Find notable cyber news and cases, enriched with sources, timelines, and signals.

Azazel's Leakned breakaway from The Gentlemen RaaS

Threat Actor Meta
First reported
Last updated
Happening score
H score 82
1 unique sources, 1 articles

Summary

Hide ▲

Azazel broke away from The Gentlemen RaaS by running Leakned independently and keeping extortion proceeds, undermining the group's affiliate monetization model. The breakaway activity affected over two dozen victims across six countries and shifted victim publication control outside the parent program. The victim set included logistics, insurance, pharmaceutical, AI, medical device, and government organizations. The move shows how a ransomware affiliate can turn a standard revenue-sharing arrangement into a direct extortion business.

Related Happenings

Azazel-managed exposed servers holding stolen victim data

Data Leak
H score68 First: 06.10.2026 11:30 Last: 06.10.2026 11:30 Sources 1

How related: They researchers found two exposed servers managed by “Azazel” – an affiliate of The Gentlemen RaaS outfit – containing several terabytes of data stolen from logistics, insurance, pharmaceutical, AI, medical device, and government victims across six countries.

About this happening: The exposure of two servers managed by Azazel left several terabytes of stolen victim data at risk of publication, spanning six countries and multiple sectors. The ser...

The Gentlemen RaaS split exposed by hastalamuerte

Threat Actor Meta
H score25 First: 19.03.2026 18:00 Last: 19.03.2026 18:00 Sources 1

About this happening: hastalamuerte exposed the internal workings of The Gentlemen ransomware group, revealing a Qilin-related RaaS split that shows how affiliate-driven ecosystems can rapi...

Latest development: 17.07.2026 12:00

ReliaQuest reported that The Gentlemen ransomware gang became the most active ransomware group over a three-month period, with 300 incidents and 1,368 victim claims tracked across 11 ransomware groups. The analysis said The Gentlemen overtook Qilin, which had 289 incidents, and linked the rise to aggressive affiliate recruitment, a pre-packaged intrusion kit, and AI-accelerated development.

Timeline

  1. 05.10.2026 03:00 2 articles · 1d ago

    CloudSEK exposes Azazel's independent Leakned extortion operation

    Initial Disclosure

    CloudSEK said a Russian-speaking ransomware affiliate, Azazel, ran an independent leak site called Leakned, kept extortion proceeds from over two dozen victims, and maintained exposed servers holding several terabytes of stolen data from logistics, insurance, pharmaceutical, AI, medical device, and government organizations across six countries. The report tied the activity to exposed GitLab secrets, an SSRF flaw in an unauthenticated AI medical-imaging API, and an AI coding assistant used through MCP to send commands to a compromised machine on the victim’s network.

    Show sources