Disney Family Listed by thegentlemen Ransomware Group: What Was Exposed & What To Do
Disney Family has been listed by thegentlemen ransomware group, with internal files reportedly exfiltrated. The incident was publicly disclosed on July 23, 2026, and affected an undisclosed number of people; anyone connected to the organisation should check for notifications and follow any guidance issued.
People connected to Disney Family and Shamrock Holdings may face lasting practical consequences if internal files from a reported ransomware incident have been taken. When a family office that manages private wealth, trusts, and long-term financial arrangements is listed by a ransomware group, the individuals named in those records can confront risks that extend well beyond a single company email address—risks that touch tax history, estate planning, and personal financial identity.
Public reporting dated July 23, 2026 states that Disney Family has been listed by the ransomware group thegentlemen. The number of people affected remains unknown. What is described is the exfiltration of internal files in a ransomware attack; further independent confirmation of the full scope is limited.
What happened
According to the available record, Disney Family—also identified with Shamrock Holdings—was listed by thegentlemen ransomware group on or around July 23, 2026. The incident is characterized as a ransomware attack in which internal files were exfiltrated. The reported summary describes a compromised dataset said to total over 800 GB and to span records from the 1980s through June 2026. It further states that the material covers highly sensitive information across 14 critical categories, among them family trusts, tax administration, and private equity fund management. Named individuals referenced in connection with the material include Abigail Disney, Roy P. Disney, and Stanley Gold, with mention of personal financial records. The precise intrusion method, the exact date of initial access, and any ransom demand or negotiation details are not disclosed in the facts provided. The listing itself remains a claim advanced by the group unless and until independently verified.
The group behind it: thegentlemen
thegentlemen is a ransomware operation known in public reporting for double-extortion tactics: encrypting systems while also copying data and threatening to publish or sell it if payment is not made. Groups of this type commonly maintain leak sites or negotiation channels where they name victims and, in some cases, release sample files to pressure organizations. Their activity has typically focused on organizations holding valuable internal or financial records rather than on mass consumer platforms alone. With respect to this specific incident, the public facts establish only that thegentlemen listed Disney Family; any broader statements the group may have made about the victim beyond that listing are not detailed here. Claims posted on criminal leak sites should be treated as unverified until corroborated by the organization or by independent investigation.
About Disney Family
Disney Family, through Shamrock Holdings, is described as the private investment firm and family office established by Roy E. Disney to manage the wealth of that branch of the Disney family. It is distinct from the publicly traded Walt Disney Company. Family offices of this kind ordinarily oversee concentrated private wealth, trusts, tax and estate administration, private equity and investment holdings, and the personal financial affairs of principals and related parties. Because such entities sit at the intersection of family governance and sophisticated finance, the records they maintain are often both long-lived and highly sensitive. A breach affecting this type of organization is consequential precisely because the data are not generic customer lists; they can map the financial lives of specific individuals and entities over decades.
What was likely exposed
The facts state that internal files were exfiltrated in a ransomware attack. The reported summary further describes a dataset of over 800 GB spanning the 1980s to June 2026 and covering 14 critical categories that include family trusts, tax administration, and private equity fund management, with reference to personal financial records of named individuals such as Abigail Disney, Roy P. Disney, and Stanley Gold. Exact file inventories, full category lists, and confirmation of every data element remain subject to the limits of the public record. Organizations of this nature typically hold trust instruments, tax filings and related correspondence, investment and fund documents, banking and wire details, legal agreements, and identifying information for principals, family members, and advisors. Whether every such category was present in the taken material is unconfirmed beyond what the reported summary asserts. Readers should treat the precise contents as claimed rather than as fully audited fact.
Why it matters
For affected individuals, exposure of trust, tax, and private-equity records can enable targeted fraud, identity misuse, or social-engineering attempts that reference real financial relationships and historical transactions. Long-dated archives increase the chance that outdated but still sensitive identifiers—former addresses, account references, or family structures—remain useful to criminals. For the organization, loss of control over internal files can complicate fiduciary duties, damage relationships with co-investors and advisors, and create ongoing legal and regulatory exposure even if systems are restored. Because the count of people affected is unknown, the circle of risk may include not only principals but also staff, external counsel, fund partners, and family members whose details appear in the files. These harms are concrete and often slow to surface; they do not require dramatic public dumps to become real for the people named in the records.
Were you affected?
If you have a past or present connection to Disney Family, Shamrock Holdings, or related trusts and funds—whether as a family member, employee, advisor, or counterparty—monitor financial accounts and tax correspondence for unusual activity, and treat unexpected requests that reference private financial details with caution. Consider placing fraud alerts or credit freezes where appropriate, and retain records of any official notifications you receive. Because the full list of affected individuals is unknown, you can also run a free exposure scan of your email address to check whether your information has already appeared in known breach datasets. That step does not confirm involvement in this incident, but it can help you decide what further monitoring is warranted.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Disney Family Listed by thegentlemen Ransomware GroupTerry P Moosmann CPA PC Listed by thegentlemen Ransomware GroupHenry Frerk Sons Listed by thegentlemen Ransomware GroupTitle Resources Listed by thegentlemen Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Disney Family Listed by thegentlemen Ransomware Group →
Publicly posted by thegentlemen — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.