RANSOMWARE VICTIM

Diviso Grupo Financiero

THEGENTLEMEN📅 April 29, 2026
8
same group

Attack Intelligence

Diviso Grupo Financiero was compromised in a ransomware attack attributed to THEGENTLEMEN in April 2026. The organization, operating in an undisclosed sector in Unknown, was added to the group's data leak site as part of an extortion campaign.

THEGENTLEMEN operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.

diviso.pe zoominfo.com/c/diviso-grupo-financiero-sa/372139811 Diviso Grupo Financiero S.A. is a Lima-based financial holding company founded in 2003 (formerly NCF Inversiones SA, rebranded in November 2013). With around 1,000–5,000 employees and led by CEO José Romero Tapia, it offers a comprehensive portfolio of capital market services through its two main subsidiaries — DIVISO Fondos (mutual and investment funds) and DIVISO Bolsa (stock brokerage). The group holds strategic stakes in major regional exchanges, including the Lima Stock Exchange (BVL), CAVALI, and the Chilean Products Exchange. It is publicly traded on the Lima Stock Exchange under ticker DIVIC1 with a market cap of ~313 million PEN

Other Victims — THEGENTLEMEN (8)

Quick Facts

Attack DateApr 29, 2026
Intel Sourceransomlook

Threat Group

THEGENTLEMEN
Motivation: financial
View group profile →

External Links

Data sourced from Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Victim listing does not imply confirmed breach — intelligence based on group claims.