All ransomware incidents
Ransomware group thegentlemen hits Crystal Glass
Crystal Glass — a manufacturing target operating in GB has been listed by the thegentlemen ransomware group on 2026-09-21. The information below reflects what the threat actor has publicly claimed on their leak site; the details have not been independently verified.
Incident Report
| Target Organization | Crystal Glass |
|---|---|
| Threat Group | thegentlemen |
| Summary | crystalglassltd.co.uk Crystal Glass (Leeds) Ltd is a family-owned glass company based in Leeds, West Yorkshire, UK, founded in 1962 and officially registered as a limited company in 1974. It operates 5 branches — Leeds (HQ), Bradford, Harrogate, Wakefield, and Castleford — covering all of West Yorkshire. Its core services are 24/7/365 emergency glazing, double glazing replacement, and custom glasswork (shower screens, shopfronts, mirrors, partitions, and commercial facades). The company runs a lean family-managed SME model with roughly 10–25 employees and estimated revenue of £1–3 million per year |
| Date of Breach | 2026-09-21 |
| Discovery Date | 2026-09-26 |
| Region | GB |
| Target Domain | crystalglassltd.co.uk |
| Business Sector | Manufacturing |
| Severity | MEDIUM |
Claim by thegentlemen
crystalglassltd.co.uk Crystal Glass (Leeds) Ltd is a family-owned glass company based in Leeds, West Yorkshire, UK, founded in 1962 and officially registered as a limited company in 1974. It operates 5 branches — Leeds (HQ), Bradford, Harrogate, Wakefield, and Castleford — covering all of West Yorkshire. Its core services are 24/7/365 emergency glazing, double glazing replacement, and custom glasswork (shower screens, shopfronts, mirrors, partitions, and commercial facades). The company runs a lean family-managed SME model with roughly 10–25 employees and estimated revenue of £1–3 million per year
Posted by the thegentlemen threat actor on its public leak site. This is the group's own statement and has not been independently verified by HackerFeeds.
Disclaimer
HackerFeeds does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.

