Ransomware victim disclosure
← All victimsGlobal Group
Claimed by Thegentlemen · listed 4 months ago
Status timeline
- ListedFeb 15, 2026
- Data leakeddate unknown
At a glance
- Group
- Thegentlemen
- Status
- Data leaked
- Country
- India
- Listed on leak site
- Feb 15, 2026
About the victim
AI dossier — public-source company profileGlobal Group is a Pune-based industrial real estate and development company with over 15 years of experience. The company specialises in industrial park development, built-to-suit lease alternatives, land acquisition, project management, and warehouse logistics, having developed more than 50 industrial facilities across more than 1,800 acres. It serves over 250 multinational clients and is led by Chairman Sanjiv Aurora and Managing Director Manoj Hingorani.
- Industry
- Industrial Real Estate & Park Development
- Address
- Pune, Maharashtra, India
Attack summary
Severity: medium — The disclosed status is 'data_published', suggesting data has been released, but the leak post is inaccessible and provides no verifiable proof, data inventory, or details on regulated/sensitive data exposure. Moderate severity is assigned given the publication claim without confirmable evidence.The ransomware group 'thegentlemen' has listed Global Group under a 'data_published' status, indicating claimed exfiltration and/or publication of data; however, the leak post itself was blocked by a bot-verification page and yielded no specific details about the nature or volume of data stolen or published.
What the group claims
globalgroup.co.in zoominfo.com/c/global-group/437399408 Global Group is a leading construction and real estate company based in Pune, specializing in industrial development and turnkey solutions. With over 15 years of experience, they offer services such as Industrial Park Development, Built-to-Suit lease alternatives, Land Acquisition Solutions, Project Management, and Warehouse Logistics. Their commitment to safety, integrity, and quality has earned them a reputation as a trusted partner
The leak post
captured from the group's siteGentlecloud Protection 🛡️ Gentlecloud Verifying your browser... Initializing security checks... I'm not a bot
Sources
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

