Nutex Health has confirmed a significant data breach involving patient, employee, and financial records. The 'Gentlemen' ransomware group is now threatening to leak the stolen data publicly.

  • Nutex Health confirmed unauthorized access to its corporate network.
  • Stolen data includes patient, employee, provider, and financial information.
  • 'The Gentlemen' (Storm-2697) ransomware group claimed responsibility.
  • A class-action lawsuit has been filed against the company in Texas.

Healthcare services firm Nutex Health has officially confirmed that a sophisticated cyberattack resulted in the exfiltration of sensitive personal and business data. The company disclosed the incident to the US Securities and Exchange Commission (SEC), admitting that hackers successfully bypassed network security to steal critical files from its servers.

According to the latest SEC filings, the compromised data is extensive, encompassing patient health records, employee personal details, provider information, and corporate financial data. The threat actors have explicitly threatened to publish this information externally if their demands are not met.

Why This Matters

BozokMedia analysis shows that the healthcare sector is currently the highest-value target for RaaS (Ransomware-as-a-Service) operators due to the critical nature of the data and the urgency of service restoration. The Nutex Health incident underscores a growing trend where hackers move beyond simple encryption to 'double extortion,' leveraging the threat of public disclosure to force payment.

"The shift toward double extortion in healthcare means that backups are no longer enough; data exfiltration prevention is the new frontline of defense."

The attack has been claimed by The Gentlemen (also known as Storm-2697), a notorious ransomware-as-a-service group that emerged in mid-2025. The group has added Nutex Health to its Tor-based leak site, setting a strict nine-day deadline before the stolen data is released to the public.

The Gentlemen group is known for its aggressive global reach, having targeted over 580 victims across more than 75 countries. Their operational model focuses on stealing data first and encrypting it second, ensuring they have maximum leverage over the victim.

Beyond the technical breach, Nutex Health is facing immediate legal repercussions. A purported class-action complaint has been filed in Texas, leaving the company in a precarious position regarding its financial stability and stock price. The company stated it is currently unable to predict the final outcome of this litigation.

Did You Know?: RaaS (Ransomware-as-a-Service) allows low-skill criminals to launch high-end attacks by 'renting' ransomware software from professional developers in exchange for a cut of the profit.

Frequently Asked Questions

1. What specific data was stolen from Nutex Health?
The breach included patient, employee, provider, business, and financial information.

2. Who is the 'Gentlemen' ransomware group?
They are a RaaS operator (Storm-2697) specializing in double extortion across 75+ countries.