LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surface
Recent BreachesData breach tracker

Recent Breaches › Disney Family Listed by thegentlemen Ransomware Group

HIGH severityUnverified claimHow we verify

Disney Family Listed by thegentlemen Ransomware Group: What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·July 23, 2026
Disney Family Listed by thegentlemen Ransomware Group

Reported July 23, 2026.

HIGH
Severity
1
Data types exposed
July 23, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Disney Family has been listed by thegentlemen ransomware group after internal files were exfiltrated in a ransomware attack, a disclosure that came to light on July 23, 2026. An undisclosed number of people may be affected; check any notifications or statements from Disney Family and follow recommended steps if your information is involved.

Severity & verification
HIGH severityUnverified claim
Contact / identity PII exposed.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Was your email in the Disney Family Listed by thegentlemen Ransomware Group breach?
See every leak tied to your email — not just this one. 15-second check, no card, no account.

Ransomware groups continue to target family offices and private investment vehicles, treating the concentrated wealth and long historical records these entities hold as high-value leverage. In that landscape, a listing that appeared on 23 July 2026 has drawn attention to Disney Family, also known as Shamrock Holdings.

Public reporting states that thegentlemen ransomware group has claimed responsibility for a ransomware attack in which internal files were exfiltrated. The number of people affected remains unknown, and independent confirmation of the full scope is limited. The incident matters because the organisation manages private family wealth rather than the public Walt Disney Company, and the claimed dataset is described as both large and historically deep.

What happened

According to the reported summary, Disney Family / Shamrock Holdings was listed by thegentlemen ransomware group on 23 July 2026. The group claims a ransomware attack in which internal files were exfiltrated. The compromised dataset is described as totaling over 800 GB and spanning records from the 1980s through June 2026. Public detail on the precise intrusion method, initial access vector, or whether encryption was also deployed has not been disclosed. The number of individuals affected is listed as unknown.

The listing itself constitutes a claim by the threat actor; it has not been independently verified in the available facts. What is stated is that the material covers highly sensitive information across 14 critical categories, with explicit mention of family trusts, tax administration, and private equity fund management. Named individuals referenced in connection with the claimed exposure include Abigail Disney, Roy P. Disney, and Stanley Gold, whose personal financial records are among those described as affected. Further technical or forensic particulars remain undisclosed.

The group behind it: thegentlemen

thegentlemen is a ransomware operation that has appeared in public reporting as a group that exfiltrates data before or alongside encryption and then lists victims on a leak site to apply pressure. Like other actors in this category, it typically publicises claimed breaches to advertise the volume or sensitivity of stolen material and to encourage negotiation. Established public knowledge of the group centres on double-extortion tactics and opportunistic targeting of organisations that hold concentrated financial or personal records.

With respect to this specific incident, the facts state only that thegentlemen listed Disney Family and claimed exfiltration of internal files. No additional statements, ransom demands, or proof-of-compromise details beyond the summary already noted are provided in the available record. Any broader characterisation of motive or internal group structure specific to this victim would be speculative and is therefore omitted.

Who is Disney Family?

Disney Family, operating through Shamrock Holdings, is the private investment firm and family office established by Roy E. Disney to manage the wealth of that branch of the Disney family. It is distinct from the publicly traded Walt Disney Company. Family offices of this type typically oversee trusts, tax planning, private equity holdings, philanthropic vehicles, and multi-generational financial administration. They routinely retain decades of correspondence, legal instruments, investment performance data, and personal identifiers belonging to principals and close associates.

A breach affecting such an entity is consequential because the data are rarely limited to a single corporate perimeter. They often intertwine the personal finances of named family members with the operational records of the office itself. The longevity of the claimed archive—from the 1980s onward—amplifies the potential sensitivity, as older records may contain information that has never been digitised elsewhere or that remains relevant to ongoing trusts and tax positions.

What was likely exposed

The facts identify the exposed material as internal files exfiltrated in a ransomware attack. The reported summary further characterises the dataset as exceeding 800 GB, covering the period from the 1980s to June 2026, and spanning 14 critical categories. Explicitly named categories include family trusts, tax administration, and private equity fund management. Personal financial records associated with Abigail Disney, Roy P. Disney, and Stanley Gold are also referenced.

Exact file inventories, full category lists, and confirmation of every data element remain unconfirmed beyond these statements. Organisations of this kind commonly hold:

Because the precise contents have not been independently verified in the public facts, readers should treat the above as the claimed and typical scope rather than as a confirmed inventory.

Why it matters

For affected individuals, exposure of trust, tax, and private-equity records can create lasting risks of targeted fraud, identity misuse, and unwanted scrutiny of private financial arrangements. Multi-decade archives increase the chance that outdated but still sensitive details—former addresses, historic account numbers, or family governance documents—surface in criminal markets or public dumps. Named principals and their associates may face elevated phishing or social-engineering attempts that reference authentic personal details.

For the organisation, the incident raises operational and reputational considerations common to family offices: the need to assess continuity of sensitive processes, to notify relevant parties where legally required, and to evaluate whether any exfiltrated material could affect ongoing investment or fiduciary obligations. The unknown count of affected people and the absence of fuller forensic disclosure mean that the full residual risk cannot yet be quantified from public information alone.

Were you affected?

If you have a personal, professional, or familial connection to Disney Family / Shamrock Holdings or to the named individuals, treat the possibility of exposure seriously until more definitive information appears. Practical first steps include monitoring financial and tax accounts for unusual activity, placing fraud alerts with major credit bureaus where appropriate, and being sceptical of unsolicited communications that reference private family or investment matters. Because the total number of people affected is unknown and the exact data elements remain only partially described, a cautious approach is warranted.

Readers can also run a free exposure scan of their email addresses against known breach datasets to check whether their information has already surfaced in publicly indexed dumps. Remain alert for official notifications from the organisation or from regulators; until those appear, rely on verified sources rather than on claims circulating solely from the threat actor’s listing.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyDisney Family security record
64/100
DoxxScan™ · Moderate doxx risk
B- 76Above-average record

1 reported incident on record.

See Disney Family’s full breach history →

More recent breaches

Terry P Moosmann CPA PC Listed by thegentlemen Ransomware GroupJuly 16, 2026MatTek Listed by thegentlemen Ransomware GroupJuly 23, 2026Optiforms Listed by thegentlemen Ransomware GroupJuly 23, 2026Affinity Designs Listed by thegentlemen Ransomware GroupJuly 23, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Disney Family Listed by thegentlemen Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by thegentlemen — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram