The Gentlemen ransomware group claims it breached workplace review and job platform Glassdoor and has threatened to publish allegedly stolen information after a 172-hour countdown.
The group added Glassdoor to its leak site, but it has not released samples of the supposed data. As a result, the claimed Glassdoor data breach remains unconfirmed, and the type and volume of information allegedly taken are unknown.
It is unclear whether the data could involve internal company material, employee details, job seeker information, or a combination of records.
Glassdoor holds data from millions of users and companies
Glassdoor publishes anonymous workplace reviews, salary information and job listings submitted by current and former employees.
The platform has up to 67 million unique monthly visitors, reviews for more than two million companies and millions of active job listings. That scale could make it a valuable target for criminals if the claim proves accurate.
Employment platforms aggregate large amounts of information about employers, applicants and workforce trends. Researchers said such data can potentially help attackers identify businesses undergoing staffing changes or hiring for specific roles.
Data could support phishing and reconnaissance
Information about job applicants could help criminals create believable phishing messages that appear to come from a company the person has applied to.
Corporate email addresses, recruitment details and account structures could also make social-engineering campaigns more targeted. Attackers may be able to combine this material with information from earlier breaches to identify exposed credentials or other sensitive details.
Researchers noted that job advertisements can themselves offer reconnaissance value. A sudden rise in openings for incident response, forensics or security operations roles may reveal that a company is dealing with an internal security problem.
Glassdoor has been contacted for comment. The company had not publicly confirmed the alleged incident at the time of publication.
Gentlemen uses double-extortion tactics
Gentlemen operates a ransomware-as-a-service model, sharing profits with affiliates that conduct attacks. The group uses double extortion, which combines data theft and encryption with demands for payment.
Researchers link the group to ArmCorp, a former affiliate cluster of the Qilin ransomware operation. The split reportedly followed a payment dispute in July 2025, although evidence suggests the group’s separation had already been planned.
Gentlemen has previously claimed attacks against organisations including NATO contractor Indra and the Dutch ice arena Thialf.
Job and recruitment platforms have repeatedly attracted criminals because they can hold large stores of personal information. Several recent incidents have exposed resumes, recruitment data, applicant contact details and credentials, creating risks of identity theft and targeted scams.


0 responses to “Gentlemen Ransomware Claims Glassdoor Data Breach”