280 EU organisations have been claimed on ransomware leak sites so far this quarter (Q3 2026). One group tops the EU leaderboard — The Gentlemen — the most-targeted country is Germany, and the most-targeted industry is manufacturing. Here's the quarter to date, and why the group leading it should worry any mid-market manufacturer, in NIS2 scope or not. (These are claimed victims from leak sites — groups exaggerate and double-post — so read the counts as direction, not a ledger.)

The attacks: who's claiming EU victims this quarter

Across the EU-27, the quarter's claims are concentrated in a handful of active crews. The Gentlemen alone account for roughly a fifth of all EU claims — ahead of Qilin, the group they splintered from.

EU claims by group · Q3 2026 to date

The Gentlemen
58
Qilin
52
Deadlock
44
SafePay
22
Krybit
11
Cl0p
8

The industry split tells the real story. Manufacturing is the single most-claimed sector (58), followed by professional services (45) and technology (34) — a reminder that ransomware crews follow operational fragility and ability to pay, not a company's regulatory label.

EU claims by industry · Q3 2026 to date

Manufacturing
58
Professional Services
45
Technology
34
Other (unclassified)
22
Agriculture & Food Production
17
Financial Services
13

The country picture: Germany leads the EU

Germany is the most-claimed EU country this quarter by a clear margin, followed by Italy and France — the EU's three largest industrial economies, in order. That's not a coincidence: a dense base of mid-market manufacturers and suppliers is exactly the target profile the most active groups favour.

EU claims by country · Q3 2026 to date

Germany (DE)
65
Italy (IT)
45
France (FR)
30
Spain (ES)
24
Poland (PL)
15
Czechia (CZ)
15

The quarter's most conspicuous German case sits at the intersection of both trends: Thyssenkrupp Marine Systems (TKMS) / Atlas Elektronik, a naval-defence manufacturer, which The Gentlemen claimed with an alleged 1TB+ data theft. TKMS confirmed an intrusion while disputing the sensitivity of the material — a textbook reminder that a leak-site claim is an allegation, not a verified breach scope.

The group has also reached into the public sector: around August 2026 The Gentlemen listed “Arbeiterkammern” on its leak site (tracked by ransomware.live), coinciding with the attack on Arbeiterkammer Oberösterreich — an Austrian public-law body that ran “analog” for weeks and issued a precautionary GDPR notification to hundreds of thousands of members. The AK itself has not named an attacker, so — as with any leak-site entry — treat it as an unverified claim. We break down what’s actually public, and the real cost drivers, in our analysis of the AK Oberösterreich cyberattack.

Who are The Gentlemen?

The Gentlemen surfaced around August 2025 as a splinter of the Qilin ransomware-as-a-service operation — reportedly founded by Russian-speaking actors after a dispute over affiliate commissions. In under a year they've become one of the fastest-scaling crews on record: security vendors put their 2026 claim count in the hundreds of victims across 70+ countries, second only to Qilin by volume, with more than 200 claims in the first quarter of 2026 alone.

Their growth is engineered. The operation reportedly offers affiliates a 90/10 revenue split — far above the 70–80% industry norm — to pull in skilled operators fast. And the sectors they favour map almost exactly onto this quarter's EU picture: manufacturing, healthcare, IT and professional services, financial services, construction and logistics, with a focus on medium-to-large organisations.

How they get in — and why it's the exact risk Nisura models

Researchers tie The Gentlemen's initial access to two paths above all:

  • Exposed edge appliances — unpatched FortiGate / FortiOS and other perimeter devices (e.g. the FortiOS authentication-bypass flaw), then Erlang/OTP SSH and Windows SMB weaknesses. This is the external-exposure path a passive scan sees.
  • Stolen credentials — VPN and webmail logins brute-forced or lifted from infostealer logs. This is the credential vector — invisible to a port scan, and often the dominant path for SMBs and cloud-only firms.

Those are the two initial-access routes Nisura's engine prices for every organisation: known-exploited exposure on your perimeter, plus a non-CVE credential/RDP vector scaled by your breach and identity exposure. The Gentlemen aren't doing anything exotic — they're industrialising the two doors most companies leave ajar.

What it means for you

The uncomfortable takeaway from the quarter isn't a single group — it's the shape of the data. The most-hit industry is manufacturing; the most-hit country is a manufacturing economy; and the leading group gets in through unpatched edge devices and stolen logins. None of that is decided by whether you're formally an NIS2 essential or important entity — attackers pick targets by exposure and payability, not annex.

Three steps, in order: confirm whether the Directive even binds you with the NIS2 Scope Checker; watch the live picture on the EU Ransomware Tracker; then turn it into your own number — run a free CRQ simulation to see your projected annual loss in euros from exactly these vectors.

Sources & references