Ransomware victim disclosure
← All victimsVexin Normand
Claimed by Thegentlemen · listed 3 months ago
Status timeline
- ListedMar 18, 2026
- Data leakeddate unknown
At a glance
- Group
- Thegentlemen
- Status
- Data leaked
- Country
- France
- Listed on leak site
- Mar 18, 2026
About the victim
AI dossier — public-source company profileVexin Normand (Communauté de Communes du Vexin Normand) is a French intercommunal public body located in the Normandy region of France. It groups several municipalities to coordinate local public services and territorial development. Based on the domain cdc-vexin-normand.fr, it is a public administrative structure ('Communauté de Communes').
- Industry
- Regional Community Development / Local Government or Public Administration
Attack summary
Severity: high — The victim is a public administrative/local government entity in France; data_published status indicates confirmed exfiltration and release of data. Government/public sector records likely contain citizen PII and administrative data, warranting a high severity rating, though critical cannot be confirmed without visibility into the actual leak post contents.The group 'thegentlemen' claims to have attacked Vexin Normand and has published data (disclosed status: data_published), though the leak post content is inaccessible due to a bot-verification screen, preventing confirmation of specific claims about encryption or exfiltration.
What the group claims
cdc-vexin-normand.fr zoominfo.com/c/cdc-vexin-normandfr/1316064619 The Communauté de Communes du Vexin Normand offers a wide range of services including health care, public services, and cultural activities to support the local community. It focuses on various sectors such as health, education, mobility, and economic development, catering to residents and businesses in the Vexin Normand area. The community also promotes tourism and recreational activities, providing facilities like swimming pools, gyms, and libraries. Their initiatives aim to enhance the quality of life and foster a connected and sustainable environment for all inhabitants
The leak post
captured from the group's siteGentlecloud Protection 🛡️ Gentlecloud Verifying your browser... Initializing security checks... I'm not a bot
Sources
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

