LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surface
Recent BreachesData breach tracker

Recent Breaches › Lenrose Listed by thegentlemen Ransomware Group

HIGH severityUnverified claimHow we verify

Lenrose Listed by thegentlemen Ransomware Group: What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·July 23, 2026
Lenrose Listed by thegentlemen Ransomware Group

Reported July 23, 2026.

HIGH
Severity
1
Data types exposed
July 23, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Lenrose has been listed by thegentlemen ransomware group following the exfiltration of internal files, with the incident disclosed on July 23, 2026. Individuals are advised to check for any related notifications and review their accounts or data access.

Severity & verification
HIGH severityUnverified claim
Contact / identity PII exposed.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Was your email in the Lenrose Listed by thegentlemen Ransomware Group breach?
See every leak tied to your email — not just this one. 15-second check, no card, no account.

Lenrose, a Melbourne-based jewellery manufacturing firm also associated with Ace David Jewellery, was listed by the ransomware group known as thegentlemen on or around 23 July 2026. Public reporting indicates that internal files were exfiltrated in a ransomware attack. The number of people affected remains unknown, and further operational details have not been disclosed.

The listing itself is a claim published by the group. What is confirmed in available records is limited: the organisation’s name appeared on the group’s leak site in connection with alleged data theft. For customers, suppliers and staff, even an unverified claim of this kind raises practical questions about what information may have left the company’s systems and how it could be misused.

Inside the incident

According to the reported summary, Lenrose was listed by thegentlemen ransomware group with a report date of 23 July 2026. The only data description provided is that internal files were exfiltrated in a ransomware attack. No public figure has been given for the volume of data, the number of systems involved, or the precise date the intrusion began or was discovered. Methods of initial access, dwell time, and whether encryption was also deployed have not been detailed in the available record.

Ransomware incidents of this type commonly involve unauthorised access followed by theft of files before or alongside any encryption. In this case, the public facts stop at the leak-site listing and the statement that internal files were taken. Scale, specific file names, and confirmation of full or partial recovery remain undisclosed. Readers should treat the group’s publication as an assertion rather than independent verification until the organisation or investigators provide further confirmation.

The group behind it: thegentlemen

thegentlemen is a ransomware operation that has appeared in public threat reporting as a group that conducts double-extortion style attacks: data is stolen and victims are threatened with publication if a ransom is not paid. Like other groups in this category, it has used dedicated leak sites to name organisations and, in some cases, to release samples or larger archives of stolen material. Tactics typically associated with such actors include phishing or exploitation of exposed remote services for initial access, lateral movement inside networks, and staged exfiltration of files before ransom demands are issued.

Public knowledge of thegentlemen does not extend to verified technical claims unique to the Lenrose incident beyond the listing itself. The group claims Lenrose as a victim and associates the listing with exfiltrated internal files. No independent confirmation of the full contents, the success of any ransom negotiation, or the completeness of any data dump has been supplied in the facts available here. Prior activity by the group against other organisations follows the familiar pattern of naming victims publicly to increase pressure; that pattern is well documented across the ransomware ecosystem and does not, by itself, prove the accuracy of every individual listing.

Who is Lenrose?

Lenrose, operating in connection with Ace David Jewellery, is described as a premier jewellery manufacturing and casting company based in Melbourne, Australia. The business specialises in precious-metal casting—including gold, platinum, silver and bronze—CAD design services, and the production of hand-made chain products. It presents itself as a full-service manufacturing facility that uses modern technology to turn custom jewellery designs into finished pieces for clients.

Organisations in this sector routinely hold commercial designs, client specifications, supplier and customer contact details, order and invoicing records, and internal operational documents. Because custom jewellery work often involves high-value materials and bespoke intellectual property, a breach can affect both the company’s competitive position and the privacy of individuals whose personal or business information appears in those records. The consequential nature of an incident here stems less from consumer-scale databases than from the concentration of design files, commercial relationships and potentially sensitive client data inside a specialised manufacturing environment.

What data was at risk

The facts state that internal files were exfiltrated in a ransomware attack. No further breakdown—such as employee records, customer databases, financial documents or design files—has been named in the public report. The number of people affected is listed as unknown.

Companies of this type typically store CAD drawings and design specifications, client and supplier contact information, purchase orders, shipping details, and internal correspondence. They may also hold employee payroll or identity data and credentials used to access manufacturing or business systems. Because the exact contents of the stolen material have not been disclosed or independently catalogued in the available record, it is not possible to state which of these categories, if any, were included. The only confirmed description remains “internal files.” Anything beyond that is unconfirmed.

The real-world impact

For individuals whose details may appear in Lenrose’s systems—clients who commissioned custom work, suppliers, or staff—the primary risks are misuse of contact information, targeted phishing that references genuine orders or designs, and, in rarer cases, identity-related fraud if identity documents or financial details were present. Even without confirmation of specific data types, knowledge that internal files left the network can enable more convincing social-engineering attempts.

For the organisation, consequences can include disruption to manufacturing workflows, loss of confidentiality around proprietary designs, strain on client trust, and the cost of investigation, containment and any required notifications under Australian privacy rules. Ransomware incidents also carry the secondary risk that stolen data later appears on criminal forums or is reused in further attacks against the same supply chain. None of these outcomes is guaranteed by a leak-site listing alone; they represent the realistic range of harm when internal files are confirmed or claimed to have been taken.

Were you affected?

If you have done business with Lenrose or Ace David Jewellery, or if you are a current or former employee or supplier, treat the incident as a prompt to review your own exposure. Monitor bank and card statements for unexpected activity, be cautious of emails or calls that reference jewellery orders or company details you recognise, and consider changing passwords on accounts that may have shared credentials or recovery addresses with work-related systems. Enable multi-factor authentication where it is available.

You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach data sets. That step does not confirm or rule out involvement in this specific incident, but it provides a practical way to see whether your details appear in previously compiled breach collections and to decide what further monitoring is warranted.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyLenrose security record
64/100
DoxxScan™ · Moderate doxx risk
B- 76Above-average record

1 reported incident on record.

See Lenrose’s full breach history →

More recent breaches

Sicsoe Listed by thegentlemen Ransomware GroupJuly 23, 2026Conecsus Listed by thegentlemen Ransomware GroupJuly 23, 2026Sirl Listed by thegentlemen Ransomware GroupJuly 23, 2026Kaneko Listed by thegentlemen Ransomware GroupJuly 16, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Lenrose Listed by thegentlemen Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by thegentlemen — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram