
Check Point Research
Check Point's threat-research division; gained C2 visibility into The Gentlemen's 1,570+ victim network.
Check Point Research infiltrated a SystemBC command server used by The Gentlemen ransomware group in May 2026, surfacing 1,570 confirmed victims, the most detailed public picture of the group's reach to date.
Last refreshed: 3 August 2026 · Appears in 1 active topic
Did Check Point Research notify the 1,570 Gentlemen ransomware victims it identified?
Timeline for Check Point Research
Mentioned in: Qilin's own affiliate now outposts it
Cybersecurity: Threats and DefencesGained visibility on 1,570 Gentlemen ransomware victims via a compromised SystemBC C2 server
Cybersecurity: Threats and Defences: KB5091157, Gentlemen C2 intel, ENISA CNAs: in briefBackground
Check Point Research is the threat-intelligence and vulnerability research division of Check Point Software Technologies, one of the oldest publicly traded cybersecurity companies. In May 2026, it identified and monitored a SystemBC command-and-control server operated by The Gentlemen RaaS, gaining visibility into at least 1,570 confirmed victims across the group's global operations, the most comprehensive public picture of that group's reach to date .
Check Point Research publishes monthly and annual threat intelligence including the widely cited Global Threat Index, operating autonomously from Check Point's commercial product teams. It is a distinct entity from Check Point Software's product division, which separately disclosed the CVE-2026-50751 VPN zero-day; the 90 per cent Gentlemen affiliate-revenue figure sometimes attributed to Check Point Research in fact comes from the leak-site tracker ransomware.live, not from this division's own reporting.
The C2 monitoring technique, identifying and gaining access to a threat actor's command infrastructure, is a high-value intelligence collection method that can reveal victim lists, operational schedules and malware configurations. That Check Point Research achieved this against an active top-tier ransomware operation suggests either a misconfigured C2 or a deliberate law-enforcement cooperation effort, though neither has been confirmed on the record.