2026 Adaptavist Group — unauthorized access via stolen credentials; TheGentlemen ransomware claims disputed by firm
Data compromised
Potential internal/source/credential material per actor chatter; vendor disputed customer PII exfiltration in early statements
Technical writeup
The Register reported UK-based Adaptavist Group as investigating an “IT security incident” detected after late-March 2026 activity in which an intruder leveraged compromised login details across portions of its environment (the consultancy builds tooling and services atop Atlassian Jira/Confluence ecosystems). Adaptavist’s CEO circulated a customer letter framing forensic investigation and asserting no confirmed evidence that customer/partner personal data had been compromised. Concurrently TheGentlemen ransomware branding appeared in reporting with forum-style claims referencing hundreds of thousands of customer records plus source artefacts such as ScriptRunner—claims the vendor cautioned could be exaggerated. Separate impostor emails impersonating Adaptavists heightened downstream phishing risk.
Root cause
Credential-based unauthorized access plus alleged ransomware/extortion overlays per press