Ransomware victim disclosure
← All victimsGUERREIROS seguros
Claimed by Thegentlemen · listed 6 days ago
Status timeline
- ListedJul 23, 2026
- Data leakeddate unknown
At a glance
- Group
- Thegentlemen
- Status
- Data leaked
- Country
- Portugal
- Sector
- Financial Services
- Listed on leak site
- Jul 23, 2026
About the victim
AI dossier — public-source company profileGUERREIROS seguros is a Portuguese insurance mediation company based in Faro with an office in Olhão, operating since 1990. The company mediates a broad range of insurance products including auto, health, life, home, and pet insurance, serving approximately 3,000 clients across Portugal with 7 full-time employees.
- Industry
- Insurance Mediation & Brokerage
- Address
- Faro and Olhão, Portugal
- Employees
- 7-10
- Founded
- 1990
Attack summary
Severity: high — Insurance mediation company handling sensitive personal and financial data (PII, health information, policy details) for 3,000+ clients across Portugal. Data published status indicates exfiltration confirmed. Financial services sector is regulated and sensitive.The ransomware group thegentlemen claims to have compromised GUERREIROS seguros and published data from the breach. No specific details on encryption, exfiltration method, or data categories are provided in the leak post.
Data the group says was taken
AI dossier — extracted from the leak post- client personal data
- insurance policy information
- business records
What the group claims
***.pt zoominfo.com/c/guerreiros-seguros/483718773 GUERREIROS Seguros is a professional insurance mediation company based in Faro, Portugal, operating since 1990 and officially licensed as a mediator since 1994. They specialize in a wide range of insurance solutions, including auto, health, and life insurance. With over 30 years of experience, the company focuses on helping clients manage their policies, secure competitive rates, and ensure transparent, up-to-date coverage tailored to their specific needs
Sources
- Victim siteguerreiros.pt
Source
Indexed 6 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

