ZeroHour
Infosecurity Magazinepublished ()ingested James Coker

Nutex Health Says Patient Data Stolen, Hackers Threaten Leak

highRansomwareimportance 65
AI summary · glm-5.3-flash

The Gentlemen ransomware gang claims breach of US healthcare provider Nutex Health, exfiltrating patient and employee data and threatening publication.

Nutex Health disclosed in an SEC 8-K filing that an unauthorized third party accessed and exfiltrated patient, employee, credentialed provider, business, and financial data from company servers, and threatened to publish it. The Gentlemen ransomware group listed Nutex on its leak site; a class action was filed August 27 and Edelson Lechtzin LLP is separately investigating. Nutex operates over 27 facilities in 12 states and served nearly 100,000 patients in the first half of 2026, with no material operational impact identified so far.

  • 8-K filed August 31; earlier unauthorized activity was disclosed to the SEC on August 24.
  • The Gentlemen RaaS, first observed mid-2025, has surged in 2026 amid rapid affiliate growth.
  • Healthcare is the group's second-most targeted sector at 9% of victims, per Sophos analysis.
  • Affiliates typically gain initial access by exploiting firewall vulnerabilities and abusing VPN services.
  • Separately, McKesson confirmed a breach possibly affecting 284 million records, claimed by ShinyHunters.
Full article522 words · extracted from infosecurity-magazine.com · click to collapse

US healthcare provider Nutex Health has disclosed that a threat actor has stolen sensitive data, including of patients, and threatened to publish it online.

The Texas-based firm, which delivers care through facilities throughout the US, made the notification in an 8-K filing to the Securities and Exchange Commission (SEC) on August 31.

In the filing, Nutex said it believes that “certain information maintained on the company’s servers was accessed and exfiltrated by an unauthorized third party, including patient and employee, credentialed provider, business and financial information that is private and/or confidential.”

“The third party has threatened to post such information externally,” the company added.

Nutex said it is continuing to assess whether any other data was stolen by the attacker during the incident and will monitor for any leaks online.

It also confirmed it will notify all impacted patients of the data breach.

To date, the provider has not identified any material impact on its business operations or financial reporting systems arising from the incident.

Nutex first informed the SEC on August 24 that it had detected unauthorized activity involving data stored on its computer network.

Nutex revealed that following this prior filing, a class action complaint was filed on August 27 on behalf of individuals whose personally identifiable information (PII) and/or protected health information was accessed and/or acquired by an unauthorized party in connection with the incident.

“At this stage, the company is unable to predict the outcome of the litigation or estimate the potential impact of the incident on the company’s business strategy, operations, financial condition, results of operations or the trading price of the company’s common stock,” Nutex stated.

Legal firm Edelson Lechtzin LLP said on September 1 that it is separately investigating the data breach and is offering to evaluate affected individuals’ rights at no cost.

Nutex owns and operates over 27 facilities in 12 states across the US. It reportedly served nearly 100,000 patients during the first six months of 2026.

Notorious Ransomware Group Claims Breach

The Gentlemen ransomware gang has reportedly claimed responsibility for the attack on Nutex, listing the firm on its dark web portal.

The ransomware-as-a-service (RaaS) operator was first observed in mid-2025, with its activity levels exploding in 2026 amid rapid affiliate growth.

Read now: The Gentlemen Overtakes Qilin as Most Prolific Ransomware Threat

An analysis of the actor published by Sophos on September 1 highlighted the opportunistic nature of The Gentlemen affiliates, with victims representing a wide variety of sectors.

However, healthcare is the group’s second most commonly targeted industry, making up 9% of The Gentlemen victims, just behind manufacturing at 10%.

Affiliates typically rely on exploiting vulnerabilities in firewalls and abusing VPN services to gain initial access into victim environments.

On August 28, one of America’s largest healthcare distributors, McKesson, confirmed that it had suffered a data breach affecting customers within its Oncology & Multispecialty and Medical-Surgical business units.

Reports suggest as many as 284 million records may have been compromised, with McKesson hit with a $55m ransom demand.

Ransomware group ShinyHunters posted an entry for the firm on their leak site, claiming to have compromised hundreds of millions of records.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/nutex-patient-data-stolen/