HackMyIP
← Back to News
2026-09-01 The Record

Gentlemen Ransomware Gang Steals Patient Data in Nutex Healthcare Breach

RansomwareData BreachIncident Response

Houston-based healthcare facilities operator Nutex confirmed in an 8-K filing with the Securities and Exchange Commission on Monday that cybercriminals breached its servers in August and exfiltrated sensitive data belonging to patients, employees, and external providers, along with confidential financial records. The company, which generated $427.2 million in revenue during the first half of 2026 across 27 hospital and outpatient facilities in 12 states, disclosed the initial intrusion to the SEC on August 24 and stated the threat actor is now attempting to extort the organization by threatening to publish the stolen information. Nutex has not yet quantified the volume of compromised records or the financial impact, and the filing did not name the attacker. Users concerned about exposed personal data can verify their exposure using an email breach checker.

The Gentlemen ransomware-as-a-service gang claimed responsibility for the attack on Monday, adding Nutex to its dark web leak site. Active since September 2025, Gentlemen is believed by researchers to be a Russia-based operation that emerged from a disgruntled former affiliate of the Qilin ransomware group, a connection evidenced by its prohibition on attacks against Commonwealth of Independent States (CIS) countries and the use of Russian-language posts on cybercrime forums. The group has conducted at least 350 attacks and differentiates itself by allowing affiliates to carry out data exfiltration-only intrusions, taking just a 3% cut of ransoms from these non-encryption incidents. In the second quarter of 2026, Gentlemen ranked third among ransomware groups targeting industrial organizations, with 125 claimed attacks according to operational technology firm Dragos.

A putative class action lawsuit has already been filed in Texas on behalf of individuals whose personally identifiable information and protected health information may have been compromised, though Nutex stated it is "unable to predict the outcome of the litigation or estimate the potential impact of the incident on the Company's business strategy, operations, financial condition, results of operations or the trading price of the Company's common stock." The breach follows Gentlemen's recent disruption of nonprofit medical system AnMed, where the gang shut down IT operations, hijacked the organization's Facebook page, and forced the closure of dozens of facilities for several days before confirming patient data theft. Two weeks ago, researchers at Gambit Security reported observing a Gentlemen affiliate conducting active network intrusions, underscoring the group's continued operational tempo against healthcare targets. Affected employees and patients are advised to update credentials immediately and test them against known compromises via a password checker.

Source: The Record →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a data breach? →Credential stuffing attacks →How to check for an email breach →