RANSOMWARE VICTIMDUPLICATE CLAIM

Line Up Korea

lineupkorea.com
THEGENTLEMEN📍 South Korea (KR)📅 February 17, 2026
8
same group

Attack Intelligence

Line Up Korea was compromised in a ransomware attack attributed to THEGENTLEMEN in February 2026. The organization, operating in an undisclosed sector in South Korea, was added to the group's data leak site as part of an extortion campaign.

THEGENTLEMEN operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.

lineupkorea.com Lineup Korea Co., Ltd. is a South Korean IT consulting company established in 2015 and located in Goyang City, Gyeonggi Province . The company has been recognized as an excellent youth-friendly small business by the Ministry of Employment and Labor and employs around 70 people . With annual sales of approximately 24.7 billion KRW, the company specializes in IT system engineering and infrastructure services . They are also registered as a partner with the Korea Radio Promotion Association

Additional Details

Other Victims — THEGENTLEMEN (8)

Quick Facts

CountrySouth Korea (KR)
Attack DateFeb 17, 2026
Domainlineupkorea.com
Intel Sourceransomware.live
StatusDUPLICATE CLAIM

Threat Group

THEGENTLEMEN
Motivation: financial
View group profile →

External Links

Data sourced from Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Victim listing does not imply confirmed breach — intelligence based on group claims.