← BACK TO FEED
ransomwarehealthcare data breachNutex Healthdouble extortionSEC disclosure

Gentlemen Ransomware Gang Takes Credit for Nutex Health Breach

Nutex Health has confirmed a data breach in which hackers stole patient, employee, financial, and business information, with the company notifying the SEC and facing a class-action lawsuit in Texas. The Gentlemen ransomware group (also known as Storm-2697) has claimed responsibility, threatening to leak the stolen data within nine days if their demands are not met. The group, which operates as a ransomware-as-a-service and has claimed over 580 victims across 75 countries since emerging in mid-2025, employs double extortion tactics by both encrypting and exfiltrating victim data.

Nutex Health, a Houston-based healthcare services company, has filed a second disclosure with the SEC confirming that attackers made off with a fairly broad sweep of sensitive data, including patient records, employee information, provider details, and financial data.

The company initially flagged the breach last week, telling the SEC that hackers had gained unauthorised access to its network and walked away with files. The follow-up filing fills in the uncomfortable details.

The threat actor, whoever they are in Nutex's telling, has already threatened to publish the stolen data publicly. The company says it hasn't identified any material impact on business operations or financial reporting systems so far, which is the kind of carefully lawyered statement you'd expect at this stage.

A purported class-action complaint has already been filed against Nutex in Texas. The company, perhaps wisely, declined to speculate on how that plays out, stating only that it cannot yet estimate the potential impact on operations, finances, or its stock price.

Nutex hasn't publicly named who's behind the attack, but the Gentlemen ransomware group solved that mystery themselves on Monday by adding Nutex to their Tor leak site. They're giving the company nine days before allegedly dumping the stolen data.

The Gentlemen, also tracked as Storm-2697, surfaced in mid-2025 and has wasted little time building a grim portfolio. The group operates as a ransomware-as-a-service outfit, has claimed over 580 victims across more than 75 countries, and runs a classic double extortion playbook: encrypt the data, steal the data, then use both as bargaining chips.

For a ransomware group barely months old, that's a fairly alarming rate of expansion. Healthcare targets remain a favourite precisely because the pressure to restore access quickly is immense and the data involved is deeply sensitive.

The nine-day clock is ticking.

READ NEXT
Boston Scientific Hit by Cyberattack, Global Operations in ChaosRiver Bank Paid Ransomware Crew to Delete Stolen Data. Trust Them on That.Ransomware Knocks Out Fairlife Milk Production Across the US