CloudSEK says an affiliate of The Gentlemen ransomware-as-a-service group, Azazel, ran a parallel leak site called Leakned while extorting more than two dozen victims across several sectors. The report says he kept the payments himself instead of routing them through the gang, and stored several terabytes of stolen victim data on servers he controlled.
That matters because the leak site and the money trail were no longer under the operator’s control. In plain terms, the affiliate was not just selling access to the ransomware brand; he was running his own extortion channel, publishing data there, and pocketing the proceeds, so the named gang did not fully control where the data sat or who got paid.
For incident responders and threat teams, that means a RaaS label can hide a split operation: the operator, the affiliate, and the data repository may all be different. If the affiliate has his own infrastructure, counting victims or tracking publication on the group’s main leak site can miss the real exposure.