The ransomware group known as TheGentlemen has listed Glassdoor, a prominent US-based technology platform, as a victim on its leak site, claiming unauthorized access to the company’s systems and data. The claim appeared on August 30, 2026, and threatens to publish the alleged data once a 172-hour countdown expires. No independent verification of the breach has been completed, and the group has not released any data samples, leaving the scope of the alleged compromise unconfirmed.
Glassdoor operates as an online platform offering anonymous company reviews, salary information and job listings contributed by current and former employees. The site draws up to 67 million unique visitors monthly, hosts reviews for more than 2 million companies and maintains millions of active job postings.
TheGentlemen has been one of the most prolific ransomware operators currently being tracked, having listed 248 victims over the preceding 60 days. The group has concentrated its activity primarily in the United States and the United Kingdom, with a particular focus on the manufacturing and technology sectors. Glassdoor’s standing as a major technology platform fits within that established targeting pattern.
An analysis of stealer logs conducted by SOCRadar’s cyber threat intelligence team returned a finding of limited exposure in the sample reviewed. The analysis identified 25 records consisting entirely of consumer email addresses, pointing toward a possible pattern of customer account takeovers rather than employee credential theft. The records did not include timestamps that would place them within a specific compromise window, and no direct employee credentials appeared in the data examined.
SOCRadar cautioned that the limited findings do not rule out a broader compromise, noting that TheGentlemen could have gained access through methods outside the scope of the stealer-log analysis, such as phishing campaigns or the exploitation of exposed remote access services including VPNs or other access portals. The firm recommended continued monitoring of dark web and stealer-log sources, along with credential hygiene checks, password rotation and a review of multi-factor authentication across corporate accounts.
Platforms of this kind hold significant appeal for cybercriminals because of the breadth of workforce and employer data they accumulate. Glassdoor and comparable services compile information across thousands of organizations, offering a wide-angle view of hiring trends and workplace shifts. Should that data be compromised, attackers could exploit it to identify which companies are recruiting for specific positions or undergoing internal changes.
Job postings tied to security roles could carry particular value for attackers. A spike in listings for cybersecurity specialists, incident responders or cloud engineers may signal that an organization is responding to an internal issue. Security researchers and open-source intelligence analysts have previously relied on public job postings as a reconnaissance tool, noting that a sudden wave of openings for forensics or security operations roles, particularly when vaguely worded or urgently posted, can hint that an incident has occurred within a company.
Click Here For The Original Source.
