Ninety percent. That’s the cut The Gentlemen ransomware crew is reportedly offering affiliates on every paid extortion, according to Brian Krebs’s reporting on the group’s recruitment push. The math isn’t subtle. A skilled operator running successful intrusions can earn more on a single payday than a senior security engineer makes in a year, with no taxes, no manager, and no compliance review. The Gentlemen has already climbed to the second-most-active ransomware brand by victim count.
That alone would be a story. What makes it a cybersecurity problem worth taking seriously is the supply chain underneath. The same week the affiliate economy is paying like a venture-backed startup, fresh data shows infostealer malware has industrialized credential theft to the point where every affiliate has more pre-validated access than they can use. Identity theft victims are showing up with multiple compromised accounts at once, because the same harvested login often gets resold across three or four operations. This is what the cybercrime market looks like when initial access is cheap and the talent is well-paid.
The Affiliate Market Is Quietly Outbidding Your IT Department
Krebs’s profile of The Gentlemen describes a deliberate recruitment strategy. Offer a 90 percent cut, advertise on Russian-language forums, prioritize affiliates who can produce volume. Compare that to traditional ransomware-as-a-service economics, where operators kept 20 to 30 percent. The Gentlemen are running a discount affiliate brand, and the discount is working: more applicants, faster victim count growth, lower friction to onboard new operators.
Treat this as a labor-market signal. The criminal market for offensive talent is liquid, well-paid, and competitive. Junior operators don’t need to develop their own initial-access tradecraft because they don’t have to. The supply chain hands them pre-authenticated sessions, valid credentials, and active browser cookies on demand. The only skill premium left is post-access movement, exfiltration, and negotiation. Everything before that has been commoditized.
Infostealers Are The Industrial Supply Chain

SecurityWeek’s review of the 2026 threat landscape lands on a number that should change how you allocate defenders’ time: infostealer malware now generates a larger share of confirmed initial access than any vulnerability class, including unpatched edge appliances. Lumma, RedLine, StealC, and their successors are running on millions of personal and contractor devices, harvesting browser-saved credentials, session cookies, cryptocurrency wallets, MFA seed files, password manager databases, and remote-access tokens. The output goes straight into criminal marketplaces, where ransomware affiliates buy access by the kilo.
Your firewall doesn’t see any of this. The stealer infection happens on a personal laptop or a contractor’s home machine. The credentials get sold. The buyer logs into your VPN, your IdP, or your SaaS tenant with a valid username, password, and cookie. From your telemetry, this is a clean authentication from a residential IP that matches the user’s geography. Threat detection that depends on bad-origin signals or known-bad indicators fails closed. Cyber security teams that built their detection stack around malware on managed endpoints are looking in the wrong place.
One Stolen Login Now Cascades Into Six Victims
The Identity Theft Resource Center’s 2026 trends report puts the downstream impact in numbers. More than one in four people who reported identity theft were dealing with multiple identity-related incidents at the same time, drawn from 6,188 individuals the ITRC assisted between April 2025 and March 2026. The chain effect is real and accelerating. A single infostealer infection on a personal device produces credentials that get sold to one affiliate for ransomware staging, another for tax-refund fraud, a third for synthetic-identity loans, and a fourth for SIM-swap-driven crypto theft. Each victim spends months untangling overlapping incidents that all trace back to the same root compromise.
For an enterprise, this matters because the contractor whose home machine is compromised is the one with privileged access to your systems. The exec whose personal Gmail got phished last month still has their corporate session cookie sitting in a stealer log somewhere. The downstream framing former National Cyber Director Chris Inglis described, where cyber attacks reshape everyday life, isn’t theoretical. The cyberattack that shut down Australia’s second-largest sugar producer this week, disrupting the cane harvest, started with someone’s credentials in someone’s marketplace. The same pipeline that ends in a ransom note ends in canceled harvests.
Cybersecurity Moves That Actually Cut The Pipeline
The good news is that the supply chain has weak points you can actually attack. The bad news is that almost none of them live inside the perimeter you already defend. If your threat-protection budget is still weighted toward edge appliances and endpoint malware on corporate-managed devices, you are defending the wrong half of the attack chain.
Concrete actions to take now:
- Subscribe to a stealer-log feed and run continuous matches against your workforce email domains, IdP usernames, and known contractor accounts. When a hit lands, force a password reset, kill active sessions, and rotate any MFA factors tied to that identity.
- Cap session lifetimes hard. Cookie theft is only valuable while the session is live. Twelve-hour maximum for privileged users, with re-authentication on sensitive actions.
- Bind tokens to device posture where your IdP supports it. A cookie pulled out of a stealer log on a residential IP fails the device-bound check even when the credentials are valid.
- Move to phishing-resistant MFA on every account that touches production, billing, source code, or customer data. Push-prompt MFA is no longer sufficient against pre-authenticated session theft.
- Apply brute-force controls and anomaly scoring to every internet-facing auth surface, including VPN, RDP gateways, Citrix, OWA, and any forgotten legacy SSO endpoint. Cheap credentials still get tested at scale.
- Rehearse an incident response playbook that starts with “the credentials are already valid.” If your IR runbook assumes the attacker still needs to phish or exploit, rewrite it.
Security hardening for the contractor and BYOD path matters more than another EDR rollout on the corporate fleet. A defense in depth posture that ignores the personal-device credential pipeline is mostly theater. The affiliate gets paid the same whether your firewall is on or off.
Sources
- Who Runs the Ransomware Group ‘The Gentlemen?’
- Infostealers Turn Millions of Devices Into Credential Theft Machines
- Identity theft is turning into a chain reaction for victims
- The Invisible Battlefield: How Cyber War Is Reshaping Everyday Life
- Cyberattack shuts down major Australian sugar mills, disrupting harvest
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
