Healthcare facilities operator Nutex says patient, employee data stolen in August incident
Healthcare facilities operator Nutex has been targeted in a cyberattack, resulting in the theft of patient and employee data, as well as confidential financial information. The attack was carried out by the Gentlemen ransomware gang, who have a history of data exfiltration and ransomware attacks, and have recently been linked to the shutdown of AnMed's systems. Nutex is currently being extorted by the attackers, and a class action lawsuit has been filed.
Healthcare facilities operator Nutex has been targeted in a cyberattack, resulting in the theft of patient and employee data, as well as confidential financial information. The attack was carried out by the Gentlemen ransomware gang, who have a history of data exfiltration and ransomware attacks, and have recently been linked to the shutdown of AnMed's systems. Nutex is currently being extorted by the attackers, and a class action lawsuit has been filed.
Nutex initially disclosed the cyberattack to the SEC on August 24, warning investors that it hired cybersecurity experts to help address the attack. Monday’s filing notes that after the initial disclosure, a class action complaint was filed in Texas “on behalf of a putative class of all individuals whose personally identifiable information and/or protected health information was allegedly accessed and/or acquired by an unauthorized party in connection with the incident.”
Nutex earned $427.2 million in the first half of 2026 through its operation of 27 hospital and outpatient facilities in 12 states. It also controls a physician network focused on primary care. The Gentlemen ransomware gang has operated since September 2025 and experts said it was created by a disgruntled former affiliate of the Qilin ransomware operation. The group allows affiliates to conduct both ransomware attacks and data exfiltration-only incidents, offering to only take a 3% cut of all ransoms coming from the latter.
The Gentlemen ransomware gang recently caused alarm after it shut down the IT system of nonprofit medical system AnMed and took over the company’s Facebook. AnMed was forced to shutter dozens of its facilities for a number of days and later confirmed that the hackers stole patient information. In the second quarter of 2026, the group claimed 125 attacks on industrial organizations, the operational technology firm Dragos said — the third most among ransomware groups. Two weeks ago, experts at Gambit Security said they saw an affiliate of the group using Claude Code during intrusions into at least six organizations.
