Who are 'The Gentlemen' — the new ransomware group attacking hospitals with insider trading tactics
Executive Summary
Brian Krebs has published a comprehensive investigation identifying the operators behind the “The Gentlemen” ransomware group, a new active threat against hospitals and health systems that applies tactics similar to insider trading: they study the financial statements of victims before setting the ransom amount, leveraging information obtained from prolonged initial access.
Unlike groups like LockBit or BlackCat that demand fixed ransoms based on organization size, The Gentlemen personalizes each demand based on actual payment capacity: they analyze operating revenue, cybersecurity budget, and insurance policies.
Key Points
- Extended reconnaissance tactics: dwell times of 60-90 days collecting financial intelligence
- Ransom personalization: amount calculated based on operating revenue and insurance coverage
- Operating model: core of 5-7 people (presumably Eastern Europe), Latin American affiliates for regional operations
- Victim geography: US hospitals (60%), Spain, Germany, France (30%), LatAm (10%)
Regulatory Implications
HIPAA: The extended dwell time (60-90 days) means HIPAA §164.312(b) logs must maintain at least 6 months of audit to investigate similar incidents.
ENS: CCN-STIC 802 (log management) requires adequate retention. For category ALTA, audit logs must be kept at least 5 years.
NIS2: Hospitals must report unauthorized access even if there is no encryption, if it affects personal data.
Recommendation
- Advanced EDR with lateral movement detection: The Gentlemen techniques include mimikatz, RDP lateral, exfiltration via DNS tunneling. Classic signature-based EDR does not detect this.
- Proactive threat hunting: don’t wait for encryption. Search for IoCs in DC, AD, VPN logs regularly. If your SOC only reacts to alerts, you’re already late.
- Strict network segmentation: the finance server should not have a route to the EHR server. If The Gentlemen manages to pivot between them, the attack is greatly complicated.
- Limiting public financial information: consider reducing the detail of annual reports, IT budgets, insurance coverage. What’s public is reconnaissance for attackers.
- Anomalous access monitoring to financial files: CFO accessing PACS, or finance system accessing EHR, should generate immediate alert.
- Cyber insurance with anti-reconnaissance clause: some policies exclude payments if it is demonstrated that the organization facilitated public financial reconnaissance.
Source: Krebs on Security - Who Runs the Ransomware Group ‘The Gentlemen?’
This analysis is part of HealthSec, the weekly briefing on healthcare cybersecurity.