In an updated filing submitted to the Securities and Exchange Commission (SEC) on Monday, Nutex Health said an unauthorized third party had threatened to publish the stolen information. The company initially disclosed the intrusion on August 24 under a catch-all category, but has now reported the incident under the section reserved for material cybersecurity incidents as its investigation continues.
Nutex did not identify the intruders. However, The Gentlemen ransomware-as-a-service (RaaS) operation added the company to its leak site on Monday and claimed responsibility for the attack. The gang offered no evidence or details to substantiate its claim. Naming victims on a leak site and threatening to publish their data is a standard pressure tactic in double-extortion attacks.
A proposed class action was filed against Nutex on August 27 on behalf of people whose personally identifiable information or protected health information was allegedly accessed or acquired during the intrusion. Nutex said it could not predict the litigation's outcome and had not identified any material impact on its operations or financial reporting systems.
The Gentlemen emerged in mid-2025, reportedly after former Qilin affiliates fell out with that gang's leadership and launched a rival RaaS operation. Researchers describe it as a primarily Russian-speaking operation whose victims are generally located outside the Commonwealth of Independent States. In May, Microsoft detailed a self-propagating encryptor used by the gang's affiliates, warning that the malware combines multiple lateral-movement techniques, increasing the likelihood of widespread impact once initial access is achieved.
Nutex's hospital division now operates 28 facilities across 12 states.