Disney Family
Attack Intelligence
Disney Family was compromised in a ransomware attack attributed to THEGENTLEMEN in July 2026. The organization, operating in the Financial Services sector in United States, was added to the group's data leak site as part of an extortion campaign.
THEGENTLEMEN operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.
This critical data breach involves Disney Family / Shamrock Holdings, the private investment firm and family office established by Roy E. Disney to manage the wealth of the Disney family branch, rather than the public Walt Disney Company. The compromised dataset, totaling over 800 GB and spanning from the 1980s to June 2026, exposes highly sensitive information across 14 critical categories, including family trusts, tax administration, and private equity fund management. Key victims include prominent figures such as Abigail Disney, Roy P. Disney, and Stanley Gold, whose personal financial records, passports, and KYC documents were leaked alongside detailed trust instruments for the "Disney Grandchildren Trusts." The breach reveals active operational data, including recent payroll records, bank reconciliations with CNB, and subscription agreements for funds like the Shamrock Israel Growth Fund. With unencrypted databases, embedded ERP credentials etc..