The Thialf cyberattack has been claimed by the ransomware group known as The Gentlemen, which is threatening to publish allegedly stolen data unless the Dutch ice arena pays a ransom.
Thialf, based in Heerenveen, confirmed that it had experienced a cyberattack. However, the venue said its investigation found no material impact on its data or operational processes.
The incident is significant because Thialf is set to host long-track speed skating events during the 2030 Winter Olympics.
Thialf says operations and data were not compromised
Thialf is one of the Netherlands’ best-known ice arenas and serves as the home venue for the Dutch national speed skating team. It also hosts short-track speed skating, figure skating and ice hockey events.
In a statement, the arena described the incident as a cyberattack with minimal impact. It said internal and external security specialists launched a forensic investigation as soon as the attack was discovered.
According to Thialf, the investigation found that its data and operational systems had not been affected or compromised.
The venue said relevant parties were informed during the investigation but did not disclose further technical details.
The Gentlemen claims responsibility
The Gentlemen ransomware group has claimed responsibility for the Thialf cyberattack.
The group, also tracked as Storm-2697, has been active since summer 2025. It has claimed several victims in the Netherlands, including the Institute for the Dutch Language.
The criminals have reportedly threatened to release all data taken from Thialf if the organisation does not pay within the next few days. However, the group’s claims have not been independently verified.
Ransomware group uses double extortion tactics
Microsoft warned about The Gentlemen in May 2026, describing it as a financially motivated ransomware operation.
The group reportedly began as a closed operation before launching a ransomware-as-a-service platform for affiliates in September 2025. It has since sought to recruit new partners, including penetration testers and initial-access brokers.
Like many modern ransomware groups, The Gentlemen reportedly uses double extortion. This means attackers may both encrypt systems and steal sensitive data, then threaten to publish the information if a victim refuses to pay.
Known vulnerabilities reportedly used in attacks
Security firms Group-IB and Palo Alto Networks have linked The Gentlemen to attacks exploiting known vulnerabilities.
Reported targets include Fortinet FortiOS, the Erlang/OTP SSH server, Windows SMB and React2Shell. Exploiting unpatched systems can give ransomware operators an initial foothold in a victim’s network.
For now, Thialf maintains that the cyberattack did not materially disrupt the arena or compromise its data.


0 responses to “Thialf Cyberattack: Ransom Gang Threatens Dutch Ice Arena”