TERMINAL SEGURO // VISOR DE DOCUMENTOS CLASIFICADOS v3.1.7
[SYS] Verificando código de autorización: 5FC9 ... [VÁLIDO]
[SYS] Descifrando archivo de documento ... [OK]
[SYS] Nivel de autorización 7 — ACCESO RESTRINGIDO
[SYS] Sesión registrada. Monitoreo activo. No copiar ni distribuir.
[SYS] Renderizando documento ...
CLASIFICADO — LEVEL 7 AUTORIZACIÓN REQUERIDA
ID DE DOCUMENTO: FZ-5FC9-2026
FECHA: 2026-05-13
DEPARTAMENTO: CRYPTOGRAPHIC OPERATIONS BRANCH
ESTADO: ACTIVO -- NO DISTRIBUIR
INCIDENT REPORT 5FC9 -- GENTLEMEN LEAK
For thirty years we have been guessing what the inside of a ransomware operation looks like.
The Gentlemen's backend is gone from the internet now. The ████████████████████████████████████████████████████████████████████████████████
We could see the outside. The ransom notes. The leak sites. The wreckage in hospitals and factories and school districts. From that we built a picture — informed, careful, and still fundamentally a reconstruction. An outline drawn around a hole.
The people encrypting hospitals are not exceptional. They are employees ████████████████████████████████████████████████████████████████████████████████
One of the most active ransomware operations on Earth got breached. Not raided by police. Breached — by somebody else, through a weakness in their own supplier. Their back office spilled open: the chat logs, the staff roster, the ransom negotiation transcripts, the discussions about which tools to buy.
RECOMMENDATION: Maintain active monitoring of the named entities and systems. Refer requests for declassified detail to the Office of Operations. Fragment Zero.

// ENVÍO DE INFORME DE TESTIGO
Si tiene información relacionada con este documento, envíe su relato a continuación. Todas las entregas son monitoreadas.
DESIGNACIÓN DE AGENTE
INFORME DE INCIDENTE / TEORÍA