
criticalThreat Intelligence
GlobalSecretGroup and The Gentlemen Lead Late-August Ransomware Surge Targeting US Critical Supply Chains
A coordinated wave of ransomware attacks by GlobalSecretGroup and The Gentlemen has impacted multiple US sectors, including automotive and architectural solutions, utilizing advanced double-extortion tactics.
26 August 2026Last updated 26 August 20265 min readFortiGuard Labs
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here
Executive Takeaway — TL;DR
- Category:
- Threat Intelligence
- Severity:
- Critical
- Actor Type:
- Ransomware Group
- Geography:
- North America
- Confidence:
- High Confidence
- CVE:
- CVE-2024-55591, CVE-2025-32433
- Source:
- FortiGuard Labs
- Read Time:
- 5 min
Executive Summary\nBetween August 24 and August 26, 2026, Encrygma threat intelligence monitors observed a significant spike in ransomware activity across North America and Europe. Two primary actors, GlobalSecretGroup and The Gentlemen, have claimed responsibility for high-profile breaches across the automotive, architectural, and energy sectors. Notable victims identified in the last 24 hours include Johnson City Honda and Lockheed Architectural Solutions, both targeted by GlobalSecretGroup. This surge follows a series of attacks earlier in the week by the Storm ransomware group against the Phoenix Group of Companies, signaling a period of heightened threat activity as August concludes.\n\n## Threat Analysis\nGlobalSecretGroup has emerged as a highly aggressive Ransomware-as-a-Service (RaaS) affiliate, focusing its efforts on mid-to-large scale US enterprises. Their operational tempo has increased dramatically, with multiple victims posted to their leak site on August 26 alone. Simultaneously, The Gentlemen group has escalated its operations, targeting Romanian energy producers and global manufacturers like Tempel. Both groups utilize a sophisticated double-extortion model, exfiltrating sensitive corporate data and intellectual property before deploying encryption payloads. This strategy ensures leverage even if the victim possesses robust backup recovery systems, as the threat of public data exposure remains a potent motivator for payment.\n\n## Technical Details\nThe Gentlemen group is known to exploit a variety of critical vulnerabilities to gain initial access, including CVE-2024-55591 and CVE-2025-32433. Their toolkit frequently includes the React2Shell remote code execution (RCE) tool and custom data exfiltration scripts designed to bypass standard EDR solutions. GlobalSecretGroup appears to favor credential harvesting and the exploitation of unpatched VPN concentrators. Once initial access is established, they move laterally using Cobalt Strike and encrypt files using a variant of the Chaos ransomware engine. In the recent attack on Lockheed Architectural Solutions, the actors reportedly spent less than 48 hours in the environment before triggering the encryption phase, demonstrating a highly efficient attack lifecycle.\n\n## Attribution Assessment\nWhile The Gentlemen has been linked to Iranian-aligned interests in some technical reports, their primary motivation remains financial, operating a sophisticated RaaS platform that recruits affiliates globally. GlobalSecretGroup is currently assessed as a cybercriminal syndicate, possibly a splinter group from older, disrupted operations like LockBit or Black Basta, given their similar TTPs and rapid victim acquisition. The group's focus on US-based automotive and architectural firms suggests a targeted campaign against the industrial supply chain.\n\n## Implications\nThe targeting of architectural and automotive supply chains suggests a shift toward victims with high-pressure operational requirements. For companies like Johnson City Honda, the disruption of sales and service data can lead to immediate revenue loss. For architectural firms, the theft of proprietary designs and blueprints poses a long-term competitive risk. The continued success of these groups highlights the ongoing vulnerability of the mid-market supply chain to RaaS affiliates.\n\n## Recommendations\nOrganizations should immediately prioritize patching critical CVEs in external-facing infrastructure, particularly VPNs and remote access gateways. Implementing strict Multi-Factor Authentication (MFA) across all services is essential to prevent credential-based entry. Furthermore, maintaining immutable, offline backups and conducting regular tabletop exercises for ransomware response are critical for resilience. Encrygma recommends a 'Zero Trust' architecture to limit lateral movement once a perimeter breach occurs.
ENCRYGMA
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Share
Back to News Room