Ransom gang targets Dutch ice arena Thialf in cyberattack
Threat actor The Gentlemen is threatening to release all stolen data if Thialf refuses to pay the ransom within the next few days.

Image by Cybernews.
- Thialf confirmed a cyberattack, but said its data and operations were not materially affected.
- The Gentlemen ransomware group claims responsibility and threatens to publish stolen data unless paid this week.
- The attack matters because Thialf will host long-track speed skating at the 2030 Winter Olympics.
- Microsoft says The Gentlemen uses double extortion and has expanded by recruiting affiliates through ransomware services.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
The famous Dutch ice stadium Thialf has become the victim of a cyberattack. The attackers are threatening to publish the stolen data on the dark web if their ransom demand isn’t paid this week.
Thialf is a world-renowned ice arena located in Heerenveen, the Netherlands. It serves as the home base for the Dutch national speed skating team and hosts a wide range of ice sports, including long-track and short-track speed skating, figure skating, and ice hockey.
Recently, Thialf was officially confirmed as the long-track speed skating venue for the 2030 Winter Olympics.
In a press release, Thialf confirms that a “cyberattack with minimal impact” hit the ice stadium. As soon as the attack came to light, a forensic investigation was launched and conducted by both internal and external security experts.
“The full investigation revealed that the cyberattack had no material impact. The investigation showed that the data and operational processes were not affected or compromised,” Thialf states.
During the investigation, all parties directly involved were informed and kept up to date on developments. Apart from this announcement, Thailf hasn’t provided any further details about the cyberattack.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
A group of cybercriminals called The Gentlemen is claiming responsibility. The ransomware extortion group, also known as Storm-2697, has been active since the summer of 2025 and has claimed at least 8 victims in the Netherlands, including the Institute for the Dutch Language.
In May 2026, Microsoft issued a warning against the ransomware extortion group. According to the Redmond-based tech company, The Gentlemen is a financially motivated threat actor that started as a closed ransomware group. In September 2025, it began offering its ransomware-as-a-service (RaaS) platform to affiliates.
More recently, the ransomware extortion group’s operators established an official partnership with BreachForums to recruit affiliates, including penetration testers and initial access brokers.
“The operators behind the ransomware use double extortion tactics, encrypting data while also exfiltrating sensitive information to pressure victims through the threat of public release if the ransom is not paid,” Microsoft says.
According to cybersecurity firms Group-IB and Palo Alto Networks, The Gentlemen exploits known vulnerabilities in Fortinet FortiOS, the Erlang/OTP SSH server, Windows SMB, and the React2Shell vulnerability.