Nutex Health confirms patient data stolen in ransomware attack; The Gentlemen group claims responsibility

Hospital operator says attackers threatened to publish stolen information

edit
By LineZotpaper
Published
Read Time2 min
US hospital operator Nutex Health has confirmed that attackers stole private or confidential patient, employee, provider, business and financial information during a cyberattack disclosed last week, with the ransomware group known as The Gentlemen claiming responsibility and threatening to publish the stolen data.

In an updated filing submitted to the Securities and Exchange Commission (SEC) on Monday, Nutex Health said an unauthorized third party had threatened to publish the stolen information. The company initially disclosed the intrusion on August 24 under a catch-all category, but has now reported the incident under the section reserved for material cybersecurity incidents as its investigation continues.

Nutex did not identify the intruders. However, The Gentlemen ransomware-as-a-service (RaaS) operation added the company to its leak site on Monday and claimed responsibility for the attack. The gang offered no evidence or details to substantiate its claim. Naming victims on a leak site and threatening to publish their data is a standard pressure tactic in double-extortion attacks.

A proposed class action was filed against Nutex on August 27 on behalf of people whose personally identifiable information or protected health information was allegedly accessed or acquired during the intrusion. Nutex said it could not predict the litigation's outcome and had not identified any material impact on its operations or financial reporting systems.

The Gentlemen emerged in mid-2025, reportedly after former Qilin affiliates fell out with that gang's leadership and launched a rival RaaS operation. Researchers describe it as a primarily Russian-speaking operation whose victims are generally located outside the Commonwealth of Independent States. In May, Microsoft detailed a self-propagating encryptor used by the gang's affiliates, warning that the malware combines multiple lateral-movement techniques, increasing the likelihood of widespread impact once initial access is achieved.

Nutex's hospital division now operates 28 facilities across 12 states.

§

Analysis

Why This Matters

  • Healthcare data breaches expose highly sensitive patient information, creating serious privacy and security risks for affected individuals.
  • The double-extortion tactic — threatening to publish stolen data — increases pressure on organizations to pay ransoms and raises the stakes for breach victims.
  • The class action lawsuit highlights the growing legal liability companies face after ransomware incidents, potentially leading to significant financial consequences.

Background

The Gentlemen ransomware group emerged in mid-2025, reportedly formed by former affiliates of the Qilin ransomware operation after a split. Researchers characterize it as a primarily Russian-speaking group that targets victims outside the Commonwealth of Independent States. In May 2026, Microsoft detailed a self-propagating encryptor used by the gang's affiliates, noting it combines multiple lateral-movement techniques to spread rapidly across networks.

Key Perspectives

Nutex Health: The hospital operator is focused on containing the breach, investigating what data was taken, and managing legal and regulatory fallout. It has not identified material operational impact but faces a proposed class action. The Gentlemen: The ransomware group claims responsibility and threatens to publish stolen data — a standard pressure tactic to force payment. No evidence of the theft has been provided. Patients and employees: Affected individuals face potential identity theft, medical fraud, and privacy violations. The class action seeks compensation for harm from the alleged data compromise. Cybersecurity researchers: The attack illustrates the persistent threat from ransomware groups using double extortion and self-propagating malware, especially targeting critical healthcare infrastructure.

What to Watch

  • Whether The Gentlemen follows through on its threat to publish the stolen data, which would confirm the extent of the breach.
  • The progress of the proposed class action and any additional lawsuits that may follow.
  • SEC scrutiny of Nutex's initial disclosure under the catch-all category versus the later material incident filing, as regulators increasingly focus on cybersecurity disclosure compliance.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.