Ransomware victim disclosure
← All victimsGruppo Avanti
Claimed by Thegentlemen · listed 4 months ago
Status timeline
- ListedFeb 13, 2026
- Data leakeddate unknown
At a glance
- Group
- Thegentlemen
- Status
- Data leaked
- Country
- Italy
- Listed on leak site
- Feb 13, 2026
About the victim
AI dossier — public-source company profileGruppo Avanti is an Ecuadorian company offering anti-fraud and cybersecurity solutions, including real-time facial recognition, biometric electronic signatures, and identity verification services. Their products target sectors such as pharmaceuticals, retail, and courier/last-mile delivery to prevent identity fraud. The company also provides customer experience and governance consulting services.
- Industry
- Anti-Fraud & Cybersecurity Solutions
- Address
- Ecuador
Attack summary
Severity: medium — The disclosure status is listed as data_published, suggesting exfiltration and publication of data, but the actual leak post content is inaccessible (blocked by bot protection), no specific data types, volume, or proof files are confirmed, and no ransom amount or data size is stated. A cybersecurity company being breached carries elevated sensitivity, but without confirmed regulated or sensitive data inventory, medium is appropriate.The group 'thegentlemen' claims to have attacked Gruppo Avanti and lists the disclosure status as 'data_published', indicating data has been exfiltrated and published. The leak post itself was inaccessible due to a bot-protection challenge page, so the specific data types and volume claimed cannot be confirmed from the post content.
What the group claims
gruppoavanti.com zoominfo.com/c/gruppo-avanti/459959833 Gruppo Avanti helps businesses grow by improving their processes, technology, and team skills. They work closely with companies to bring fresh ideas and practical solutions that make real differences. With deep knowledge of business practices and the latest tech, Avanti turns complex challenges into clear, successful results that help businesses work smarter and achieve more.
The leak post
captured from the group's siteGentlecloud Protection 🛡️ Gentlecloud Verifying your browser... Initializing security checks... I'm not a bot
Sources
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

