RANSOMWARE VICTIMCONSUMER SERVICESDUPLICATE CLAIM

Lotus Bedding

www.lotusbedding.com
THEGENTLEMEN📍 Thailand (TH)📅 January 20, 2026
8
same group

Attack Intelligence

Lotus Bedding was compromised in a ransomware attack attributed to THEGENTLEMEN in January 2026. The organization, operating in the Consumer Services sector in Thailand, was added to the group's data leak site as part of an extortion campaign.

THEGENTLEMEN operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.

www.lotusbedding.com https://www.zoominfo.com/c/lotus-bedding/357889420 LOTUS is Thailand's leading and most exciting bedding company. At LOTUS, inspiration comes alive through artistic expression by Lotus Design Lab. Your bed will be livened up in style with our exciting design proposals and vast collection of bedding fashion. Established in 1980, the company started off as a tiny workshop doing cut and sew using merely 3 staffs including both founders, Mr. Kamthorn and Mrs. Leena Lojanagosin. Today LOTUS is not merely having over a thousand enthusiastic staffs in the family, but it has grown into multi-national group of companies and expanded its bases to many significant markets including Belgium, Singapore, Hong Kong, to name a few. Moreover, Lotus Bedding Group has successfully diversified its business portfolio to covering other industries such as mattress, hygiene home service, ultra luxury import furniture, retail, transit media provider, aesthetic and holistic hospital, public bus transportation in Bangkok area, and real-estate development.

Additional Details

Other Victims — THEGENTLEMEN (8)

Quick Facts

CountryThailand (TH)
SectorConsumer Services
Attack DateJan 20, 2026
Domainwww.lotusbedding.com
Intel Sourceransomware.live
StatusDUPLICATE CLAIM

Threat Group

THEGENTLEMEN
Motivation: financial
View group profile →

External Links

Data sourced from Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Victim listing does not imply confirmed breach — intelligence based on group claims.