The countdown The Gents set for Glassdoor ran out on September 4. Two weeks later, no stolen knowledge has surfaced, no firm has confirmed a breach, and the story that made headlines for 3 days in early September has gone virtually totally quiet.
What Modified For the reason that Countdown Began
The Gents listed Glassdoor, the roles and workplace-review platform, on its dark-web leak web site on August 28, with a 172-hour countdown that put the deadline at roughly 8:44 p.m. UTC on September 4. Cybernews first reported the menace on September 1, citing the itemizing tracked by Ransomware.reside, which logged the posting as found on August 30 at 09:54 UTC with an estimated assault date of August 28. The itemizing’s personal textual content, in keeping with threat-intelligence tracker DeXpose, reads partly: “The complete leak will likely be revealed quickly, except an organization consultant contacts us by way of the channels offered.” As of this writing, Ransomware.reside’s tracker reveals no notice that the information has been revealed or {that a} negotiation was resolved. The entry nonetheless stands as an open declare.
The silence extends to the businesses themselves, and it’s immediately checkable. Glassdoor’s personal newsroom reveals nothing revealed after an August 11 press launch naming its 2026 Greatest CEOs checklist. Certainly’s newsroom carries nothing concerning the declare via a September 4 piece on its FutureWorks convention, its most up-to-date launch. Recruit Holdings, the Tokyo-listed father or mother that owns each corporations, posted solely routine shareholder notices in September, a dividend announcement and a share-repurchase replace, with no point out of a safety incident wherever in its 2026 newsroom.
A Greater Goal Than the First Story Captured
The declare additionally lands in another way than it might have a yr in the past. Glassdoor accomplished a merger into Certainly as a single working entity on July 1, 2026, the ultimate step in a consolidation Recruit Holdings started when it acquired Glassdoor in 2018. The run-up was gradual: Glassdoor closed its final Chicago and San Francisco workplaces in February 2024 to go absolutely distant, and Recruit Holdings reduce 1,300 mixed roles throughout Certainly and Glassdoor in July 2025, about 6 p.c of its HR expertise division, the identical announcement through which Glassdoor’s personal CEO, Christian Sutherland-Wong, departed as the 2 operations built-in. The Glassdoor model and web site nonetheless function for firm evaluations and wage knowledge, however the platform now runs below Certainly’s phrases of service and privateness coverage.
That distinction issues for anybody making an attempt to measurement up the danger. A confirmed intrusion at a standalone evaluation web site is one type of story; a confirmed intrusion at a platform that now shares infrastructure and coverage with one of many world’s largest job websites is a unique one. It additionally raises the percentages that any eventual affirmation would come via Certainly’s personal communications slightly than a devoted Glassdoor assertion, since that perform was folded into Certainly effectively earlier than this particular declare surfaced.
A Group That Doesn’t Must Bluff
The Gents’s development curve helps the unique evaluation that this isn’t an novice operation. Verify Level traced roughly 320 claimed victims to the group a few yr into its run, a determine reported by The Hacker Information in April. Unit 42 counted 580 victims throughout 77 international locations by early July. Ransomware.reside’s tracker places the entire at 868 victims throughout 87 international locations, with the group’s leak web site final noticed lively on September 15.
Microsoft, which tracks the group as Storm-2697, has documented a worm-like spreading mode that lets the malware leap routinely to each reachable system on a community as soon as an operator permits it. The group additionally affords associates a 90 p.c reduce of ransom funds, effectively above the 70 to 80 p.c typical within the ransomware-as-a-service market, in keeping with Unit 42 and The Hacker Information. Each particulars level to an operation constructed for scale slightly than a single high-profile extortion try, per a gaggle claiming effectively over 800 victims in roughly fourteen months.
My take is that this report cuts in opposition to, not for, the concept the Glassdoor declare is an empty bluff. A gaggle including dozens of victims a month and providing associates the richest break up within the ransomware-as-a-service market has little apparent purpose to manufacture a list it might’t again up. That doesn’t make the declare true. It means the burden of clarification sits extra with the entire silence on each side than with the unique menace.
The Secondary Proof Nonetheless Doesn’t Agree
Two threat-intelligence corporations ran automated checks in opposition to identified infostealer logs for indicators the declare holds up, and so they got here again with completely different footage. SOCRadar’s stealer-log correlation returned simply 25 data, all shopper e mail addresses, no worker credentials, and no technique to date when the information was collected, a consequence the agency says doesn’t clear Glassdoor of compromise however doesn’t affirm one both. SOCRadar frames this explicitly as a limited-exposure discovering, not an exoneration, because the group may have gained entry via a channel the stealer-log technique wouldn’t catch, akin to phishing or a compromised vendor.
Ransomware.reside’s personal correlation for a similar itemizing, final queried September 10, reveals far bigger figures: 45,236 compromised person data, 182,423 uncovered passwords, and 496,619 browser cookies, alongside 18 flagged worker accounts. Two corporations operating comparable automated strategies in opposition to what needs to be the identical underlying declare mustn’t land tens of 1000’s of data aside, and that hole says extra concerning the limits of stealer-log matching as a verification instrument than it does about what Glassdoor really misplaced. Neither determine has been matched to an precise knowledge pattern, which is the one factor that will settle which, if both, is near correct.
GalaxyWarden’s learn is probably the most conservative of the group: its personal evaluation states outright that “a list is the attacker’s declare,” and notes that the posting itself specifies no knowledge classes, no report counts, and no proof of possession. UpGuard’s scan of Glassdoor at present reveals an A score, 818 out of 950, and flags detected infostealer malware on techniques related to the corporate as a common indicator of “potential knowledge breach,” with out courting that discovering or tying it to The Gents’s declare particularly. Taken collectively, the 4 trackers describe 4 completely different shades of uncertainty slightly than converging on one reply, which is itself probably the most correct abstract out there proper now.
What Occurs Subsequent
None of this resolves the underlying query, and two weeks of quiet is just not new info by itself. Extortion teams routinely let public deadlines lapse whereas negotiations proceed in personal, and an organization below lively incident response has good purpose to say nothing till it has one thing correct to say. What has modified because the unique countdown is the amount of corroborating noise across the declare, and not one of the 4 unbiased checks agree carefully sufficient with one another to depend as affirmation of something particular.
The accountable learn has not moved a lot from the place it began: a reputable group made a particular declare, no pattern has backed it up, and no firm has denied or confirmed it. What has modified is that the declare now sits on prime of a a lot bigger, newly consolidated platform than the one it was made in opposition to, and the 2 weeks of silence, nonetheless bizarre it might be as incident-response apply, are doing extra of the storytelling proper now than the unique countdown timer did.
The countdown The Gents set for Glassdoor ran out on September 4. Two weeks later, no stolen knowledge has surfaced, no firm has confirmed a breach, and the story that made headlines for 3 days in early September has gone virtually totally quiet.
What Modified For the reason that Countdown Began
The Gents listed Glassdoor, the roles and workplace-review platform, on its dark-web leak web site on August 28, with a 172-hour countdown that put the deadline at roughly 8:44 p.m. UTC on September 4. Cybernews first reported the menace on September 1, citing the itemizing tracked by Ransomware.reside, which logged the posting as found on August 30 at 09:54 UTC with an estimated assault date of August 28. The itemizing’s personal textual content, in keeping with threat-intelligence tracker DeXpose, reads partly: “The complete leak will likely be revealed quickly, except an organization consultant contacts us by way of the channels offered.” As of this writing, Ransomware.reside’s tracker reveals no notice that the information has been revealed or {that a} negotiation was resolved. The entry nonetheless stands as an open declare.
The silence extends to the businesses themselves, and it’s immediately checkable. Glassdoor’s personal newsroom reveals nothing revealed after an August 11 press launch naming its 2026 Greatest CEOs checklist. Certainly’s newsroom carries nothing concerning the declare via a September 4 piece on its FutureWorks convention, its most up-to-date launch. Recruit Holdings, the Tokyo-listed father or mother that owns each corporations, posted solely routine shareholder notices in September, a dividend announcement and a share-repurchase replace, with no point out of a safety incident wherever in its 2026 newsroom.
A Greater Goal Than the First Story Captured
The declare additionally lands in another way than it might have a yr in the past. Glassdoor accomplished a merger into Certainly as a single working entity on July 1, 2026, the ultimate step in a consolidation Recruit Holdings started when it acquired Glassdoor in 2018. The run-up was gradual: Glassdoor closed its final Chicago and San Francisco workplaces in February 2024 to go absolutely distant, and Recruit Holdings reduce 1,300 mixed roles throughout Certainly and Glassdoor in July 2025, about 6 p.c of its HR expertise division, the identical announcement through which Glassdoor’s personal CEO, Christian Sutherland-Wong, departed as the 2 operations built-in. The Glassdoor model and web site nonetheless function for firm evaluations and wage knowledge, however the platform now runs below Certainly’s phrases of service and privateness coverage.
That distinction issues for anybody making an attempt to measurement up the danger. A confirmed intrusion at a standalone evaluation web site is one type of story; a confirmed intrusion at a platform that now shares infrastructure and coverage with one of many world’s largest job websites is a unique one. It additionally raises the percentages that any eventual affirmation would come via Certainly’s personal communications slightly than a devoted Glassdoor assertion, since that perform was folded into Certainly effectively earlier than this particular declare surfaced.
A Group That Doesn’t Must Bluff
The Gents’s development curve helps the unique evaluation that this isn’t an novice operation. Verify Level traced roughly 320 claimed victims to the group a few yr into its run, a determine reported by The Hacker Information in April. Unit 42 counted 580 victims throughout 77 international locations by early July. Ransomware.reside’s tracker places the entire at 868 victims throughout 87 international locations, with the group’s leak web site final noticed lively on September 15.
Microsoft, which tracks the group as Storm-2697, has documented a worm-like spreading mode that lets the malware leap routinely to each reachable system on a community as soon as an operator permits it. The group additionally affords associates a 90 p.c reduce of ransom funds, effectively above the 70 to 80 p.c typical within the ransomware-as-a-service market, in keeping with Unit 42 and The Hacker Information. Each particulars level to an operation constructed for scale slightly than a single high-profile extortion try, per a gaggle claiming effectively over 800 victims in roughly fourteen months.
My take is that this report cuts in opposition to, not for, the concept the Glassdoor declare is an empty bluff. A gaggle including dozens of victims a month and providing associates the richest break up within the ransomware-as-a-service market has little apparent purpose to manufacture a list it might’t again up. That doesn’t make the declare true. It means the burden of clarification sits extra with the entire silence on each side than with the unique menace.
The Secondary Proof Nonetheless Doesn’t Agree
Two threat-intelligence corporations ran automated checks in opposition to identified infostealer logs for indicators the declare holds up, and so they got here again with completely different footage. SOCRadar’s stealer-log correlation returned simply 25 data, all shopper e mail addresses, no worker credentials, and no technique to date when the information was collected, a consequence the agency says doesn’t clear Glassdoor of compromise however doesn’t affirm one both. SOCRadar frames this explicitly as a limited-exposure discovering, not an exoneration, because the group may have gained entry via a channel the stealer-log technique wouldn’t catch, akin to phishing or a compromised vendor.
Ransomware.reside’s personal correlation for a similar itemizing, final queried September 10, reveals far bigger figures: 45,236 compromised person data, 182,423 uncovered passwords, and 496,619 browser cookies, alongside 18 flagged worker accounts. Two corporations operating comparable automated strategies in opposition to what needs to be the identical underlying declare mustn’t land tens of 1000’s of data aside, and that hole says extra concerning the limits of stealer-log matching as a verification instrument than it does about what Glassdoor really misplaced. Neither determine has been matched to an precise knowledge pattern, which is the one factor that will settle which, if both, is near correct.
GalaxyWarden’s learn is probably the most conservative of the group: its personal evaluation states outright that “a list is the attacker’s declare,” and notes that the posting itself specifies no knowledge classes, no report counts, and no proof of possession. UpGuard’s scan of Glassdoor at present reveals an A score, 818 out of 950, and flags detected infostealer malware on techniques related to the corporate as a common indicator of “potential knowledge breach,” with out courting that discovering or tying it to The Gents’s declare particularly. Taken collectively, the 4 trackers describe 4 completely different shades of uncertainty slightly than converging on one reply, which is itself probably the most correct abstract out there proper now.
What Occurs Subsequent
None of this resolves the underlying query, and two weeks of quiet is just not new info by itself. Extortion teams routinely let public deadlines lapse whereas negotiations proceed in personal, and an organization below lively incident response has good purpose to say nothing till it has one thing correct to say. What has modified because the unique countdown is the amount of corroborating noise across the declare, and not one of the 4 unbiased checks agree carefully sufficient with one another to depend as affirmation of something particular.
The accountable learn has not moved a lot from the place it began: a reputable group made a particular declare, no pattern has backed it up, and no firm has denied or confirmed it. What has modified is that the declare now sits on prime of a a lot bigger, newly consolidated platform than the one it was made in opposition to, and the 2 weeks of silence, nonetheless bizarre it might be as incident-response apply, are doing extra of the storytelling proper now than the unique countdown timer did.















