Glassdoor’s Ransomware Deadline Expired Two Weeks Ago: The Data Never Showed Up

The countdown The Gentlemen set for Glassdoor ran out on September 4. Two weeks later, no stolen data has surfaced, no company has confirmed a breach, and the story that made headlines for three days in early September has gone almost entirely quiet.

What Changed Since the Countdown Started

The Gentlemen listed Glassdoor, the jobs and workplace-review platform, on its dark-web leak site on August 28, with a 172-hour countdown that put the deadline at roughly 8:44 p.m. UTC on September 4. Cybernews first reported the threat on September 1, citing the listing tracked by Ransomware.live, which logged the posting as discovered on August 30 at 09:54 UTC with an estimated attack date of August 28. The listing’s own text, according to threat-intelligence tracker DeXpose, reads in part: “The full leak will be published soon, unless a company representative contacts us via the channels provided.” As of this writing, Ransomware.live’s tracker shows no note that the data has been published or that a negotiation was resolved. The entry still stands as an open claim.

The silence extends to the companies themselves, and it is directly checkable. Glassdoor’s own newsroom shows nothing published after an August 11 press release naming its 2026 Best CEOs list. Indeed’s newsroom carries nothing about the claim through a September 4 piece on its FutureWorks conference, its most recent release. Recruit Holdings, the Tokyo-listed parent that owns both companies, posted only routine shareholder notices in September, a dividend announcement and a share-repurchase update, with no mention of a security incident anywhere in its 2026 newsroom.

A Bigger Target Than the First Story Captured

The claim also lands differently than it would have a year ago. Glassdoor completed a merger into Indeed as a single operating entity on July 1, 2026, the final step in a consolidation Recruit Holdings began when it acquired Glassdoor in 2018. The run-up was gradual: Glassdoor closed its last Chicago and San Francisco offices in February 2024 to go fully remote, and Recruit Holdings cut 1,300 combined roles across Indeed and Glassdoor in July 2025, about 6 percent of its HR technology division, the same announcement in which Glassdoor’s own CEO, Christian Sutherland-Wong, departed as the two operations integrated. The Glassdoor brand and website still operate for company reviews and salary data, but the platform now runs under Indeed’s terms of service and privacy policy.

That distinction matters for anyone trying to size up the risk. A confirmed intrusion at a standalone review site is one kind of story; a confirmed intrusion at a platform that now shares infrastructure and policy with one of the world’s largest job sites is a different one. It also raises the odds that any eventual confirmation would come through Indeed’s own communications rather than a dedicated Glassdoor statement, since that function was folded into Indeed well before this specific claim surfaced.

A Group That Doesn’t Need to Bluff

The Gentlemen’s growth curve supports the original assessment that this is not an amateur operation. Check Point traced roughly 320 claimed victims to the group about a year into its run, a figure reported by The Hacker News in April. Unit 42 counted 580 victims across 77 countries by early July. Ransomware.live’s tracker puts the total at 868 victims across 87 countries, with the group’s leak site last observed active on September 15.

Microsoft, which tracks the group as Storm-2697, has documented a worm-like spreading mode that lets the malware jump automatically to every reachable system on a network once an operator enables it. The group also offers affiliates a 90 percent cut of ransom payments, well above the 70 to 80 percent typical in the ransomware-as-a-service market, according to Unit 42 and The Hacker News. Both details point to an operation built for scale rather than a single high-profile extortion attempt, consistent with a group claiming well over 800 victims in roughly fourteen months.

My take is that this record cuts against, not for, the idea that the Glassdoor claim is an empty bluff. A group adding dozens of victims a month and offering affiliates the richest split in the ransomware-as-a-service market has little obvious reason to fabricate a listing it can’t back up. That does not make the claim true. It means the burden of explanation sits more with the total silence on both sides than with the original threat.

The Secondary Evidence Still Doesn’t Agree

Two threat-intelligence firms ran automated checks against known infostealer logs for signs the claim holds up, and they came back with different pictures. SOCRadar’s stealer-log correlation returned just 25 records, all consumer email addresses, no employee credentials, and no way to date when the data was collected, a result the firm says does not clear Glassdoor of compromise but does not confirm one either. SOCRadar frames this explicitly as a limited-exposure finding, not an exoneration, since the group could have gained access through a channel the stealer-log method would not catch, such as phishing or a compromised vendor.

Ransomware.live’s own correlation for the same listing, last queried September 10, shows far larger figures: 45,236 compromised user records, 182,423 exposed passwords, and 496,619 browser cookies, alongside 18 flagged employee accounts. Two firms running similar automated methods against what should be the same underlying claim should not land tens of thousands of records apart, and that gap says more about the limits of stealer-log matching as a verification tool than it does about what Glassdoor actually lost. Neither figure has been matched to an actual data sample, which is the only thing that would settle which, if either, is close to accurate.

GalaxyWarden’s read is the most conservative of the group: its own assessment states outright that “a listing is the attacker’s claim,” and notes that the posting itself specifies no data categories, no record counts, and no proof of possession. UpGuard’s scan of Glassdoor currently shows an A rating, 818 out of 950, and flags detected infostealer malware on systems associated with the company as a general indicator of “potential data breach,” without dating that finding or tying it to The Gentlemen’s claim specifically. Taken together, the four trackers describe four different shades of uncertainty rather than converging on one answer, which is itself the most accurate summary available right now.

What Happens Next

None of this resolves the underlying question, and two weeks of quiet is not new information on its own. Extortion groups routinely let public deadlines lapse while negotiations continue in private, and a company under active incident response has good reason to say nothing until it has something accurate to say. What has changed since the original countdown is the volume of corroborating noise around the claim, and none of the four independent checks agree closely enough with each other to count as confirmation of anything specific.

The responsible read has not moved much from where it started: a credible group made a specific claim, no sample has backed it up, and no company has denied or confirmed it. What has changed is that the claim now sits on top of a much larger, newly consolidated platform than the one it was made against, and the two weeks of silence, however ordinary it may be as incident-response practice, are doing more of the storytelling right now than the original countdown timer did.

The post Glassdoor’s Ransomware Deadline Expired Two Weeks Ago: The Data Never Showed Up appeared first on DataFLOQ.

Leave a Reply

Your email address will not be published. Required fields are marked *

Subscribe to our Newsletter