Cyber Incident Victim: The Adaptavist Group
Date:
Mar 2026
Location:
United Kingdom
Summary
The Adaptavist Group reported detecting a security breach after an attacker used stolen credentials to gain access to its systems. The company said the accessed systems held typical business data such as contact information and client contracts, and that it engaged external security experts to conduct an internal review. A ransomware group called 'The Gentlemen' claimed responsibility, alleging a full infrastructure compromise and theft of customer records, source code and internal documents, but the company stated there is no evidence that sensitive customer data was accessed or exfiltrated.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 0 techniques |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
In late March 2026, Adaptavist Group detected unauthorized access to its internal systems after an attacker used stolen credentials to log in. The intrusion was identified during routine monitoring, prompting the company to initiate an internal review. Adaptavist subsequently engaged external security experts to assist with the investigation. The company confirmed that the breach came to light when the unauthorized individual gained entry using compromised login details.

The systems that were accessed contained typical business data, specifically contact information and client contracts, according to Adaptavist's statement. A ransomware group calling itself 'The Gentlemen' later claimed responsibility for the incident, asserting that it had achieved a complete infrastructure compromise and exfiltrated a large volume of data including customer records, source code, and internal documents. Adaptavist responded by stating that there is currently no evidence indicating that sensitive customer data was accessed or removed from its environment.
Adaptavist continues to investigate the breach and has not disclosed further technical details about the attacker's actions or the specific systems affected beyond the use of stolen credentials. The company has stated that it is working with external security experts to examine the incident. Adaptavist has emphasized that, based on its current findings, there is no indication that sensitive customer data was compromised.
