~/f4n6 $ grep -r "Ransomware: thegentlemen named INTERNET AG (DE)" ./investigations/ --include="*.md"

Ransomware: thegentlemen named INTERNET AG (DE)

Jeff Davies 11 Jul 2026 4 min read

1. Executive summary

On 11 July 2026, the ransomware group "thegentlemen" publicly claimed a compromise of INTERNET AG (inet.de), a German IT service provider specialising in managed hosting, server solutions, and enterprise network connectivity. The victim organisation provides IT infrastructure and managed services to corporate clients, meaning downstream disruption to financial services customers is a realistic secondary risk. Attribution to the actor "thegentlemen" is unconfirmed — the group has no MITRE ATT&CK profile in verified reference data. The claim is currently single-sourced (Ransomware.live); no technical details, initial-access vector, malware payload, or IOCs have been disclosed. No CISA-KEV-listed CVE is associated with this incident.

2. Regulatory framing

Article Trigger (the fact in this item) Practical impact
DORA Art. 17: ICT-related incident management process A ransomware claim against a German IT service provider that may act as an ICT third-party provider to EMEA financial entities. Financial entities using INTERNET AG or its partner INTERNIC GmbH for hosting or managed services should activate their ICT-related incident management process to assess potential impact on their own operational continuity.
DORA Art. 28: ICT third-party risk — general principles The victim is an ICT third-party provider (hosting, managed services, network connectivity) with potential exposure to financial entity clients. Entities with contractual relationships with INTERNET AG should assess whether the claimed compromise affects services they depend on and review third-party risk exposure.
DORA Art. 19: reporting of major ICT-related incidents to competent authorities If a financial entity determines that the compromise of its ICT third-party provider (INTERNET AG) constitutes a major ICT-related incident for its own operations. Entities must classify the incident per Art. 18 and, if major, report to competent authorities within applicable timelines.
NIS2 Art. 21(2)(d): supply chain security measures The claimed compromise targets a supplier in the IT services supply chain. NIS2 in-scope organisations should evaluate whether INTERNET AG forms part of their supply chain and whether supply chain security measures are adequate.
NIS2 Art. 23: incident reporting obligations If a NIS2 essential/important entity is affected through its relationship with INTERNET AG. Affected entities must assess whether the incident triggers their own NIS2 incident reporting obligations.

3. Technical analysis & attack chain

No technical details of the compromise are available in the source material. The claim consists solely of a victim listing on Ransomware.live naming INTERNET AG (inet.de), Germany, under the group "thegentlemen." No initial access vector, exploited CVE, malware family, persistence mechanism, C2 infrastructure, lateral movement technique, exfiltration method, or ransom note content has been disclosed.

What is known about the victim: INTERNET AG (inet.de) is a German IT service provider offering hosting, managed services, server solutions, and global network connectivity. It operates alongside partner INTERNIC GmbH, providing enterprise software and digital operations services to corporate clients. Hudson Rock's exposure data (indexed via Ransomware.live) reports 0 compromised employees, 0 compromised users, 2 third-party employee credentials, and 0 external attack surface findings for the victim's domain. The significance of the two third-party credentials is unclear without further context.

Attribution caveat: The actor "thegentlemen" has no MITRE ATT&CK profile in verified reference data. Attribution is unconfirmed. The group has been observed listing at least one other victim ("hiddeenn") on Ransomware.live, but no corroborating technical reporting from a second source is available. All claims are single-sourced (Ransomware.live); verify before enforcement.

Confidence caveat: This advisory is based entirely on a single source (Ransomware.live victim listing). No independent corroboration, technical forensic detail, or vendor advisory has been identified at time of writing. Treat all claims as unconfirmed pending victim acknowledgement or additional reporting.

4. Mitigation & containment

Given the absence of technical detail, IOCs, or a known exploit vector, mitigation guidance is necessarily precautionary and focused on third-party risk.

P1 — Within 24 hours

  • Determine whether your organisation has a direct contractual relationship with INTERNET AG (inet.de) or INTERNIC GmbH for hosting, managed services, or network connectivity. If yes, contact the provider to request an incident status confirmation and impact assessment.
  • Identify any critical services or data hosted on INTERNET AG infrastructure. Assess whether failover or migration to an alternative provider is required.
  • Review logs for connections to inet.de domains, IP ranges associated with INTERNET AG infrastructure, and any anomalous access patterns originating from or terminating at INTERNET AG-hosted assets.

P2 — Within 72 hours

  • If INTERNET AG is confirmed as an ICT third-party provider, classify the potential impact per your DORA Art. 18 incident classification methodology. If the incident is assessed as major for your operations, prepare Art. 19 reporting.
  • Notify internal incident response and legal teams. Document the third-party exposure assessment for regulatory evidence.
  • If INTERNET AG services are non-critical, monitor for service degradation or outage and maintain a contingency plan.

P3 — Within 7 days

  • Conduct a review of all third-party hosting and managed service providers to identify single points of failure in your ICT supply chain.
  • Request a written incident post-mortem from INTERNET AG if the compromise is confirmed, including root cause, data affected, and remediation taken.
  • Update vendor risk registers and third-party risk assessments to reflect this event.

5. Indicators of compromise

No indicators of compromise available in the source material.

6. Detection

Insufficient indicators to author detection rules.

7. Sources

  • Ransomware.live — "Ransomware: thegentlemen named INTERNET AG (DE)" — https://www.ransomware.live/id/SU5URVJORVQgQUdAdGhlZ2VudGxlbWVu — Published 2026-07-11
  • Ransomware.live — "Victim: INTERNET AG – thegentlemen" (Hudson Rock exposure data) — https://www.ransomware.live/id/SU5URVJORVQgQUdAdGhlZ2VudGxlbWVu — Accessed 2026-07-11
  • Ransomware.live — "Ransomware: thegentlemen named hiddeenn" — https://www.ransomware.live/id/aGlkZGVlbm5AdGhlZ2VudGxlbWVu — Context only (prior victim listing by same group)

8. Adverse Trace position

This is a low-confidence, single-sourced ransomware claim with no technical detail available. The primary risk to EMEA financial services clients is indirect: INTERNET AG is an IT service provider whose compromise could cascade to dependent customers, including potential financial sector clients using its hosting or managed services. Attribution to "thegentlemen" is unconfirmed (no MITRE ATT&CK profile). We assess the immediate operational risk to most clients as low-to-moderate, elevated for any client with a direct dependency on INTERNET AG or INTERNIC GmbH. Adverse Trace will monitor for corroboration from additional sources, victim acknowledgement, or disclosure of technical indicators, and will update this advisory if material new information emerges. Clients with confirmed third-party relationships to INTERNET AG should activate their DORA Art. 17 incident management process immediately.


Read the original source →

Published via PulseTrace — Adverse Trace threat intelligence.

Post this to LinkedIn
Formatting is converted automatically — headings, bullets, a link back & hashtags. Paste straight in.
J
Jeff Davies