Rapid Ransomware Wave Targets Municipalities and Financial Institutions Worldwide with Double Extortion

The Gentlemen (also tracked as GOLD SHERWOOD) operates as a ransomware‑as‑a‑service (RaaS), providing affiliates with infrastructure, malware, negotiation platforms, and leak sites, enabling attackers to progress from initial access to encryption in under 24 hours.
The operation combines RaaS with double extortion, meaning attackers threaten to publish stolen data in addition to encrypting systems to increase pressure on victims.
ThreatMon linked Qilin to victim 'TANNER' and Dire Wolf to 'Cartrack Holdings' in separate alerts around Sept. 3, 2026; a victim-list appearance is an intelligence signal that can indicate various stages of an intrusion, including data theft or encryption.
ThreatMon notes rapid publication of ransomware claims: Ormond Beach, FL, attributed to 'WallStreet,' and GSAC Auto Financing attributed to 'Storm' appeared within minutes of each other on Sept. 2, 2026, illustrating how quickly threat intel can surface—often before full confirmation of intrusion.
Fresh monitoring on Sept. 2, 2026 linked Ville de Libercourt (France) to Kairos and Asfaltos y Pavimentos S.A. (Spain) to Incransom, underscoring ongoing targeting of municipalities, infrastructure, and industrial firms by ransomware operators.
Ransomware groups are moving faster and hitting harder. Palo Alto Networks found that attackers can now breach a network, steal data, and encrypt systems in under 24 hours using automated tools. At the same time, criminals are adopting new tricks like "quishing"—embedding malicious QR codes in images to trick people into clicking malicious links that bypass traditional security defenses.
Real targets are feeling the pain right now. City governments like Ormond Beach, Florida, and auto financing companies like GSAC Auto Financing have been hit in recent attacks. ThreatMon reports that multiple ransomware groups are listing victims and demanding money within hours, often before organizations even know they've been breached.
A group called The Gentlemen (also tracked as GOLD SHERWOOD) runs what cybersecurity experts call "ransomware-as-a-service," or RaaS. Think of it like a franchise: they provide the tools, platforms, and leak sites. Affiliate criminals buy in and launch attacks. Unit 42 reports that this model lets attackers move from initial access to full encryption in under 24 hours—far faster than even a year ago.
These groups use "double extortion." They don't just encrypt your files and demand ransom. They also steal your data first, then threaten to publish it online unless you pay. This doubles the pressure on victims and makes it much harder to refuse payment.
On September 2, 2026, ThreatMon detected two major attacks within minutes of each other: Ormond Beach, Florida's city government hit by a group called WallStreet, and GSAC Auto Financing hit by a group called Storm. Both victims appeared on ransom leak sites almost immediately—a sign that attackers are publishing names before victims even realize they're compromised.
The pattern extends beyond the US. A city in France called Ville de Libercourt was linked to ransomware group Kairos. Asfaltos y Pavimentos, a paving company in Spain, was hit by Incransom. Municipalities and critical infrastructure remain high-value targets because they often struggle with outdated security and have limited budgets for defense.
Attackers are ditching old-fashioned email links and turning to "quishing"—embedding malicious QR codes in images. When you scan the code with your phone, it silently directs you to a fake website that steals your login credentials. This bypasses traditional security tools that scan text-based URLs, making it harder for defenders to catch the attack before damage occurs.
The trend signals a shift in how breaches start. Instead of clicking a suspicious link, victims scan what looks like a normal QR code. This exploits everyday habits—most people trust QR codes because they see them everywhere. Once attackers have credentials, they move fast. Palo Alto Networks documented cases where the entire attack, from initial access to encryption, took fewer than 10 hours.
Organizations must assume attackers are working at machine speed. Incident response plans need to account for data theft—not just encryption. When a victim appears on a ransom leak site, the damage is already done. Defenders should monitor dark web forums and leak sites constantly and prepare negotiation responses in advance.
Teams also need to train staff on quishing. A QR code in an email or text is a red flag. Additionally, organizations should deploy threat intelligence feeds that track ransomware group activity and tie it to known vulnerabilities in their environment. Speed and preparation matter more than ever.
Publishers
16
Articles
0
Reach
16