Glassdoor has appeared on the leak site operated by the Gentlemen ransomware group, with the attackers threatening to release allegedly stolen information if the company does not respond before a countdown expires.

 

 

Glassdoor is a major online employment platform where current and former employees can anonymously review companies, share salary information, and describe their workplace experiences. The service also provides job listings and information about employers, allowing job seekers to research companies and employment opportunities. Glassdoor attracts as many as 67 million unique visitors per month, hosts reviews covering more than two million companies, and features millions of active job listings.

The Gentlemen ransomware gang claims it breached Glassdoor and exfiltrated data from the company. Its leak-site listing reportedly included a 172-hour countdown, giving Glassdoor slightly more than seven days before the threatened publication.

However, Gentlemen has not released samples that would substantiate its claims. Glassdoor has also not confirmed the alleged breach, meaning the amount and nature of any potentially compromised information remain unknown.

There is currently no evidence establishing whether the attackers obtained internal corporate documents, information belonging to Glassdoor employees, data associated with job seekers, or other records. Until Glassdoor or investigators provide additional information, the ransomware group’s claims should be treated as unverified.

If employment-related information were among the stolen records, it could potentially have value beyond the immediate extortion attempt. Employment platforms contain information about hiring activity across large numbers of organizations, while individual job postings can provide clues about companies’ staffing priorities and workforce changes.

Personal information could create additional risks if it were compromised. Contact details combined with information about a person’s job search could potentially be used to create targeted phishing emails impersonating prospective employers. Corporate email information could similarly assist attackers in constructing social engineering campaigns or cross-referencing records against information exposed in previous breaches. None of these categories of information have been confirmed as stolen from Glassdoor.

Gentlemen operates using a ransomware-as-a-service model in which affiliates conduct attacks using infrastructure provided by the operation and share proceeds with its organizers.

Security researchers have linked the group to ArmCorp, previously an affiliate cluster associated with the Qilin ransomware operation. A dispute involving approximately $48,000 in allegedly unpaid commissions became public on an underground forum in July 2025. Evidence suggests the separation was already underway before the dispute became public, as a Gentlemen ransomware sample containing the group’s leak-site address had appeared earlier that month.

The operation uses double extortion tactics involving data theft, encryption, and threats to publish stolen information. Researchers have identified victims in multiple countries, with Thailand reportedly accounting for the largest number.

For now, Gentlemen’s claims against Glassdoor remain unverified. No samples have been published, and the company has not confirmed that its systems or data were compromised.

Leave a Reply