Ransomware victim disclosure
← All victimsFGF - Faculdades e Universidades
listed as Fgf Colleges & Universities · Claimed by Thegentlemen · listed 4 months ago
Status timeline
- ListedFeb 10, 2026
- Data leakeddate unknown
At a glance
- Group
- Thegentlemen
- Status
- Data leaked
- Country
- Brazil
- Sector
- Education
- Listed on leak site
- Feb 10, 2026
About the victim
AI dossier — public-source company profileFGF (fgf.edu.br) is a Brazilian higher education institution group operating colleges and universities. Based in Brazil, it offers undergraduate and postgraduate programs across multiple campuses. The organization operates under the broader Brazilian private higher education sector.
- Industry
- Higher Education
Attack summary
Severity: high — Status is confirmed data_published against an educational institution, which likely holds PII of students, staff, and financial records at scale; however, no specific data inventory or volume is confirmable from the truncated post.The group 'thegentlemen' claims to have attacked FGF Colleges & Universities and has published data (disclosed status: data_published), though the leak post content is obscured by a bot-verification page and no specific data types or ransom amount are stated.
What the group claims
fgf.edu.br zoominfo.com/c/fgf/1128423083 UNIGRANDE is a higher education institution that offers a wide range of undergraduate programs including Bachelor's and Technological degrees, with courses available in both virtual and face-to-face modalities. The institution aims to provide educational opportunities for students and supports them through various admission processes such as online assessments and ENEM scores. Targeting prospective students, UNIGRANDE facilitates access to quality
The leak post
captured from the group's siteGentlecloud Protection 🛡️ Gentlecloud Verifying your browser... Initializing security checks... I'm not a bot
Sources
- Victim sitefgf.edu.br
- Leak posthttp://tezwsse5czllksjb7cwp65rvnk4oobmzti2znn42i43bjdfd2prqqkad.onion
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

