Skip to content
Ransomware News

Ransomware Group thegentlemen Hits: Soja de Portugal

Admin
HookPhish team
Target organization Soja de Portugal write.as Agriculture and Food Production

Summary

In the latest cybersecurity news, Soja de Portugal — a company operating in the PT — has fallen victim to a ransomware attack conducted by the group thegentlemen. This data breach, discovered on 2026-06-04T09:09:36.829737+00:00, underscores the increasing need for proactive cybersecurity defenses as we continue through 2026.

Incident Report

Attribute Information
Target Organization Soja de Portugal
Threat Group thegentlemen
Summary ***.pt ***.com/c/soja-de-portugal/458493209

491GB leaked from there as a result of this breach.

What kind of data leaked:
– SAP data
– contacts
– contracts
– planning
– logistics
– projects data
– personal data
– employee data
– partners data
– customers data
– financial data
– correspondence
– production data
– quality control data
– offers and proposals
– data related to Sorgal, Avicasal, Savinor and other brands
– other sensitive business data

Instead of negotiations, threats were made and the leaked data was not even reported to anyone

here is the text they wrote https://***.as/***.md

Date of Breach 2026-06-03T14:43:45+00:00
Discovery Date 2026-06-04T09:09:36.829737+00:00
Region PT
Target Domain write.as
Business Sector Agriculture and Food Production

 

Recommended Security Actions

In response to increasing cyber threats, it’s critical to protect your organization with proactive security measures. HookPhish provides enterprise-grade solutions designed to reduce your risk of future attacks:

Protect your organization before it becomes the next headline. Explore HookPhish.

How HookPhish Helps You Stay Ahead

Don’t wait for a breach to take action — stay informed and take control of your cybersecurity posture today.

You can also check if your organization’s data has been exposed using our free Data Breach Checker.

Disclaimer

HookPhish does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.

Related articles

Security training designed for people.

See how HookPhish turns phishing simulation, training and threat monitoring into measurable human-risk reduction.

Book a demo Explore solutions