LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Agrocampo Listed by The Gentlemen Ransomware Group

HIGH severityUnverified claimHow we verify

Agrocampo Listed by The Gentlemen Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·September 21, 2026
Agrocampo Listed by The Gentlemen Ransomware Group

Reported September 21, 2026.

HIGH
Severity
September 21, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Agrocampo was listed by The Gentlemen ransomware group on 21 September 2026. Individuals are advised to check for any unusual activity and to monitor their personal information.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

A ransomware group known as The Gentlemen has listed Agrocampo on its leak site, according to a report dated September 21, 2026. The listing names the Colombian veterinary and agricultural supplier; it does not, on the public record provided here, state that any systems were entered or that any files left the company. Agrocampo has not publicly confirmed the claim as of writing. For customers, partners, veterinarians, and staff who deal with the firm, the practical question is conditional: if personal or business data were ever copied in an intrusion of this kind, what would that mean and what can people do about it.

Public detail is limited. The number of people who might be affected is unknown, and the listing does not name specific data types. That uncertainty is itself the story readers need: a leak-site claim is pressure and marketing from an extortion crew, not a verified inventory of stolen records.

Inside the listing

The Gentlemen has listed Agrocampo on its leak site. The report associated with that listing is dated September 21, 2026. Beyond the organisation’s name and related public identifiers referenced in the summary material (including agrocampo.com.co and a commercial profile entry), the facts supplied here do not describe how any alleged intrusion would have occurred, when it would have begun, what volume of data might be involved, or whether any deadline or sample files were posted.

People affected are recorded as unknown. Data types named as exposed are not disclosed. Nothing in the available record establishes that files were taken, published, or sold. The listing should be read as an unverified claim by the group, not as a claimed breach report from the company, a regulator, or an independent breach index.

Inside The Gentlemen

The Gentlemen is known in public reporting as a ransomware and extortion actor that follows a pattern common to many such crews: encrypt or threaten encryption of business systems, exfiltrate data or claim to have done so, and pressure victims by listing them on a dedicated leak site if payment is not made. Groups in this category typically advertise alleged victims, sometimes with countdown language or purported file samples, to increase leverage. Their public posts are designed to coerce; they are not audited disclosures.

Well-documented activity by actors of this type often includes double-extortion messaging—ransom for decryption keys plus a threat to release data—and opportunistic targeting across sectors rather than a single industry focus. For this specific listing, only what the facts state applies: the group has named Agrocampo. Any broader claim about what was taken from this company, or how, is not established in the material provided and should not be treated as proven.

About Agrocampo

Agrocampo S.A.S. is described in public business information as Colombia’s first and only veterinary hypermarket, founded in 1979 by veterinarian Alfonso Villa and headquartered in Bogotá. It is characterised as a leading distributor of veterinary drugs and agricultural supplies, with more than 45 years in the market. Operations described in that same public profile include a flagship hypermarket in Bogotá and a large distribution centre of roughly 8,000 m² in Cota, operating around the clock, and delivery of more than 15,000 products to about 980 municipalities—covering the large majority of Colombia’s territory—through e-commerce, a call centre, and a network of partner veterinary stores.

Organisations in wholesale veterinary pharmaceuticals and farm supplies sit at the junction of animal health, rural commerce, and regulated product distribution. They typically maintain supplier and customer account records, order and logistics data, and internal staff information. A credible compromise in this sector would matter because those relationships span clinics, farms, partner stores, and households that buy animal-health products—not because any such compromise has been proven here.

What data was at risk

The facts state that data types named as exposed are not disclosed. It is therefore not possible to say which fields, databases, or document stores—if any—were involved. Asserting a concrete inventory would repeat the attacker’s marketing as if it were an audit.

If files were taken from a firm of this kind, organisations in veterinary and agricultural distribution typically hold some mix of the following, depending on systems and retention: customer and partner contact details; purchase and delivery histories; invoices and payment references; veterinary-practice or farm account identifiers; employee directory and HR-related records; and internal documents tied to inventory, pricing, and logistics. Whether any of that exists in an attacker’s hands in this case remains unconfirmed. The listing does not establish a verified list of exposed data.

What's at stake

For individuals and small businesses that buy from or sell through a national veterinary supplier, the conditional risks are familiar. If contact and account data were copied, phishing and social-engineering attempts could become more convincing—messages that reference real orders, clinic names, or delivery patterns. If financial or identity-adjacent details were included, account takeover and invoice fraud become more plausible. If employee data were involved, staff could face targeted scams. None of that is a finding that Agrocampo’s data is “out”; it is the standard residual risk profile when a leak-site claim appears and contents are unknown.

For the organisation, an unverified listing still creates reputational and operational pressure: customers ask questions, partners reassess trust, and legal or regulatory notice duties may need internal review even while facts remain unsettled. A listing alone does not prove negligence, successful theft, or the scale of any event. It proves that a named extortion group chose to put the company’s name on a public pressure page.

Steps worth taking either way

Because the incident is unconfirmed and the data types are undisclosed, the useful posture is precaution without panic. Steps that remain sensible whether or not this claim is ever substantiated include:

Public confirmation from Agrocampo, a regulator, or a reputable breach registry would change what can be said with confidence. Until then, the accurate summary is narrow: The Gentlemen has listed Agrocampo on its leak site as of the September 21, 2026 report; the company has not publicly stated the incident in the material available here; affected-person counts and data types remain unknown; and ordinary vigilance around phishing, credentials, and financial monitoring is warranted if your relationship with the firm means your details could ever have been in scope.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

SourceLeak-site claim data adapted from RansomLook.io, used under CC BY 4.0.

CompanyAgrocampo security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See Agrocampo’s full breach history →

More recent breaches

Magnetos y Refacciones Listed by The Gentlemen Ransomware GroupSeptember 21, 2026Pajulahti Listed by The Gentlemen Ransomware GroupSeptember 21, 2026Craisa Listed by The Gentlemen Ransomware GroupSeptember 21, 2026Trifecta Software Listed by The Gentlemen Ransomware GroupSeptember 21, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Agrocampo Listed by The Gentlemen Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by thegentlemen — unverified claim, pending independent verification. Leak-site claim data adapted from RansomLook.io, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram