Ransomware Group The Gentlemen Claims Attack on Leeds Glass Firm Crystal Glass
A family-run glazing company in West Yorkshire has been listed on a dark-web extortion page by The Gentlemen ransomware group. The firm has not confirmed any incident, and the claim is unverified.

Key points
- Ransomware.live, a monitoring service, first observed The Gentlemen's listing of Crystal Glass (Leeds) Ltd on September 26, 2026.
- The group's post dates the claimed incident to September 21, 2026, five days before the listing appeared.
- Crystal Glass has not publicly confirmed any breach, and the claim could not be independently verified at publication time.
- Manufacturing is the most frequently targeted sector in The Gentlemen's claimed victim list, consistent with this listing.
- This is the sixth story Threat Vectr has published on The Gentlemen, building on our report of 8 September when the group listed Australian supplier Sharp Office.
Crystal Glass (Leeds) Ltd isn't a household name outside West Yorkshire, which is precisely the kind of target ransomware groups have favoured for years. Small, family-run, operating across multiple local branches, almost certainly without a dedicated security team. The group's own post describes the company as a family-managed business with roughly 10 to 25 employees, founded in 1962. Treat that description with caution: it's written by criminals trying to pressure the company into paying, and leak-site listings are sometimes exaggerated or outright fabricated.
Ransomware groups run extortion pages, sometimes called leak sites, on the dark web. Name a company publicly, threaten to release stolen files, hope the pressure forces a payout. A listing does not prove a breach happened.
How serious is The Gentlemen as a group?
Active enough to warrant attention. Threat Vectr has tracked this group across five stories since first covering them on 10 June 2026, and the pace of their claimed listings puts them near the top of extortion operations by sheer volume. Manufacturing companies are among their most common listed targets. Those are aggregate counts of unverified criminal claims, not confirmed breaches, but the tempo is notable.
Whether the group is running coordinated intrusions or padding its list to build a reputation is harder to say from the outside. Both happen.
What should Crystal Glass customers and staff do right now?
The claim's unverified, so panic isn't the right response. Practical caution is.
Watch for phishing emails, where criminals send fake messages pretending to be from Crystal Glass or a supplier. Criminals sometimes use the news of a claimed breach to craft convincing scam messages. Any unexpected email asking you to click a link or confirm account details deserves suspicion, regardless of who it appears to be from.
Check whether you're reusing the same password across services if you've shared contact details with the company. A password manager makes fixing that straightforward.
Be wary of any unsolicited phone call offering "breach compensation" or claiming to help you check whether your data was stolen. That scam format reliably follows high-profile leak-site listings.
Crystal Glass has made no public statement. If the company does issue one, that'll be the authoritative source on what, if anything, was actually taken.
Common questions
Does being listed on a ransomware leak site mean the company was definitely hacked?
No. Listings are made by criminals and are sometimes false or posted before any negotiation to create public pressure. Only a statement from the company itself, or an independent investigation, can confirm whether a real breach occurred.
Should I be worried if I'm a Crystal Glass customer?
There's no confirmed data exposure at this stage. Keep an eye on unusual emails or calls referencing your dealings with the company, and report anything suspicious to Action Fraud, the UK's national fraud reporting service, at actionfraud.police.uk.



