Velum Listed by thegentlemen Ransomware Group: What Was Exposed & What To Do
Velum was listed by thegentlemen ransomware group on July 23, 2026, with internal files reported as exfiltrated in the attack. An undisclosed number of people may have been affected; anyone connected to Velum should check for notifications and follow any guidance issued by the organisation.
Ransomware groups continue to pressure mid-sized manufacturers by pairing encryption with the threat of public data leaks, a pattern that has become routine across European industry. In this climate, listings on criminal leak sites often surface before independent confirmation, leaving customers, partners and employees to weigh incomplete claims against real operational risk.
On 23 July 2026, the ransomware group known as thegentlemen listed Velum, a French professional-lighting manufacturer, asserting that it had exfiltrated internal files. The number of people affected remains unknown, and public detail beyond the group’s own statements is limited. The incident matters because the claimed material includes client contracts and personal data, categories that can expose both commercial relationships and individuals if released.
Inside the incident
According to the listing reported on 23 July 2026, thegentlemen claimed responsibility for a ransomware attack on Velum in which internal files were exfiltrated. The group stated that it was making some files publicly available and that it held hundreds of gigabytes of material, specifically naming database projects, client contracts, personal data and documents. It warned that the full set would be published unless contact was made. No independent confirmation of the intrusion method, the precise date of access, the volume actually taken, or whether systems were encrypted has been supplied in the available record. The number of individuals whose information may be involved is undisclosed.
Who is thegentlemen?
thegentlemen is a ransomware operation that follows the now-common double-extortion model: data is copied before systems are locked, and the threat of publication is used to increase pressure. Groups of this type typically maintain dedicated leak sites where they post victim names, sample files and countdown timers, and they often target organisations whose disruption would be costly or reputationally sensitive. Public reporting on thegentlemen has described campaigns against companies across multiple sectors, with the same pattern of claiming large data hauls and inviting negotiation. In the present case, the listing of Velum and the description of the files constitute claims by the group; they have not been independently verified in the facts available here.
Velum and its sector
Velum is a French manufacturer of professional lighting solutions headquartered in Bischoffsheim, Alsace. The company has operated since 1975 and specialises in the design, development and manufacture of custom LED fixtures for indoor and outdoor use. Firms in this segment typically maintain engineering drawings, project databases, supplier and client contracts, and employee or contact records necessary to fulfil specialised orders for commercial, architectural and industrial clients. A breach affecting such an organisation is consequential because lighting projects often involve long-term client relationships, proprietary designs and personal data of staff or business contacts; exposure can disrupt supply chains, reveal commercial terms and create compliance obligations under European data-protection rules.
The information in question
The facts identify the exposed material only as internal files exfiltrated in a ransomware attack. thegentlemen’s own statement adds that the haul allegedly comprises hundreds of gigabytes including database projects, client contracts, personal data and documents. Exact file inventories, the sensitivity of any personal data fields, and whether customer or employee records were included in identifiable form remain unconfirmed. Organisations of Velum’s type ordinarily hold design and production databases, contractual documents, and contact or personnel information; until verified inventories appear, those categories should be treated as possible rather than established contents of this incident.
What's at stake
For individuals, the principal risks are misuse of personal data if it was among the files—phishing, identity fraud or unwanted contact—and the secondary inconvenience of monitoring accounts and documents tied to Velum projects. For the company, publication of client contracts or proprietary project data could damage commercial confidentiality, strain partner trust and trigger regulatory notification duties. Because the scale of affected people is unknown and the precise data set is unconfirmed, the practical impact cannot yet be quantified; the credible threat is the combination of operational disruption and the potential release of material the group claims to hold.
If your data was in this breach
If you have worked with Velum as an employee, contractor or client, treat the group’s claims as a prompt for caution rather than proof of your personal exposure. Review financial and email accounts for unusual activity, enable multi-factor authentication where available, and be alert to targeted phishing that references lighting projects or contracts. Consider placing fraud alerts with relevant credit services if you believe identity data may have been involved. You can also run a free exposure scan of your email address to check whether it has already appeared in known breach data sets, which provides an additional, independent signal while official details remain limited.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Smrtr Listed by thegentlemen Ransomware GroupTikona Infinet Listed by thegentlemen Ransomware GroupInternet Ag Listed by thegentlemen Ransomware GroupAdvanced Marketing Listed by thegentlemen Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Velum Listed by thegentlemen Ransomware Group →
Publicly posted by thegentlemen — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.