A Russian-speaking ransomware affiliate who went by the handle “Azazel” spent months quietly looting more than two dozen organizations across six countries, then did something almost unheard of in the ransomware-as-a-service world: he cut his own gang out of the payout. Threat intelligence firm CloudSEK published the findings on October 5, 2026, in a report titled “Caught in 4K: The Gentlemen Files,” and the story has been working its way through security outlets including Infosecurity Magazine, GBHackers, and Cybersecurity News ever since.
The breach chain itself is almost mundane by 2026 standards: exposed CI/CD variables, old secrets left sitting in Git commit history, and credentials that let one attacker walk straight into databases, payment gateways, and cloud infrastructure. What makes this case notable isn’t the entry point. It’s who ended up holding the money, and the fact that the affiliate reportedly ran part of the intrusion through an AI coding assistant using the Model Context Protocol, a technique CloudSEK says has no prior public documentation.
What happened: the Azazel campaign, in brief
According to CloudSEK’s October 5 report, Azazel operated as an affiliate of The Gentlemen, a ransomware-as-a-service operation that most researchers place as emerging around mid-2025. Rather than splitting proceeds with the core group under the usual affiliate revenue-share model, Azazel allegedly kept extortion payments from his victims for himself, publishing stolen data on a private leak site instead of routing it through The Gentlemen’s shared infrastructure.
CloudSEK describes “more than two dozen organizations across six countries” as affected, spanning logistics, insurance, pharmaceuticals, artificial intelligence, medical devices, and government-adjacent infrastructure, per reporting from Cybersecurity News. One compromised managed service provider alone reportedly exposed access to more than 150 databases, payment gateways, and hundreds of repositories, putting more than a dozen of that provider’s own client companies at risk in a single incident. CloudSEK’s researchers put the total stolen data at roughly 6 terabytes spread across the victim directories they found exposed.
No individual victim companies have been named publicly in the reporting reviewed for this story. That detail matters for readers trying to assess their own exposure: if your organization runs self-hosted GitLab infrastructure and hasn’t audited CI/CD secret hygiene recently, the absence of a named-victim list is not a reason to assume you’re clear.
The attack technique: old secrets in new commits
The core access method wasn’t a zero-day. It was credential reuse at scale. CloudSEK’s investigation found that Azazel harvested CI/CD pipeline variables, database credentials, API keys, SSH private keys, and other deployment secrets from exposed GitLab instances. Crucially, many of those secrets had already been deleted from the current version of affected repositories, but remained recoverable from earlier commits in the Git history, a detail Infosecurity Magazine flagged as a recurring theme across the victim set.
GBHackers reported that the credential-harvesting toolkit associated with the campaign included open-source utilities such as glato, nord-stream, gitlab-secrets, gitlab-watchman, and gitleaks, all of which are built to scan repositories (including historical commits) for leaked tokens and keys. None of these are exotic or hard to obtain; they’re publicly available tools that security teams themselves use defensively, which is exactly why relying on “we don’t have obvious secrets in our latest commit” has never been a real control.
One case CloudSEK highlighted shows how quickly a single misconfigured instance can cascade. A GitLab instance serving two unrelated organizations exposed a CI/CD token tied to one tenant. That token revealed Oracle and PostgreSQL database credentials, shipping API credentials, and SSH keys granting access to three cloud-hosted servers belonging to the second, entirely separate organization sharing the same instance. One leaked token, two victims, no exploit required.
The MCP twist: an AI assistant as attack infrastructure
The detail drawing the most attention from researchers is CloudSEK’s claim that Azazel used the Model Context Protocol, the open standard that lets AI coding assistants call external tools and data sources, to execute commands during live intrusions against at least one victim, an AI medical-imaging service provider. Cybersecurity News described this as turning “an AI coding assistant into a channel for running attacks inside enterprise networks,” and CloudSEK says the technique has no prior public reporting tied to a ransomware intrusion.
This is a meaningful shift for defenders to internalize. MCP servers are designed to give AI agents broad, programmatic reach into a company’s tools, repositories, and cloud accounts, precisely the kind of access an attacker wants once they’re inside. If an intrusion can route commands through an MCP integration that already has legitimate credentials and broad permissions, it can blend into normal developer-tooling traffic in a way a traditional reverse shell doesn’t. Security teams that have rushed to wire AI agents into CI/CD and production systems over the past year, often without the same change-control scrutiny applied to other privileged automation, now have a concrete incident to point to when arguing for tighter guardrails.
Who (and what) is The Gentlemen
The Gentlemen is a Russian-speaking ransomware-as-a-service operation that researchers at Palo Alto Networks’ Unit 42 track under the alias Storm-2697. Unit 42’s own writeup, “No Manners Here: The Ruthless Rise of The Gentlemen Ransomware,” places the group’s activity back to at least July 2025, running the standard double-extortion playbook: steal data first, encrypt second, threaten publication if the victim doesn’t pay.
Kaspersky’s Securelist team, in its own analysis of the group, describes a Go-based locker capable of hitting Windows, Linux, NAS, and BSD systems, and notes that observed intrusions have concentrated heavily on Brazil, China, Indonesia, Taiwan, and Thailand, alongside manufacturing, IT services, healthcare, financial services, construction, and logistics targets worldwide. Different trackers give different victim counts for the group overall, which is worth noting precisely because it shows how messy ransomware-tracking data still is even in 2026: Unit 42’s associated figures put total claimed victims above 580 across 77 countries through early July 2026, while other trackers cited by CloudSEK and Mallory.ai put the number nearer 483 victims across 66 countries over roughly the same stretch. The exact figure is unsettled; the trend (rapid, multi-continent growth in well under a year) is not in dispute.
By the numbers: the Azazel incident
| Metric | Reported figure | Source |
|---|---|---|
| Organizations affected | More than two dozen (24+) | CloudSEK |
| Countries affected | Six | CloudSEK |
| Stolen data volume | Approximately 6 TB | CloudSEK investigation |
| Databases/payment gateways exposed via one MSP | 150+ | Cybersecurity News |
| Client companies hit through that one MSP | 12+ | Cybersecurity News |
| Credential-harvesting tools identified | glato, nord-stream, gitlab-secrets, gitlab-watchman, gitleaks | GBHackers |
| Report publication date | October 5, 2026 | CloudSEK |
| Named CVE tied to the intrusion itself | None confirmed | CloudSEK / Infosecurity Magazine |
Where this fits in 2026’s ransomware landscape
The Azazel story lands in a year that has already been brutal for ransomware headlines. Industry tracking cited in earlier shattered.io coverage of August 2026 ransomware activity showed attack counts climbing 12% to 1,073 incidents that month alone, and a separate analysis found data-theft-only extortion surging 275% even as actual ransom payments trend downward, a sign that gangs are adapting their business model faster than defenders are adapting their defenses. The Gentlemen’s rapid rise fits that same pattern: steal first, encrypt second, and extract value even from victims who refuse to pay the ransom demand.
It also isn’t the only ransomware operation making headlines this year for internal dysfunction or law enforcement pressure. A member of the Qilin ransomware operation, age 28, was extradited to Germany earlier in 2026, and the KillSec ransomware-as-a-service brand saw its own infrastructure dismantled in a multi-country law enforcement action, Operation KillSwitch, that eventually expanded to ten countries. The common thread across Qilin, KillSec, and now The Gentlemen is that ransomware-as-a-service has become loose enough, and lucrative enough, that affiliates increasingly see little reason to stay loyal to the operators who license them the malware in the first place.
Supply-chain echoes: this isn’t an isolated pattern
The Azazel campaign is also part of a broader 2026 trend of attackers treating developer tooling itself as the primary target rather than a stepping stone. Earlier this year, a supply-chain compromise tied to email marketing vendor Brevo used a ClickFix-style social-engineering technique to reach more than 100,000 downstream sites, and GitLab itself disclosed a separate, unrelated critical flaw in its AI Gateway, tracked as CVE-2026-90970 at a CVSS score of 9.9, that could let authenticated Duo users escape a prompt sandbox. CloudSEK’s reporting on the Azazel case is explicit that no confirmed GitLab software vulnerability was exploited in this particular campaign; the access path was leaked secrets and configuration exposure, not a patchable code flaw. That distinction matters for remediation: patching GitLab won’t fix a leaked API key that’s already sitting in a developer’s forked repository three companies away.
Security teams have spent years treating “patch management” and “secrets management” as adjacent but separate disciplines. Incidents like this one argue they need to converge. A fully patched GitLab instance with a 2023 commit still containing a live database password is just as exploitable as an unpatched one.
Market and business impact
For enterprises running self-hosted DevOps platforms, the practical fallout from this story is less about a single patch and more about an audit burden. Security teams at organizations using GitLab Self-Managed, and comparable platforms, now have fresh justification to scan full commit history (not just current branch state) for exposed secrets, rotate any credential that has ever touched a CI/CD variable, and review MCP or AI-agent integrations with the same change-control rigor applied to production deployment pipelines.
There’s also a cyber-insurance angle worth watching. Insurers have increasingly asked policyholders detailed questions about secrets management and CI/CD hardening during underwriting, and a well-documented case study like the Azazel campaign, with a named research firm, named techniques, and specific tooling, gives underwriters concrete language to put into coverage questionnaires and exclusions going forward. Expect renewal cycles in early 2027 to reflect that.
Competitive comparison: ransomware-as-a-service models under strain
The affiliate revenue-share structure that underpins most ransomware-as-a-service operations assumes a baseline of trust: affiliates do the breaching, operators get a cut (often reported in the 10-30% range across various RaaS brands) for providing the locker, infrastructure, and negotiation support. Azazel’s alleged decision to bypass that split and run his own extortion and leak operation on the side exposes a structural weakness that has shown up elsewhere in the ransomware economy throughout 2026.
| Ransomware operation | 2026 development | Core issue exposed |
|---|---|---|
| The Gentlemen (Azazel affiliate) | Affiliate diverted ransom proceeds from the core operation | RaaS trust model breaking down between operators and affiliates |
| Qilin | Member, 28, extradited to Germany | Law enforcement cooperation across borders catching individual operators |
| KillSec | Operation KillSwitch expanded to 10 countries, seized servers | Centralized RaaS infrastructure remains a single point of failure |
| Industry-wide (per August 2026 tracking) | Attack volume up 12% to 1,073 incidents; data-theft-only extortion up 275% | Shift away from encryption toward pure data-theft extortion as ransom payments decline |
Historical context: from encryption-only to double, triple extortion
Ransomware’s business model has gone through several distinct phases since the first widely recognized crypto-ransomware campaigns in the mid-2010s. Early operations simply encrypted files and demanded payment for a decryption key. That model collapsed in effectiveness once backups became standard practice, pushing groups toward double extortion: steal the data before encrypting, then threaten to leak it regardless of whether the victim restores from backup. The Gentlemen’s playbook, and now Azazel’s variant on it, represents a further evolution some researchers call “affiliate-side extortion,” where even the criminal partnership structure itself has no enforceable loyalty, and an affiliate with enough technical skill can simply cut out the middleman entirely.
That evolution tracks a broader industry shift documented across 2026 reporting: ransom payment rates have been falling as more victims refuse to pay and instead rely on backups and incident response, which is precisely what’s driving the pivot toward pure data-theft extortion where payment isn’t needed to restore operations, only to prevent public disclosure.
What security teams should do now
Based on the specific techniques CloudSEK documented, a few concrete steps stand out for any organization running self-hosted GitLab or similar CI/CD platforms:
- Scan full repository commit history, not just current branch state, for exposed secrets using tools like gitleaks or gitlab-watchman before an attacker does it for you.
- Rotate every credential that has ever been stored in a CI/CD variable, even ones believed to have been deleted or replaced, since Git history retains them by default.
- Audit multi-tenant GitLab instances for cross-tenant exposure; a single leaked token should never grant access to a second, unrelated organization’s infrastructure.
- Review any AI coding assistant or MCP server integration for the scope of credentials and systems it can reach, and apply the same change-control review used for other privileged automation.
- Segment CI/CD service accounts so that no single exposed token can reach databases, payment systems, and cloud infrastructure simultaneously.
# Example: scanning full Git history for leaked secrets with gitleaks
gitleaks detect --source . --log-opts="--all" --report-path gitleaks-report.json
Predictions: where this story goes next
- More ransomware-as-a-service affiliates will attempt to bypass their own operators once they realize the RaaS “brand” offers little practical enforcement against a skilled technical operator going solo.
- CI/CD secrets scanning across full commit history will become a baseline expectation in cyber-insurance underwriting questionnaires within the next one to two renewal cycles.
- Expect at least one more documented case of an AI agent or MCP integration being used as attacker infrastructure before the end of 2026, now that the technique has public precedent.
- The Gentlemen’s victim count will likely keep climbing regardless of the Azazel defection, since the core group’s affiliate recruitment and tooling appear unaffected by one affiliate’s departure.
- Expect GitLab, GitHub, and Bitbucket to each publish or expand secret-scanning guidance referencing commit-history exposure specifically in response to this reporting cycle.
Frequently asked questions
Was GitLab itself hacked or exploited by a vulnerability?
No. CloudSEK’s investigation found no confirmed GitLab software vulnerability involved in the Azazel campaign. The access path was exposed CI/CD secrets and credentials, including ones left in old Git commits, not a patchable code flaw in GitLab’s platform.
Who is Azazel?
Azazel is the handle used by a Russian-speaking affiliate of The Gentlemen ransomware-as-a-service operation. CloudSEK’s October 5, 2026 report identifies the operator by that alias and describes the campaign in detail, but does not disclose a real-world identity.
How many organizations were affected?
CloudSEK and multiple outlets, including Cybersecurity News, report more than two dozen organizations across six countries, with roughly 6 terabytes of stolen data identified across exposed victim directories.
What is The Gentlemen ransomware group?
The Gentlemen is a ransomware-as-a-service operation, tracked by Palo Alto Networks’ Unit 42 as Storm-2697, that researchers date back to at least mid-2025. It uses double extortion, stealing data before encrypting systems, and has claimed victims across dozens of countries and multiple industries.
What is the Model Context Protocol, and why does it matter here?
MCP is an open standard that lets AI coding assistants and agents call external tools, data sources, and systems. CloudSEK reported that Azazel used MCP to execute commands during a live intrusion against an AI medical-imaging service, a technique the firm says had no prior public documentation in a ransomware context.
Did any named companies confirm they were breached?
No individual victim organizations have been publicly named in the reporting reviewed. Researchers describe affected sectors, including logistics, insurance, pharmaceuticals, AI, medical devices, and government-adjacent infrastructure, without naming specific companies.
How is this different from other 2026 ransomware incidents?
Most ransomware stories in 2026 involve an operator-affiliate relationship holding together, with extortion proceeds shared under a license agreement. This case is notable because the affiliate allegedly broke that arrangement entirely, diverting proceeds and running an independent leak site rather than working through The Gentlemen’s shared infrastructure.
What should organizations do if they use self-hosted GitLab?
Scan complete commit history for exposed secrets, rotate any credential that has ever appeared in a CI/CD variable, audit multi-tenant instance isolation, and review the permission scope of any AI assistant or MCP integration connected to the development environment.




