RANSOMWARE VICTIMDUPLICATE CLAIM

Grupo Tawa

grupotawa.com
THEGENTLEMEN📍 PE (PE)📅 March 23, 2026
8
same group

Attack Intelligence

Grupo Tawa was compromised in a ransomware attack attributed to THEGENTLEMEN in March 2026. The organization, operating in an undisclosed sector in PE, was added to the group's data leak site as part of an extortion campaign.

THEGENTLEMEN operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.

grupotawa.com zoominfo.com/c/grupo-tawa/459512890 Grupo Tawa is a business group operating in Peru and Chile, dedicated to providing comprehensive business solutions that allow clients to focus on their core competencies. With over 18 years of experience, they offer expertise in personnel solutions, process outsourcing, cleaning, maintenance, and commercial management. The group serves more than 2,500 clients and employs over 15,000 individuals annually. Their commitment to excellence positions them as a reliable partner for companies across various industries

Additional Details

Other Victims — THEGENTLEMEN (8)

Quick Facts

CountryPE (PE)
Attack DateMar 23, 2026
Domaingrupotawa.com
Intel Sourceransomware.live
StatusDUPLICATE CLAIM

Threat Group

THEGENTLEMEN
Motivation: financial
View group profile →

External Links

Data sourced from Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Victim listing does not imply confirmed breach — intelligence based on group claims.