1. Executive summary
On 7 September 2026, the ransomware group self-identifying as "thegentlemen" listed the University of San Francisco (US) as a victim on its leak site. This is a leak-site claim only: no technical detail on initial access, malware, encryption, or exfiltration volume is present in the source material, and the group has no MITRE ATT&CK profile — attribution and the claim itself are unconfirmed. The victim is a US private university, not an EMEA financial services entity, so direct exposure to our client base is low. The item is relevant to EMEA FIs only as third-party/supply-chain exposure (any FI relationship with USF for research, alumni, payment or data processing) and as a data-point on an emerging group's targeting. Hudson Rock-sourced context on the victim page reports 1,068 compromised users and 2 compromised employees associated with the victim's domain — single-sourced vendor telemetry, not evidence of the intrusion path for this incident.
2. Regulatory framing
No specific DORA/NIS2 article is directly engaged by this item. The item is an uncorroborated leak-site listing against a US university with no confirmed intrusion detail, no EMEA FI victim, and no identified third-party relationship triggering a distinctive obligation. Clients should not treat this as a reportable incident trigger on the current facts.
3. Technical analysis & attack chain
No confirmed attack chain can be reconstructed from the source material. The ransomware.live listing contains only: group name ("thegentlemen"), victim name (University of San Francisco), country (US), and victim website (usfca.edu). There is no description of the claimed intrusion, no ransom note text, no sample, no CVE, no tooling, and no exfiltration evidence.
What the source does establish:
- Claim: "thegentlemen" published a victim entry for the University of San Francisco on or before 2026-09-07 (listing timestamp 2026-09-07T21:55:37Z).
- Victim profile: usfca.edu — private Jesuit university, ~10,200 students, $428M endowment, main campus in San Francisco with additional sites in downtown SF, Pleasanton and Tokyo. R2 Carnegie classification ("high research activity").
- Hudson Rock telemetry on the victim page (single-sourced, vendor-sponsored context — not incident evidence): 2 compromised employees, 1,068 compromised users, 99 third-party employee credentials, and an external attack surface of 103 assets associated with the victim's domain. These figures describe infostealer-derived credential exposure around the victim's domain generally; they are not linked by the source to the thegentlemen claim and must not be treated as the intrusion vector. Treat as "single-sourced; verify before enforcement."
Attribution caveat: "thegentlemen" has no MITRE ATT&CK profile in our verified reference data. Attribution of this listing to any established ransomware operation, and the accuracy of the victim claim itself, are both unconfirmed. Leak-site claims are routinely inflated, recycled, or fabricated; ransomware.live explicitly does not verify the underlying data theft.
4. Mitigation & containment
No victim-side technical containment applies to our clients — the victim is a third party. Actions are exposure-mapping only:
P1 — within 24h
- Query third-party/vendor management records for any contractual or data relationship with University of San Francisco or usfca.edu (research partnerships, data sharing, payment rails, alumni/donor systems). If none, log the check and close.
- If a relationship exists: identify what data or connectivity the relationship involves and whether a breach notification clause is triggered by a credible (not merely claimed) compromise.
P2 — within 72h
- For any identified relationship, request a written status statement from the counterpart on the thegentlemen claim.
- Add "thegentlemen" and usfca.edu to threat-intel watchlists for corroborating reporting (samples, negotiation-chat leaks, second-source confirmation).
P3 — within 7 days
- Review whether the Hudson Rock-style exposure pattern (infostealer-compromised credentials around a target domain preceding ransomware claims) is monitored for your own organisation's domains — this is the generalisable lesson of the item, not a USF-specific control.
5. Indicators of compromise
No indicators of compromise available in the source material. The listing provides no hashes, domains beyond the victim's legitimate website, IPs, or malware artefacts. The victim domain usfca.edu is not an IOC — it is the victim's own infrastructure and must not be blocked.
6. Detection
Insufficient indicators to author detection rules.
7. Sources
- Ransomware.live — "Victim: University of San Francisco – thegentlemen" — https://www.ransomware.live/id/VW5pdmVyc2l0eSBvZiBTYW4gRnJhbmNpc2NvQHRoZWdlbnRsZW1lbg== — 2026-09-07
- Hudson Rock (victim-page telemetry via ransomware.live) — compromised employee/user credential counts and external attack surface figures for usfca.edu — same URL as above — accessed 2026-09-08
8. Adverse Trace position
Low direct severity for EMEA financial services: an uncorroborated, single-source leak-site claim against a US university, with no technical detail, no confirmed data theft, and no MITRE-verified profile for the claiming actor — attribution unconfirmed. The only actionable angle for clients is third-party exposure mapping (P1 check above) and watchlisting "thegentlemen" for corroborating technical reporting; the Hudson Rock credential-exposure figures are single-sourced vendor telemetry and should not drive enforcement action. We will update this advisory if a second source corroborates the claim, if samples or negotiation-chats surface, or if any client reports a material relationship with the victim institution.
Published via PulseTrace — Adverse Trace threat intelligence.