CSIDB logo
Incident

The Adaptavist Group

Incident posture

Attack window
Mar 2026
Location
United Kingdom
Status
Ongoing
CIA posture
Available to members
Updated
2026-09-12 04:59

Linked entities

Victim
The Adaptavist Group
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Mar 2026
Discovered
Mar 2026
Disclosed
Apr 2026
Resolved
Pending

Summary

The Adaptavist Group is investigating a security breach after an unauthorized individual gained access to its systems using stolen credentials. The intrusion exposed typical business data such as contact information and client contracts, according to the company’s statement. A ransomware group called The Gentlemen has claimed responsibility, alleging a complete infrastructure compromise and the theft of customer records, source code and internal documents. The company says there is currently no evidence that sensitive customer data was accessed or exfiltrated, and it has engaged external security experts to conduct an internal review.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

0 techniques

Description

In late March 2026, Adaptavist Group detected unauthorized access to its internal systems after an attacker used stolen credentials to log in. The discovery triggered an immediate internal review and the company promptly engaged external security experts to assist with the investigation. According to the company, the breach was identified through monitoring that flagged the anomalous login activity. Adaptavist confirmed that the intrusion was the result of compromised login details rather than a vulnerability in its software offerings.

The systems that were accessed contained typical business data such as employee contact information and client contracts, reflecting the consultancy’s role in providing Atlassian‑based tools like Jira and Confluence. Adaptavist emphasized that the compromised environment did not include repositories of source code or sensitive customer databases. Shortly after the incident became known, a ransomware group styling itself “The Gentlemen” publicly claimed responsibility, asserting a complete infrastructure takeover and the exfiltration of vast amounts of data including customer records and internal documents. Adaptavist responded by disputing the claim, stating that forensic analysis to date has uncovered no evidence that any sensitive customer information was accessed or removed.

The company has continued its investigation alongside the external security experts it engaged. Adaptavist has not disclosed any impact on its client‑facing services or on the availability of its consultancy offerings. As of the latest public statement, the firm reiterates that there is currently no evidence that sensitive customer data was accessed or exfiltrated and says it will share further information if the investigation yields new findings.

Sources

Sources available to members: 1 source.

CSIDB