Ransomware victim disclosure
← All victimsMBM sp. z o.o. sp. k.
listed as MBM · Claimed by Thegentlemen · listed 5 months ago
Status timeline
- ListedJan 24, 2026
- Data leakeddate unknown
At a glance
- Group
- Thegentlemen
- Status
- Data leaked
- Country
- Poland
- Listed on leak site
- Jan 24, 2026
About the victim
AI dossier — public-source company profileMBM sp. z o.o. sp. k. is a Polish professional services firm headquartered in Gliwice, with an additional branch in Bielsko-Biała. The company provides compliance training, GDPR implementation, occupational health and safety (BHP) audits, and data protection documentation services to clients across the education, public administration, and business sectors throughout Poland.
- Industry
- Compliance Training & Data Protection Consulting
- Address
- ul. Łabędzka 22, Gliwice, Poland
Attack summary
Severity: high — The victim is a GDPR and data protection consultancy whose systems likely contain sensitive personal data of numerous clients from education, government, and business sectors. Data_published status indicates exfiltration has occurred; exposure of a compliance firm's client PII and documentation carries significant regulatory and reputational risk.The group 'thegentlemen' claims to have attacked MBM and lists the disclosure status as data_published, indicating exfiltration and publication of data; however, the leak post content was blocked by an anti-bot verification page and no specific data claims or proof details are directly visible.
Data the group says was taken
AI dossier — extracted from the leak post- Client data protection documentation
- GDPR compliance records
- Training certificates and materials
- Personal data of training participants
- Internal business documents
What the group claims
https://mbm.edu.pl MBM is a Polish company specializing in professional training, compliance support, and implementation of mandatory procedures for both public institutions and private organizations across the country. They have over eight years of experience delivering vocational training, advisory services, audits, and ready‑to‑use documentation tailored to legal requirements, particularly in areas such as data protection and workplace obligations. Their services include courses on personal data protection and assistance in meeting the requirements of current data privacy laws, helping clients align with GDPR‑related duties and other legal obligations concerning handling and safeguarding personal information.
The leak post
captured from the group's siteGentlecloud Protection 🛡️ Gentlecloud Verifying your browser... Initializing security checks... I'm not a bot
Sources
- Victim sitembm.edu.pl
- Leak posthttp://tezwsse5czllksjb7cwp65rvnk4oobmzti2znn42i43bjdfd2prqqkad.onion
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

