Nutex Health Data Breach Tied to Gentlemen
Healthcare operator Nutex confirms patient and employee data was stolen in an August cyberattack, with the Gentlemen ransomware gang claiming

Healthcare facilities operator Nutex has confirmed that hackers stole patient and employee data during a cyberattack in August 2026. The company disclosed the data theft in a regulatory filing with the U.S. Securities and Exchange Commission on Monday.
Nutex stated that cybercriminals breached its servers and exfiltrated information related to patients, employees, and external providers, along with confidential financial data. The attackers are now extorting the company. "The third party has threatened to post such information externally," Nutex said in its 8-K filing. An investigation into the full scope of the stolen data is ongoing.
The Houston-based company, which operates 27 hospital and outpatient facilities across 12 states, first disclosed a cybersecurity incident to the SEC on August 24. It reported earning $427.2 million in the first half of 2026.
The Gentlemen Ransomware Gang Claims Attack
The Gentlemen ransomware gang claimed responsibility for the attack on Monday, adding Nutex to its data leak site. This ransomware-as-a-service group has been active since September 2025. Cybersecurity experts believe it was formed by a disgruntled former affiliate of the Qilin ransomware operation.
The gang is suspected to be based in Russia. Its rules prohibit attacks on Commonwealth of Independent States countries, and its communications on cybercrime forums are in Russian. Since emerging, the group has launched at least 350 attacks.
Gentlemen offers a flexible model to its affiliates. They can conduct full ransomware encryption attacks or opt for data exfiltration-only incidents. The gang takes a notably small cut from exfiltration attacks.
Legal and Operational Fallout
Following Nutex's initial disclosure, a class action complaint was filed in Texas. The lawsuit is on behalf of individuals whose personally identifiable information and protected health information were allegedly accessed in the breach.
Nutex warned investors that it cannot predict the outcome of this litigation. The company also stated it is unable to estimate the potential impact of the incident on its business strategy, operations, or financial results.
A Pattern of Healthcare Targeting
The attack on Nutex follows a disruptive incident caused by the same gang. The Gentlemen group recently shut down the IT system of nonprofit medical provider AnMed and took over the company's Facebook page. AnMed was forced to close dozens of facilities for several days and later confirmed a theft of patient information.
The gang has shown a significant focus on industrial and healthcare sectors. In the second quarter of 2026 alone, the group claimed 125 attacks on industrial organizations, according to operational technology firm Dragos. This made it the third most active ransomware group during that period.
Cybersecurity firm Gambit Security reported two weeks ago that an affiliate of The Gentlemen was seen using the AI tool Claude Code during intrusions into at least six organizations. The company did not specify which cybercrime group was behind the Nutex attack in its filing and has not responded to requests for comment.





