Ransomware Group ‘thegentlemen’ Claims Attack on University of San Francisco

A ransomware group calling itself thegentlemen claims to have obtained data from the University of San Francisco, according to a listing posted on the group’s own leak site. The claimed attack is dated September 7, 2026. This listing has been tracked by ransomware.live, a security research platform that monitors ransomware groups’ public leak sites. It is important to stress that this is an unverified claim made by a criminal group — the University of San Francisco has not confirmed this incident, and no regulator has confirmed it either.

What we know — and don’t
  • A group calling itself thegentlemen listed the University of San Francisco on its leak site with a claimed date of September 7, 2026.
  • The University of San Francisco operates in the education sector.
  • The specific types of data the group claims to have obtained have not been disclosed in the listing and have not been confirmed by any party.
  • There is no independent confirmation at this time that any data was actually accessed, obtained, or compromised.
  • The university has not issued a public statement confirming or denying this claim as of this writing.
What should you do if you have an account with this company?
  • Change your password for any account associated with the University of San Francisco, and avoid reusing that password elsewhere.
  • Enable two-factor authentication (2FA) wherever it is offered, particularly on email and financial accounts.
  • Be cautious of unexpected emails, texts, or phone calls claiming to be from the university, especially those asking you to click links, verify information, or provide personal details.
  • Monitor your financial statements and credit reports for any unusual or unauthorized activity.
  • Consider using a service like a service like Aura or LifeLock to monitor for signs that your personal information is circulating or being misused.
  • Keep an eye on official communications from the university for any updates regarding this claim.

BreachLetter will update this page if the University of San Francisco confirms this incident, if new details emerge, or if the matter is officially reported to regulators.

Leave a Comment