LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Aware Listed by The Gentlemen Ransomware Group

HIGH severityUnverified claimHow we verify

Aware Listed by The Gentlemen Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·October 3, 2026
Aware Listed by The Gentlemen Ransomware Group

Reported October 3, 2026.

HIGH
Severity
October 3, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Aware was listed by The Gentlemen ransomware group on 03 October 2026; the group claims to hold data belonging to an undisclosed number of people, but no occurrence date has been established and the organisation has made no statement. Anyone who has shared personal information with Aware should review their accounts and consider protective steps such as changing passwords and enabling multi-factor authentication.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

A ransomware group known as The Gentlemen has listed Aware, a U.S. biometrics software company, on its leak site. The listing, reported on October 03, 2026, does not state that any customer, employee, or partner data has actually left the company. As of writing, Aware has not publicly confirmed the claim. For people who use identity-verification or biometric services that may connect to firms in this sector, the practical question is conditional: if files were copied, what kinds of information might be involved, and what steps reduce risk either way.

Public detail remains limited. The number of people potentially affected is unknown, and the listing does not name specific data types. What follows separates the group's claim from established background on the actor and the industry, without treating the accusation as proven fact.

What the listing says

According to the leak-site listing attributed to The Gentlemen, Aware appears among organizations the group has named. The reported material associated with the claim references roughly 400 GB in connection with Aware, Inc., and points to public company identifiers such as aware.com and related business-profile pages. The listing itself does not, in the available record, spell out a theft method, an intrusion timeline, a ransom demand amount, or a confirmed inventory of files.

People affected are listed as unknown. Data types named as exposed are not disclosed. The company has not publicly confirmed the claim as of writing. A leak-site entry is a claim by the operators who posted it; it may be incomplete, recycled, exaggerated, or incorrect. Nothing in the available facts establishes that data was taken, published, or sold.

The group behind it: The Gentlemen

The Gentlemen is a ransomware and extortion-style group that, like others in this category, has used dedicated leak sites to pressure organizations by naming them and threatening to publish material. Public reporting on such groups generally describes double-extortion patterns: encrypting systems where they can, and separately claiming to hold copied data to increase leverage. Tactics commonly associated with this class of actor include phishing or compromised remote access as initial footholds, lateral movement inside networks, and staged claims on a leak blog when negotiations stall—though none of those methods are confirmed for this specific listing.

For this Aware entry, the only incident-specific assertion in the facts is that the group has listed the company and that the claim is tied to a reported figure of about 400 GB and public descriptions of the firm. The group claims association with Aware; that claim has not been independently verified in the material provided. Readers should treat volume figures and marketing-style descriptions on leak sites as unverified assertions, not as audited inventories.

Who is Aware?

Aware, Inc. is described in public company materials as a U.S. biometrics software firm (NASDAQ: AWRE), founded in 1986 and based in Burlington, Massachusetts. It has a long history in fingerprint and related biometric standards work, including early involvement with fingerprint image standards used in law-enforcement contexts, and it went public in 1996. Today it sells identity-verification and multi-modal biometric software—face, fingerprint, iris, voice, palm—and related platforms to government agencies and commercial customers. Public descriptions reference an Awareness Platform positioned as software that orchestrates biometric workflows, liveness checks intended to resist certain presentation and injection attacks, and matching across modalities.

Organizations in identity and biometrics sit at a sensitive intersection: they may process or help customers process credentials, biometric templates or images, identity documents, audit logs, and administrative accounts used to run verification systems. A listing that names such a vendor is consequential because trust in identity systems depends on confidentiality and integrity of those workflows—even when a specific incident remains unconfirmed. That consequence is about the sector's role, not a finding that any particular system at Aware failed.

What was likely exposed

The facts state that data types named as exposed are not disclosed. It is therefore not possible to say what, if anything, was copied. Asserting a precise inventory would go beyond the record.

If files were taken from a biometrics and identity-software company of this kind, organizations in the sector typically hold some mix of business records and, depending on product design and customer contracts, data tied to verification services. That can include corporate email and documents, customer and partner contact information, contracts, system configuration details, authentication material for staff or support channels, and in some deployments biometric-related data or templates, identity-document images, liveness-session artifacts, or logs of matching decisions. Government and commercial customers may also appear in sales, support, or integration records. None of these categories is confirmed as present in any alleged archive here; they are the sorts of information such firms often handle, offered only to frame conditional risk.

The reported 400 GB figure, if accurate as a claim, would suggest a large bulk of material in the attackers' narrative, but size alone does not identify contents, sensitivity, or whether the material is current, unique, or relevant to individuals.

What's at stake

For individuals, the stakes depend entirely on whether personal or biometric-related data was involved and whether it later appears in criminal markets or public dumps. If credential or contact data were included, risks can include targeted phishing, account-takeover attempts, and social-engineering calls that reference real employers or service relationships. If identity-document or biometric-related material were involved, risks can extend to long-lived fraud concerns, because biometric identifiers are not changed like a password. Those outcomes remain hypothetical until there is confirmed exposure.

For the organization and its customers, an unverified listing can still create operational and trust pressure: customers may ask for assurances, regulators or partners may inquire, and staff may face a higher volume of social-engineering attempts that cite the public claim. A leak-site listing establishes that a group chose to name the company; it does not by itself establish the scope of any intrusion, the presence of ransomware on production systems, or the quality of any defense.

Steps worth taking either way

Because the incident is unconfirmed and data types are undisclosed, action should stay proportional and conditional. If you are a customer, employee, or partner who interacts with Aware or with biometric verification services in the same supply chain, watch for unexpected password resets, MFA prompts, or messages that urge urgent payment or credential submission while citing a breach. Prefer official channels you already trust rather than links or contacts supplied in unsolicited mail.

If you used a password with any related account, changing it and enabling multi-factor authentication reduces takeover risk whether or not this listing proves accurate. Treat unexpected requests for identity documents or biometric re-enrollment with caution. Organizations that rely on biometrics vendors may wish to review contractual notice paths and logging on their own side, again without assuming a confirmed loss at Aware.

Readers who want a practical check can run a free exposure scan of their email addresses against known breach datasets to see whether their information has already surfaced elsewhere. That kind of check does not prove or disprove this particular claim; it only helps spot credentials that are already circulating so they can be rotated. Remain skeptical of anyone selling “full databases” tied to this listing, and rely on confirmations from the company or competent authorities if and when they appear.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

SourceLeak-site claim data adapted from Ransomfeed.it, used under CC BY 4.0.

CompanyAware security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See Aware’s full breach history →
RelatedMore incidents at Aware

More recent breaches

Center State Engineering Listed by The Gentlemen Ransomware GroupOctober 3, 2026Westrop Primary & Nursery School Listed by The Gentlemen Ransomware GroupOctober 2, 2026Hospital de la Santa Creu i Sant Pau Listed by The Gentlemen Ransomware GroupOctober 2, 2026CareerSource Palm Beach County Listed by The Gentlemen Ransomware GroupSeptember 1, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Aware Listed by The Gentlemen Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by thegentlemen — unverified claim, pending independent verification. Leak-site claim data adapted from Ransomfeed.it, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram