All ransomware incidents
Ransomware group thegentlemen hits Defencebit
Defencebit — a government & defense target operating in GB has been listed by the thegentlemen ransomware group on 2026-09-29. The information below reflects what the threat actor has publicly claimed on their leak site; the details have not been independently verified.
Incident Report
| Target Organization | Defencebit |
|---|---|
| Threat Group | thegentlemen |
| Summary | defencebit.com zoominfo.com/c/defencebit/532842616 DefenceBit (founded 2018, Lisbon) is a boutique cybersecurity consulting firm — self-described "hackers, but the good ones" — spun off from Bullray-CIT, an Angolan-government-focused critical-systems integrator. It provides offensive-security services: penetration testing, vulnerability assessments, hardening, source-code and web/API audits, mobile app audits, social-engineering tests and full Red Team engagements, working to PTES/OWASP/OSSTMM standards with manual verification. The team holds top certifications (CEH, CISSP, PMP, Checkpoint CCSE, ISO 27001) and its co-founder later moved to a senior role at the NATO Communications and Information Agency. A notable credential is its contract with Portugal's National Cybersecurity Centre (CNCS) to run the "Cidadão Ciberseguro" course for government workers on the state NAU platform. It remains a very small company (1–10 staff) |
| Date of Breach | 2026-09-29 |
| Discovery Date | 2026-09-30 |
| Region | GB |
| Target Domain | defencebit.com |
| Business Sector | Government & Defense |
| Severity | MEDIUM |
Claim by thegentlemen
defencebit.com zoominfo.com/c/defencebit/532842616 DefenceBit (founded 2018, Lisbon) is a boutique cybersecurity consulting firm — self-described "hackers, but the good ones" — spun off from Bullray-CIT, an Angolan-government-focused critical-systems integrator. It provides offensive-security services: penetration testing, vulnerability assessments, hardening, source-code and web/API audits, mobile app audits, social-engineering tests and full Red Team engagements, working to PTES/OWASP/OSSTMM standards with manual verification. The team holds top certifications (CEH, CISSP, PMP, Checkpoint CCSE, ISO 27001) and its co-founder later moved to a senior role at the NATO Communications and Information Agency. A notable credential is its contract with Portugal's National Cybersecurity Centre (CNCS) to run the "Cidadão Ciberseguro" course for government workers on the state NAU platform. It remains a very small company (1–10 staff)
Posted by the thegentlemen threat actor on its public leak site. This is the group's own statement and has not been independently verified by HackerFeeds.
Sources
Disclaimer
HackerFeeds does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.

