Healthcare facilities operator Nutex says patient, employee data stolen in August incident | #cybercrime | #infosec


Hackers stole patient and employee data from healthcare giant Nutex during a cyberattack announced last week, the company said in regulatory filings on Monday. 

In an 8-K filing with the Securities and Exchange Commission (SEC), Nutex said it is being extorted by cybercriminals who broke into the company’s servers and exfiltrated information related to patients, employees and external providers as well as confidential financial data. 

 “The third party has threatened to post such information externally,” Nutex said, adding that it is still investigating how much data was taken and what impact it will have on the company. 

Nutex earned $427.2 million in the first half of 2026 through its operation of 27 hospital and outpatient facilities in 12 states. It also controls a physician network focused on primary care. 

The Houston-based company initially disclosed a cyberattack to the SEC on August 24, warning investors that it hired cybersecurity experts to help address the attack. Monday’s filing notes that after the initial disclosure, a class action complaint was filed in Texas “on behalf of a putative class of all individuals whose personally identifiable information and/or protected health information was allegedly accessed and/or acquired by an unauthorized party in connection with the incident.”

Nutex said that it is  “unable to predict the outcome of the litigation or estimate the potential impact of the incident on the Company’s business strategy, operations, financial condition, results of operations or the trading price of the Company’s common stock.”

The 8-K filing did not specify the cybercrime group. Nutex did not respond to requests for comment.

The Gentlemen ransomware gang took credit for the attack on Monday, adding Nutex to its leak site. The ransomware-as–service group has operated since September 2025 and experts said it was created by a disgruntled former affiliate of the Qilin ransomware operation. 

The gang has launched at least 350 attacks since emerging and experts believe the group is based in Russia because it prohibits members from attacking Commonwealth of Independent States (CIS) countries and its posts on cybercriminal forums are written in Russian.

The group allows affiliates to conduct both ransomware attacks and data exfiltration-only incidents, offering to only take a 3% cut of all ransoms coming from the latter.

The group recently caused alarm after it shut down the IT system of nonprofit medical system AnMed and took over the company’s Facebook. AnMed was forced to shutter dozens of its facilities for a number of days and later confirmed that the hackers stole patient information.

In the second quarter of 2026, the group claimed 125 attacks on industrial organizations, the operational technology firm Dragos said — the third most among ransomware groups. Two weeks ago, experts at Gambit Security said they saw an affiliate of the group using Claude Code during intrusions into at least six organizations.



Click Here For The Original Source.

——————————————————–

..........

.

.