ZeroHour
Victim

Nutex Health

0 mentions in 7 days · 3 in 30 days · 3 total · first seen · last

Timeline

Nutex Health Says Patient Data Stolen, Hackers Threaten Leak

The Gentlemen ransomware gang claims breach of US healthcare provider Nutex Health, exfiltrating patient and employee data and threatening publication.

Nutex Health disclosed in an SEC 8-K filing that an unauthorized third party accessed and exfiltrated patient, employee, credentialed provider, business, and financial data from company servers, and threatened to publish it. The Gentlemen ransomware group listed Nutex on its leak site; a class action was filed August 27 and Edelson Lechtzin LLP is separately investigating. Nutex operates over 27 facilities in 12 states and served nearly 100,000 patients in the first half of 2026, with no material operational impact identified so far.

Infosecurity Magazine · 13d agoRansomware

Healthcare facilities operator Nutex says patient, employee data stolen in August incident

The Gentlemen ransomware gang claims the theft of patient and employee data from healthcare operator Nutex Health, which disclosed the extortion in SEC filings.

Nutex Health said in an 8-K filing that intruders broke into its servers and exfiltrated patient, employee, provider and confidential financial data, and that it is being extorted with threats to publish the information. A Texas class action was filed after the company's August 24 disclosure, and Nutex cannot yet estimate the incident's impact. The Gentlemen ransomware-as-a-service gang, active since September 2025 and believed Russia-based, listed Nutex on its leak site; Dragos ranked it third among groups attacking industrial organizations in Q2 2026 with 125 claimed attacks.

The Record · 14d agoRansomware

Risky Bulletin: Russia starts blocking DoH and DoT

Russian users report blocks on DoH and DoT servers, including Cloudflare 1.1.1.1 and Google 8.8.8.8, in an apparent censorship crackdown.

Russian internet users began reporting failures connecting to DNS-over-HTTPS and DNS-over-TLS servers, suggesting a government crackdown on the two privacy protocols. The blocks reportedly cover Cloudflare's 1.1.1.1 and Google's 8.8.8.8 resolvers; Roskomnadzor has not officially confirmed the action. The agency tested a similar block in March on Beeline's network and had named DoH for blocking as early as 2021. The bulletin also briefly notes state-sponsored phishing of EU officials, a DDoS against Norway's Digdir, the ReliaQuest/ShinyHunters dispute, and older ransomware and breach disclosures.

Risky Business News · 20d agoPolicy & legal1