Breaches · 1 day ago
CloudSEK says an affiliate of The Gentlemen ransomware-as-a-service group, Azazel, ran a parallel leak site called Leakned while extorting more than two dozen victims across several sectors. The report says he kept the payments himself instead of routing them through the gang, and stored several terabytes of stolen victim data on servers he controlled.
That matters because the leak site and the money trail were no longer under the operator’s control. In plain terms, the affiliate was not just selling access to the ransomware brand; he was running his own extortion channel, publishing data there, and pocketing the proceeds, so the named gang did not fully control where the data sat or who got paid.
For incident responders and threat teams, that means a RaaS label can hide a split operation: the operator, the affiliate, and the data repository may all be different. If the affiliate has his own infrastructure, counting victims or tracking publication on the group’s main leak site can miss the real exposure.
1 source covering this story
Ransomware Affiliate Double-Crosses Operator to Steal Victim Funds
An affiliate of The Gentlemen RaaS group ran a parallel leak site during extortion of two dozen victims
Part of the PlainSec briefing for 2026-10-07