A ransomware claim alleges that the threat actor thegentlemen breached PTT Philippines, threatening to encrypt systems and exfiltrate data from PTT Philippines Corporation. The profile describes PTT Philippines as a subsidiary of Thailandβs PTT Oil and Retail Business Public Company Limited, active across retail, wholesale, and commercial petroleum markets in the Philippines. #Philippines
Incident Details
- Victim: PTT Philippines
- Sector: Energy
- Country: PH
- Actor: thegentlemen
- Source: http://tezwsse5czllksjb7cwp65rvnk4oobmzti2znn42i43bjdfd2prqqkad.onion
- Discovered: 2026-03-22 10:43:26.797267
- Published: 2026-03-22 10:34:31.000000
Information
- Ransomware actor: thegentlemen
- Website: pttphilippines.com
- Company profile: zoominfo.com/c/ptt-philippines-corp/353484173
- Subsidiary of Thailandβs PTT Oil and Retail Business Public Company Limited
- Specializes in trading petroleum products across retail, wholesale, and commercial markets
- Offers high-performance fuels, lubricants, and related services to enhance customer satisfaction and fuel efficiency
- Targets both individual consumers and businesses while expanding market presence in the Philippines
- Committed to providing products that meet international standards
- Focuses on innovation and quality
- Engages in corporate social responsibility initiatives to support local communities

Disclaimer: This post is based on public claims made by the ransomware group "thegentlemen". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.