What Happened
Hospital operator Nutex Health (NASDAQ: NUTX) has been publicly claimed as a victim by the The Gentlemen ransomware-as-a-service gang, which is threatening to leak stolen patient, employee, provider, business, and financial data on its Tor leak site within nine days of the claim.
Houston-based Nutex Health operates 28 facilities across 12 states — including micro-hospitals, specialty hospitals, and outpatient departments such as Bayou City ER & Hospital in Texas and Green Bay ER & Hospital in Wisconsin. The company reported $875 million in 2025 revenue and carries a market capitalization of roughly $1.28 billion.
Timeline
Nutex Health first disclosed the incident in a Form 8-K filed with the SEC on August 24, 2026, stating that it had identified unauthorized activity on its network and engaged independent cybersecurity and forensic experts. At that point, no threat actor had publicly claimed responsibility — neither BleepingComputer nor SecurityWeek could find any group taking credit.
That changed the following week when The Gentlemen surfaced with a claim against Nutex Health, giving the company a nine-day window before threatening to publish the stolen data.
What Was Taken
Nutex Health's SEC filing states the company believes an unauthorized third party accessed and exfiltrated information from its servers, "including some information that may be private and/or confidential." The company says it is still working to determine whether the exposure includes:
- Patient information
- Employee records
- Credentialed provider data
- Confidential business and financial information
- Intellectual property
The filing quotes the company directly: "The third party has threatened to post such information externally. To date, the company has not identified any material impact on its business operations or financial reporting systems."
Who Is The Gentlemen
The Gentlemen is a ransomware-as-a-service operation that emerged in mid-2025 and has since claimed more than 580 victims across 75+ countries, using standard double-extortion tactics — encrypting systems and threatening to leak stolen data for additional leverage. The group has not disclosed a ransom amount or confirmed whether Nutex Health's systems were also encrypted, or whether the intrusion was data-theft-only.
Regulatory Context
Nutex Health's August 24 filing reflects the SEC's Item 1.05 requirement, which gives public companies a four-business-day clock to disclose a cybersecurity incident once it is judged material. As of the filing, Nutex says it does not believe the incident will materially affect its business strategy, operations, or financial condition — though it acknowledges it cannot yet predict litigation outcomes. Data-breach law firms have already begun soliciting affected individuals for potential class-action claims.
Why This Matters
Healthcare operators remain one of the most consistently targeted sectors for ransomware groups, both for the sensitivity of patient data and for the operational pressure hospitals face to restore systems quickly. A nine-day extortion deadline against a company still in the early stages of its own forensic investigation puts Nutex Health in a difficult position: it must assess breach scope, notify regulators and potentially patients, and decide how to respond to an active extortion threat — all at once. Organizations in similar positions should treat "no group has claimed it yet" as a temporary state, not a resolution.
Sources
- SecurityWeek — Ransomware Gang Claims Nutex Health Data Breach
- SecurityWeek — Sensitive Information Exposed in Nutex Health Data Breach
- BleepingComputer — Hospital operator Nutex Health says data stolen in cyberattack