RANSOMWARE VICTIMENERGYDUPLICATE CLAIM

Nathalin Group

nathalin.com
THEGENTLEMEN📍 Thailand (TH)📅 February 25, 2026
8
same group

Attack Intelligence

Nathalin Group was compromised in a ransomware attack attributed to THEGENTLEMEN in February 2026. The organization, operating in the Energy sector in Thailand, was added to the group's data leak site as part of an extortion campaign.

THEGENTLEMEN operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.

nathalin.com zoominfo.com/c/nathalin-group-co-ltd/353727230 Nathalin Group was founded on 21st July 1987 formerly known as "Buawaree Company Limited" and had been changed to "Nathalin Co.,Ltd in September the same year. We are widely recognized as one of the largest independent operator of petroleum and chemicals tanker in Thailand. We provide various marine services to fulfill our customers need; Logistics and Storing, International Maritime, Floating Storage and Trading and Service. We have succeed in encouraging our crew to operate under international standard that we obtained ISM Code Certificate by Lloyd's register of shipping (LR), ISO 9001:2000 by SGS and participated in Tanker Management and Self-Assessment (TMSA) program, which has been verified by major oils

Additional Details

Other Victims — THEGENTLEMEN (8)

Quick Facts

CountryThailand (TH)
SectorEnergy
Attack DateFeb 25, 2026
Domainnathalin.com
Intel Sourceransomware.live
StatusDUPLICATE CLAIM

Threat Group

THEGENTLEMEN
Motivation: financial
View group profile →

External Links

Data sourced from Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Victim listing does not imply confirmed breach — intelligence based on group claims.