The extortion crew that has repeatedly hit US hospitals was the busiest ransomware group in Japan through the first half of 2026, according to new research from Cisco Talos.
Talos counted 90 ransomware incidents against Japanese organizations from January through July, a 4.7% rise over the same stretch last year. The Gentlemen accounted for 14 of them, the most of any group. Qilin and SafePay followed with seven each. Listings on The Gentlemen’s own leak site climbed from 48 in January to 105 in July, roughly a 2.2-fold jump, and Talos said Russian-speaking actors may be involved.
Small and mid-sized companies took the brunt. Organizations capitalized under JPY 1B made up about 80% of victims, up roughly 13 points from a year earlier. Manufacturing led the sectors at 34%, followed by information and communications at 11% and services at 9%. Healthcare and social assistance accounted for about 5%.
The finding matters for medical defenders because of who The Gentlemen are, not where they struck this time. The group has claimed a string of US healthcare victims this year, from a Mississippi eye clinic to a hospital operator, and its playbook pairs stolen clinical data with public leak threats. A crew that scales up in one market tends to carry those tactics into the next.