Ransomware victim disclosure
← All victimsGlassdoor
Claimed by Thegentlemen · listed 21 hours ago
Status timeline
- ListedAug 30, 2026
- Data leakeddate unknown
At a glance
- Group
- Thegentlemen
- Status
- Data leaked
- Country
- United States
- Sector
- Professional Services
- Listed on leak site
- Aug 30, 2026
About the victim
AI dossier — public-source company profileGlassdoor is a U.S.-based job platform founded in 2007 where employees anonymously review companies on culture, salaries, and management. Acquired by Recruit Holdings and merged into Indeed on July 1, 2026, it hosts millions of reviews for approximately 600,000 companies and operates a freemium model monetized through employer branding tools and annual 'Best Places to Work' awards.
- Industry
- Online Recruitment & Employer Review Platform
- Founded
- 2007
Attack summary
Severity: low — Post contains only a listing/announcement with no proof files, screenshots, or specific claim of data exfiltration or operational disruption. No data inventory is disclosed.The group claims to have breached Glassdoor but provides no details on the scope, method, or type of data exfiltrated. No proof files or data samples are advertised in the post.
What the group claims
glassdoor.com is a U.S. job platform (founded 2007) where employees anonymously review companies — culture, salaries, management. It's owned by Recruit Holdings/Indeed (acquired for $1.2B in 2018; legally merged into Indeed on July 1, 2026). It hosts millions of reviews for ~600,000 companies, plus salary data and job listings. Free for job seekers, monetized via employer branding tools; it also publishes the annual "Best Places to Work" awards.
Sources
- Victim siteglassdoor.com
Source
Indexed 21 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

