Ollie’s Place Hit by The Gentlemen Ransomware Gang in Suspected Data Breach
Australian children’s clothing retailer Ollie’s Place has been targeted by the The Gentlemen ransomware gang, which listed the company on its dark web leak site and claimed to have exfiltrated data. The threat actor set a countdown timer expiring in under seven days at the time of reporting for the public release of the allegedly stolen data, though no specific details about the breach have been disclosed.
A spokesperson for Ollie’s Place confirmed the incident after the gang’s name appeared on a compromised point-of-sale (POS) device, rendering it unusable. The company immediately isolated the affected system, engaged its IT support provider for investigation, and replaced the device with a new POS unit. Additional security measures, including new antivirus software, were deployed across the organization.
Ollie’s Place is still assessing the full scope of the breach, including whether customer or employee data was compromised. The company has not yet determined the exact cause or identified any affected individuals but has advised staff to remain vigilant.
The Gentlemen, a ransomware group that emerged in September 2025, has quickly risen to prominence, ranking second in victim count behind Qilin’s ransomware-as-a-service (RaaS) operation. Believed to consist of Russian-speaking threat actors, the group operates under an affiliate model, offering 90% of ransom payments to partners. Recently, The Gentlemen announced a partnership with BreachForums, actively recruiting affiliates including pentesters and access brokers to expand its global operations.
Ollie’s Place TPRM report: https://www.rankiteo.com/company/ollie's-place
"id": "oll1786948330",
"linkid": "ollie's-place",
"type": "Ransomware",
"date": "8/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Children’s clothing',
'location': 'Australia',
'name': 'Ollie’s Place',
'type': 'Retailer'}],
'attack_vector': 'Compromised Point-of-Sale (POS) device',
'data_breach': {'data_exfiltration': True},
'description': 'Australian children’s clothing retailer Ollie’s Place has '
'been targeted by the The Gentlemen ransomware gang, which '
'listed the company on its dark web leak site and claimed to '
'have exfiltrated data. The threat actor set a countdown timer '
'expiring in under seven days for the public release of the '
'allegedly stolen data. The incident was confirmed after the '
'gang’s name appeared on a compromised point-of-sale (POS) '
'device, rendering it unusable.',
'impact': {'brand_reputation_impact': True,
'data_compromised': True,
'operational_impact': 'POS device rendered unusable',
'systems_affected': ['Point-of-Sale (POS) device']},
'initial_access_broker': {'entry_point': 'Compromised POS device'},
'investigation_status': 'Ongoing',
'motivation': 'Financial gain (ransom demand)',
'ransomware': {'data_exfiltration': True,
'ransomware_strain': 'The Gentlemen'},
'references': [{'source': 'Cyber incident report'}],
'response': {'containment_measures': ['Isolated the affected system',
'Replaced the compromised POS device'],
'incident_response_plan_activated': True,
'remediation_measures': ['Deployed new antivirus software across '
'the organization'],
'third_party_assistance': 'IT support provider engaged for '
'investigation'},
'stakeholder_advisories': 'Staff advised to remain vigilant',
'threat_actor': 'The Gentlemen ransomware gang',
'title': 'Ollie’s Place Hit by The Gentlemen Ransomware Gang in Suspected '
'Data Breach',
'type': 'Ransomware'}