The Gentlemen ransomware group has listed Gerrity Stone, a US stone fabricator, as a victim on its leak site. The Gerrity Stone ransomware attack is, for now, a claim rather than a fully detailed incident, but it fits a pattern that small and mid-sized manufacturers should take seriously.
What We Know About the Gerrity Stone Ransomware Attack
The source report, published by the breach-tracking service DeXpose, says the ransomware group The Gentlemen targeted Gerrity Stone in the USA. Public tracker listings describe the company as a family-owned stone fabrication and installation business. Its LinkedIn page presents it as a New England importer and fabricator of marble, granite, travertine and limestone.
The details are thin. The report does not state what data was taken, how many people are affected, whether operations were disrupted, or whether a ransom demand has been made. Gerrity Stone has not, in the material we reviewed, confirmed the incident. Listings on ransomware leak sites are claims by criminals, and they can be incomplete or exaggerated. Until the company says more, treat the specifics as unverified.
Customers and vendors should still pay attention. Fabricators typically hold quotes, invoices, job-site addresses and contact details for homeowners, contractors and designers, and the company runs an online customer portal. We cannot say whether any of that was involved here, but it is the kind of information worth watching.
How The Gentlemen Operate
The Gentlemen follow the double-extortion model: steal data first, then encrypt systems, then threaten to publish what was taken if the victim does not pay. Posting a company name on a leak site is the public pressure step.
This is not the group's first appearance in our coverage. We have reported on The Gentlemen claiming a data theft from healthcare business Nutex and on the Veradigm breach, where the group claimed 3.5M records. Those cases involved healthcare, while Gerrity Stone is a manufacturer, which suggests the group is not limiting itself to one sector.
Why Small and Mid-Sized Manufacturers Are in the Crosshairs
Manufacturers and trades businesses often run on a mix of older software, shared file servers, remote-access tools and a very small IT team, sometimes a single person or an outside contractor. Downtime is expensive, since a stalled production line or missed installation date hits revenue immediately. That makes the pressure to pay higher, and attackers know it.
The broader numbers back this up. Our coverage of the first half of the year found 4,699 confirmed ransomware attacks recorded globally. Kaspersky's State of Ransomware 2026 report, which we covered in a piece on SMB ransomware threatening big firms, describes gangs changing their playbook and small businesses paying the price twice over. Automation is also lowering the barrier: one report we covered describes an AI tool called Hermes powering ransomware attacks priced at $4, meaning attackers no longer need to be sophisticated to cause damage.
Defenses That Matter: VPNs, Segmentation and Offline Backups
A VPN can help, but it is not a ransomware cure. Here is what it can and cannot do.
What a VPN can do. If staff or contractors reach internal systems remotely, a properly configured business VPN, ideally with multi-factor authentication, keeps those connections encrypted and avoids exposing remote desktop services directly to the internet. It also protects employees on public Wi-Fi.
What a VPN cannot do. It will not stop a phishing email, a stolen password used on a legitimate login, or malware already running on a laptop. Once an attacker is inside the network, a VPN does little. An unpatched or poorly secured VPN gateway can itself become the entry point.
The controls that carry more weight against double extortion are:
- Network segmentation: keep design files, accounting, customer data and production systems on separate segments so one compromised machine cannot reach everything.
- Offline or immutable backups: keep copies that ransomware cannot encrypt or delete, and test restoring them. Backups address the encryption problem, though not the data-theft threat.
- Multi-factor authentication: require it on remote access, email and admin accounts.
- Patching: prioritize internet-facing systems, including VPN appliances.
- Least privilege: limit who can access customer and financial records.
What This Means For You
If you have dealt with Gerrity Stone as a customer, contractor or supplier, watch for unexpected emails or calls that reference your project, quote or payment, since stolen business details are often used for convincing scams. Be cautious about links and invoice changes, and use unique passwords if you have a portal account with any company in the industry.
If you run a small manufacturing or trades business, this claim is a prompt to check your own setup rather than a reason to panic.
Takeaways and Next Steps
The Gerrity Stone ransomware attack remains a claim pending confirmation, but the lesson holds either way. Review how remote access works in your business, remove anything exposed directly to the internet, turn on multi-factor authentication, and confirm you have a recent offline backup you have actually restored from. Then read the Kaspersky SMB ransomware report coverage and the H1 2026 ransomware statistics for context on where attackers are focusing. A VPN is one layer in that setup, and it works best alongside segmentation, backups and strong authentication.




