RANSOMWARE VICTIM

Keretapi Tanah

THEGENTLEMEN📅 May 5, 2026
8
same group

Attack Intelligence

Keretapi Tanah was compromised in a ransomware attack attributed to THEGENTLEMEN in May 2026. The organization, operating in an undisclosed sector in Unknown, was added to the group's data leak site as part of an extortion campaign.

THEGENTLEMEN operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.

ktmb.com.my zoominfo.com/c/keretapi-tanah-melayu-berhad/21365008 KTMB (Keretapi Tanah Melayu Berhad) is Malaysia's largest and oldest railway company, with a rail network spanning 1,699 km across Peninsular Malaysia, extending into Singapore and Thailand. It operates multiple services including KTM Komuter (urban commuter trains since 1995), ETS electric intercity trains, and diesel-powered KTM Intercity trains. The company was privatized in 1992 and today offers online ticketing via its website and mobile app, with a QR-code boarding system

Other Victims — THEGENTLEMEN (8)

Quick Facts

Attack DateMay 5, 2026
Intel Sourceransomlook

Threat Group

THEGENTLEMEN
Motivation: financial
View group profile →

External Links

Data sourced from Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Victim listing does not imply confirmed breach — intelligence based on group claims.