TERMINAL SEGURO // VISUALIZADOR DE DOCUMENTOS CLASSIFICADOS v3.1.7
[SYS] A verificar código de autorização: 5FC9 ... [VÁLIDO]
[SYS] A desencriptar arquivo de documentos ... [OK]
[SYS] Nível de autorização 7 — ACESSO RESTRITO
[SYS] Sessão registada. Monitorização ativa. Não copiar nem distribuir.
[SYS] A renderizar documento ...
CONFIDENCIAL — LEVEL 7 AUTORIZAÇÃO NECESSÁRIA
ID DO DOCUMENTO: FZ-5FC9-2026
DATA: 2026-05-13
DEPARTAMENTO: CRYPTOGRAPHIC OPERATIONS BRANCH
ESTADO: ATIVO -- NÃO DISTRIBUIR
INCIDENT REPORT 5FC9 -- GENTLEMEN LEAK
For thirty years we have been guessing what the inside of a ransomware operation looks like.
The Gentlemen's backend is gone from the internet now. The ████████████████████████████████████████████████████████████████████████████████
We could see the outside. The ransom notes. The leak sites. The wreckage in hospitals and factories and school districts. From that we built a picture — informed, careful, and still fundamentally a reconstruction. An outline drawn around a hole.
The people encrypting hospitals are not exceptional. They are employees ████████████████████████████████████████████████████████████████████████████████
One of the most active ransomware operations on Earth got breached. Not raided by police. Breached — by somebody else, through a weakness in their own supplier. Their back office spilled open: the chat logs, the staff roster, the ransom negotiation transcripts, the discussions about which tools to buy.
RECOMMENDATION: Maintain active monitoring of the named entities and systems. Refer requests for declassified detail to the Office of Operations. Fragment Zero.

// ENVIO DE RELATÓRIO DE TESTEMUNHA
Se possui informação relacionada com este documento, submeta o seu relato abaixo. Todas as submissões são monitorizadas.
DESIGNAÇÃO DE AGENTE
RELATÓRIO DE INCIDENTE / TEORIA