[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fbaqDa8pA0qT0EOgnIV-O7tMsErGNclF-TrtBPNl4u2M":3},{"article":4,"iocs":47},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":24,"category":25,"article_tags":29},"78d6b448-0a8e-4b23-962b-55f5aca27ed2","Ransomware Gang Claims Nutex Health Data Breach","ransomware-gang-claims-nutex-health-data-breach-3297a1","The company has notified the SEC that hackers accessed patient, employee, provider, business, and financial information. The post Ransomware Gang Claims Nutex Health Data Breach appeared first on SecurityWeek.","Nutex Health has confirmed a data breach after hackers accessed and exfiltrated patient, employee, provider, business, and financial information. The Gentlemen ransomware group has claimed responsibility and threatened to leak the data. The company has notified the SEC and is investigating the scope and impact of the incident, which has also led to a class-action lawsuit.","Ransomware gang claims Nutex Health data breach, threatening to leak patient and financial information.","Healthcare services and operations company Nutex Health has confirmed that personal and business information was stolen in a recently disclosed data breach. Last week, the company notified the US Securities and Exchange Commission (SEC) that it identified unauthorized access to its network and that hackers had stolen certain files from its servers. In a new filing with the SEC, the company has confirmed that the exfiltrated data includes patient, employee, provider, business, and financial information. “The third party has threatened to post such information externally. To date, the company has not identified any material impact on its business operations or financial reporting systems,” Nutex said. The company continues to investigate the scope, extent, and impact of the data breach and has notified the SEC that a purported class-action complaint was filed against it in Texas. “At this stage, the company is unable to predict the outcome of the litigation or estimate the potential impact of the incident on the company’s business strategy, operations, financial condition, results of operations or the trading price of the company’s common stock,” Nutex said.Advertisement. Scroll to continue reading. While Nutex has not named the threat actor behind the data breach, the Gentlemen ransomware group claimed responsibility on Monday. The gang has added the Houston, Texas-based company to its Tor leak site, threatening to leak data allegedly stolen from it within nine days. Operating as a ransomware-as-a-service (RaaS), The Gentlemen (also known as Storm-2697) emerged in mid-2025 and has made over 580 victims in more than 75 countries. The group engages in double extortion, both encrypting the victims’ data and exfiltrating it to use as leverage for extortion. Related: 9.5 Million Impacted by Aesto Health Data Breach Related: Extortion Group Claims Manchester Airports Group Data Breach Related: ATF Confirms Cyber Incident After Ransomware Group Claims Attack Related: Ransomware Attack Shuts Down Mills of Australia’s Second-Largest Sugar Producer Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Critical Ruby on Rails Vulnerability in Attackers’ CrosshairsExtortion Group Claims Manchester Airports Group Data BreachBerlin Won’t Pay Extortion Group Claiming Data TheftCritical Isolated-vm Vulnerability Leads to RCE on HostRust Supply Chain Attack Linked to North Korean HackersMicrosoft Patches Exploited Entra ID VulnerabilityCISA Urges Immediate Patching of Exploited TrueConf VulnerabilitiesThreat Actor Hacks 14,000 IP Cameras in Ukraine and Russia Latest News Five Venezuelans Plead Guilty in US Court to ATM JackpottingCritical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild9.5 Million Impacted by Aesto Health Data BreachWatchGuard Patches Critical VulnerabilitiesPaperCut Exploitation Escalates to Active IntrusionsNightmare Eclipse Drops ‘HardBreacher’ Kaspersky Product ExploitServiceNow Patches 3 Critical Code Injection VulnerabilitiesMcKesson Confirms Data Breach as Attacker Deadline Looms Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the MoveSocial engineering protection company Doppel has promoted Alyssa Smrekar to Chief Marketing Officer.Naveen Bhateja has been appointed Chief People Officer at HackerOne.The Department of War has appointed Sonu Shankar as Principal Deputy Chief Information Officer.More People On The MoveExpert Insights What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, \"data\" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Hired for One Job, Judged on Another: The CISO’s Real Problem The skills that get a CISO hired are rarely the skills they are judged on later. Most security leaders are stuck in that gap. Closing it is the real job. (Sravish Sridhar) Flipboard Reddit Whatsapp Whatsapp Email","https:\u002F\u002Fwww.securityweek.com\u002Fransomware-gang-claims-nutex-health-data-breach\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2026\u002F07\u002Fdata-tracking-report.jpeg","2026-09-01T10:47:47+00:00","2026-09-01T12:00:26.792549+00:00",8,[18,21],{"name":19,"type":20},"Nutex Health","product",{"name":22,"type":23},"The Gentlemen","threat_actor","7d8b5ab8-ea0b-4ced-ae97-ec251b86993a",{"id":24,"icon":26,"name":27,"slug":28},null,"Ransomware","ransomware",[30,35,40,42],{"category":31},{"id":32,"icon":26,"name":33,"slug":34},"2e06f76c-d5b9-4f54-9eef-4d3447b10730","Breaches","breaches",{"category":36},{"id":37,"icon":26,"name":38,"slug":39},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":41},{"id":24,"icon":26,"name":27,"slug":28},{"category":43},{"id":44,"icon":26,"name":45,"slug":46},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[48,52,55],{"type":49,"value":50,"context":51},"domain","gentlemen.onion","The Gentlemen ransomware group added Nutex Health to their Tor leak site.",{"type":53,"value":22,"context":54},"malware","Ransomware group claiming responsibility for the Nutex Health data breach.",{"type":53,"value":56,"context":57},"Storm-2697","Alias for the Gentlemen ransomware group."]