Thialf, one of the world’s best-known speed skating venues, has confirmed that it was targeted in a cyberattack after a ransomware group threatened to publish allegedly stolen data unless a ransom is paid. The Dutch ice arena said its investigation found no material impact on its operations or data despite the extortion attempt.
Located in Heerenveen, the Netherlands, Thialf serves as the home venue for the Dutch national speed skating team and regularly hosts long-track and short-track speed skating competitions, figure skating events and ice hockey. The arena was also recently selected as the venue for long-track speed skating during the 2030 Winter Olympics.
In a public statement, Thialf said it detected a cyberattack and immediately launched a forensic investigation involving both internal specialists and external cybersecurity experts. The organisation did not disclose when the incident occurred or provide technical details about how the attackers gained access.
According to the arena, the investigation concluded that the attack caused only minimal disruption. Thialf stated that neither its operational processes nor its data were materially affected or compromised.
The organisation added that all parties directly involved in the incident were informed during the investigation and kept updated as the inquiry progressed. Beyond its official statement, Thialf has released a few additional details about the nature of the attack.
The ransomware group known as The Gentlemen has claimed responsibility for the incident. That attribution is based solely on the group’s own claim and has not been independently verified by Thialf or Dutch authorities.
The group has reportedly threatened to publish data on the dark web if its ransom demand is not met. Thialf has not confirmed that any information was stolen or that negotiations with the attackers are taking place.
The Gentlemen, also tracked by Microsoft as Storm-2697, emerged in 2025 as a financially motivated cybercriminal operation. According to Microsoft, the group initially operated as a closed ransomware outfit before expanding in September 2025 by offering its ransomware through a ransomware-as-a-service (RaaS) model, allowing affiliated criminals to deploy its malware during attacks.
Microsoft also reported that the group’s operators later partnered with the cybercrime forum BreachForums to recruit affiliates, including penetration testers and initial access brokers. Initial access brokers specialise in obtaining and selling access to compromised corporate networks, which can then be used by ransomware operators to launch attacks.
Like many modern ransomware operations, The Gentlemen is known for using double extortion tactics, according to Microsoft. In these attacks, criminals not only encrypt a victim’s systems but also steal data beforehand, allowing them to threaten public disclosure if a ransom is not paid.
Security researchers have linked the group to attacks exploiting several publicly known vulnerabilities. According to Microsoft, Group-IB and Palo Alto Networks, the threat actors have targeted flaws affecting Fortinet FortiOS devices, the Erlang/OTP SSH implementation, Windows Server Message Block (SMB), and the React2Shell vulnerability to gain access to victim environments.
Thialf has not indicated that any of those vulnerabilities were involved in the incident at the arena. The organisation has also not confirmed whether ransomware was deployed within its network or whether any files were exfiltrated.
At the conclusion of its investigation, Thialf maintained that its systems continued operating normally and that the incident had no material impact on its activities. The organisation has not announced any further updates, while The Gentlemen’s claim that data was stolen remains unverified by independent sources.
