***.*** LAST TIMER UPDATE Listed by thegentlemen Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
***.*** LAST TIMER UPDATE was listed by thegentlemen Ransomware Group on December 10, 2025, with internal files reported as exfiltrated. The number of people affected has not been disclosed; anyone connected to the organisation should check for official updates and take steps to protect their data.
On December 10, 2025, the ransomware group thegentlemen listed ***.*** LAST TIMER UPDATE on its leak site and claimed to have stolen 1.5 terabytes of internal files from the organization. The number of individuals whose information may be involved remains unknown, and no independent confirmation of the data’s authenticity or scope has been made public.
The incident involves an Asia-based investment firm that manages more than 10 billion USD. Such events draw attention because they concern detailed records of investments, limited partners, and portfolio companies rather than routine consumer data.
What happened
Thegentlemen posted ***.*** LAST TIMER UPDATE on its data-leak site on December 10, 2025, stating that 1.5 terabytes of files had been removed during a ransomware operation. The listing describes the material as internal documentation but provides no further technical details on how access was obtained or whether encryption was also deployed. No statement from the organization confirming or disputing the claim has been recorded in public reporting to date.
Who is thegentlemen?
Thegentlemen is a ransomware operator that maintains a public leak site where it lists organizations from which it claims to have taken data. Groups of this type typically combine file exfiltration with encryption demands, then publish samples or indexes when negotiations stall. Public records show thegentlemen has previously listed companies across multiple sectors, though each listing remains an unverified assertion by the group until corroborated by the victim or independent investigators.
***.*** LAST TIMER UPDATE and its sector
***.*** LAST TIMER UPDATE is described in the listing as one of Asia’s larger investment firms, with assets under management exceeding 10 billion USD. Organizations in this sector routinely collect and store detailed financial, legal, and operational records relating to their own funds, external investors, and the companies in which they invest. A breach at such an entity therefore touches both proprietary investment strategy and third-party commercial information.
What was likely exposed
The listing states that the stolen material includes investment documentation such as private placement memorandums, investment memos, financial models, and project budgets. It also references a complete limited-partner database containing contact details, investment terms, and non-disclosure agreements, together with financial statements and operating metrics for more than thirty portfolio companies and due-diligence files on at least nine active merger-and-acquisition projects. The precise contents of the 1.5 terabytes have not been independently verified.
What's at stake
Exposure of limited-partner records and investment terms can create commercial and privacy consequences for the investors named in those files. Portfolio-company data and active deal documentation may affect ongoing negotiations or competitive positioning. For the firm itself, the loss of internal models and budgets can complicate future fundraising and operational planning. The absence of a confirmed count of affected individuals means the full personal impact cannot yet be quantified.
Were you affected?
Individuals who have invested with or worked alongside ***.*** LAST TIMER UPDATE should monitor official statements from the firm for any direct notification. A practical first step is to review recent account activity and consider whether contact details or investment records held by the firm require updated protective measures. Readers may also run a free exposure scan of their email address against known breach datasets to check whether their information appears in previously published collections.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
NBCAPITAL JOINT STOCK COMPANY Listed by thegentlemen Ransomware Group***.*** Listed by thegentlemen Ransomware GroupOriental de Seguros Listed by thegentlemen Ransomware GroupVenezuela Re Listed by thegentlemen Ransomware GroupLatest breaches
Publicly posted by thegentlemen — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.