VORANT. Threat Intelligence Research Sign in Create a free account

Ransomware group TheGentlemen lists small marble firm

elevated threat manufacturing

Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.

Ransomware group 'TheGentlemen' claims small Colorado marble restoration company Polishing Proz as a victim on its extortion site.

Ransomware.live indexed a new victim listing attributed to the ransomware extortion group operating under the alias 'thegentlemen'. The claimed victim is Polishing Proz LLC, a very small (3-6 employee) family-owned marble and stone restoration business based in Centennial, Colorado, with an estimated annual revenue of $200K-$500K. The listing was discovered on 2026-10-09 with an estimated attack date of 2026-10-06.

The entry contains no technical details of the intrusion — no malware name, no initial access vector, no exfiltrated data samples, and no confirmed cloud/SaaS exposure was detected for the victim's domain (polishingproz.com). This appears to be a standard double-extortion naming-and-shaming post typical of ransomware leak sites, used to pressure the victim into payment, rather than a detailed technical disclosure.

Given the victim's small size and the complete absence of technical indicators, exploited vulnerabilities, or confirmed data leakage in the source material, this is a low-severity, low-impact listing from a defender's perspective. Organizations should treat this primarily as evidence of the 'thegentlemen' group's continued activity rather than as actionable technical threat intelligence.

Mentioned in this report

Threat actors The Gentlemen

Detection guidance

1 detections for this report are in the app — rules that match its indicators, converted to Splunk SPL, Microsoft KQL and Elastic, plus YARA and Suricata. Three days of it free, no card.

Source reporting: https://www.ransomware.live/id/UG9saXNoaW5nIFByb3pAdGhlZ2VudGxlbWVu

What this brief leaves out

This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.

It sits in a corpus of 11,183 reports from 148 sources, 503 of them written in the last seven days, and it grows through the day.

A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.

Create a free account   What it costs