finland). The estimated attack date is October 6, 2026, with discovery/listing on October 9, 2026. The company has ~85 employees and ~$7M annual revenue, and operates critical third-party aviation logistics services (fuel sales, permits/slots, ground handling, dispatch) for airline customers worldwide.

Alongside the ransomware claim, the listing cites infostealer-derived exposure data from HudsonRock and ParanoidLab, reporting 12 compromised users, 1 third-party employee credential set, 8 external attack surface findings, and 221 exposed passwords (11 flagged critical). No specific malware sample, C2 infrastructure, or exploited CVE is disclosed in this listing; DNS records shown (Barracuda email security, Microsoft 365) reflect the victim's legitimate mail infrastructure rather than attacker infrastructure.

For defenders, this is a victim-notification style entry rather than detailed technical reporting: there is no confirmed initial-access vector, no IOC list tied to the intrusion, and no technical detail on TheGentlemen's tooling. Organizations in aviation/flight-planning and logistics supply chains should treat this as a signal to review credential hygiene (given the infostealer exposure) and monitor for data leak site publication from TheGentlemen group, which would typically follow a failed extortion negotiation.

## Mentioned in this report

- Threat actors: The Gentlemen
- Malware: Gentlemen

Source reporting: https://www.ransomware.live/id/U2t5cGxhbiBTZXJ2aWNlc0B0aGVnZW50bGVtZW4=

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/a20c44db-2e5f-58e7-b032-1c8a6b7afe8d/thegentlemen-ransomware-claims-skyplan-services.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
