HackerFeeds
All ransomware incidents
defencebit.com

Ransomware group thegentlemen hits Defencebit

MEDIUM
·Government & Defense·GB·2026-09-29

Defencebit — a government & defense target operating in GB has been listed by the thegentlemen ransomware group on 2026-09-29. The information below reflects what the threat actor has publicly claimed on their leak site; the details have not been independently verified.

Incident Report

Target OrganizationDefencebit
Threat Group
thegentlemen
Summarydefencebit.com zoominfo.com/c/defencebit/532842616 DefenceBit (founded 2018, Lisbon) is a boutique cybersecurity consulting firm — self-described "hackers, but the good ones" — spun off from Bullray-CIT, an Angolan-government-focused critical-systems integrator. It provides offensive-security services: penetration testing, vulnerability assessments, hardening, source-code and web/API audits, mobile app audits, social-engineering tests and full Red Team engagements, working to PTES/OWASP/OSSTMM standards with manual verification. The team holds top certifications (CEH, CISSP, PMP, Checkpoint CCSE, ISO 27001) and its co-founder later moved to a senior role at the NATO Communications and Information Agency. A notable credential is its contract with Portugal's National Cybersecurity Centre (CNCS) to run the "Cidadão Ciberseguro" course for government workers on the state NAU platform. It remains a very small company (1–10 staff)
Date of Breach2026-09-29
Discovery Date2026-09-30
RegionGB
Target Domaindefencebit.com
Business SectorGovernment & Defense
Severity
MEDIUM

Claim by thegentlemen

defencebit.com zoominfo.com/c/defencebit/532842616 DefenceBit (founded 2018, Lisbon) is a boutique cybersecurity consulting firm — self-described "hackers, but the good ones" — spun off from Bullray-CIT, an Angolan-government-focused critical-systems integrator. It provides offensive-security services: penetration testing, vulnerability assessments, hardening, source-code and web/API audits, mobile app audits, social-engineering tests and full Red Team engagements, working to PTES/OWASP/OSSTMM standards with manual verification. The team holds top certifications (CEH, CISSP, PMP, Checkpoint CCSE, ISO 27001) and its co-founder later moved to a senior role at the NATO Communications and Information Agency. A notable credential is its contract with Portugal's National Cybersecurity Centre (CNCS) to run the "Cidadão Ciberseguro" course for government workers on the state NAU platform. It remains a very small company (1–10 staff)

Posted by the thegentlemen threat actor on its public leak site. This is the group's own statement and has not been independently verified by HackerFeeds.

Disclaimer

HackerFeeds does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.