The Shortage of Cybersecurity Professionals is Leaving Healthcare Organizations at Risk
In this on-demand webinar, a panel of cybersecurity experts who will offer perspective and best practices for understanding and addressing this...
3 min read
Gugu Ntsele Sep 2, 2026, 2:13:23 PM
The Gentlemen ransomware group has claimed responsibility for a data breach at Nutex Health, adding the healthcare company to its dark web leak site and threatening to publish stolen patient, employee, provider, business, and financial information.
Nutex Health, a healthcare services and operations company, discovered unauthorized access to its network and confirmed that attackers stole files from its servers. In a new filing with the SEC, the company confirmed the stolen data includes patient, employee, provider, business, and financial information. Nutex has not identified any material impact on its business operations or financial reporting systems so far and is still investigating the extent of the breach. A purported class-action complaint has already been filed against Nutex in Texas. While Nutex has not named the attacker, the Gentlemen ransomware group claimed responsibility this week and added the Houston-based company to its Tor leak site, threatening to leak the stolen data within nine days.
Nutex first notified the SEC in late August that it had identified unauthorized network access and stolen files. This new SEC filing builds on that earlier disclosure, confirming exactly which categories of data were exposed.
Nutex told the SEC, "The third party has threatened to post such information externally. To date, the company has not identified any material impact on its business operations or financial reporting systems." Nutex also said, "At this stage, the company is unable to predict the outcome of the litigation or estimate the potential impact of the incident on the company's business strategy, operations, financial condition, results of operations or the trading price of the company's common stock."
Safeware, a US-based technology company that provides insurance and protection services for electronics and personal tech products, was listed as a Gentlemen victim on August 13, 2026, according to SOCRadar's Dark Web Monitoring service. In the 60 days before that listing, the group had already claimed 193 other victims, with a targeting pattern concentrated in manufacturing, technology, and general business sectors, and victims located mainly in the United States, Germany, and France. Other recent US technology or consumer-services victims with a similar profile to Safeware include Phase Technologies, aZaaS, Control Concepts Technology, and Promatrix.
In late August 2026, the Gentlemen listed employment review site Glassdoor on its leak site, giving the company a 172-hour countdown before threatening to publish allegedly stolen data. No data samples had been released publicly, so the type of information involved remained unverified, and it was unclear whether the claimed haul included Glassdoor's internal corporate data, employee information, job seeker information, or some mix of the three.
Earlier in 2026, the Gentlemen's own internal communications were leaked online after the group itself suffered a breach, exposing more than 8,200 lines of internal chat logs, infrastructure details, and bitcoin wallet addresses. That leak revealed the group's reconnaissance-heavy approach, its use of compromised Fortinet edge-networking credentials as a common entry point, and its focus on disabling backups, NAS devices, and endpoint security tools before deploying ransomware.
Ransomware-as-a-service lets affiliates rent ransomware tools from a developer group in exchange for a cut of any extortion payments. The Gentlemen's 90% affiliate revenue share is generous compared to the industry norm, which helps explain how it recruited enough affiliates to get hundreds of victims in about a year. Double extortion adds a second layer of pressure, even if a victim restores its systems from backups, the attacker still holds stolen data and can threaten to publish it, as the group is doing to Nutex now.
Nutex is not an isolated target, it is the latest name added to a leak site that has grown into one of the most prolific in the ransomware field, sitting just behind Qilin in claimed victims. That scale matters for Nutex specifically because it shows a well-resourced, high-volume operation with a track record of following through on leak threats across many sectors. The breach also exposes a mix of patient, employee, provider, business, and financial data at once, widening who is at risk, patients, staff, and business partners, rather than just one group. Nutex is already facing a class-action lawsuit in Texas before it has even finished investigating the breach's scope, showing how quickly legal exposure can follow a healthcare data incident once a group like the Gentlemen goes public with a claim.
Public companies must generally report material cybersecurity incidents within four business days of determining the incident is material to investors.
Leak sites are used as a public pressure tactic to push victims toward paying before stolen data is released.
Yes, organizations can be targeted repeatedly, especially if underlying vulnerabilities or compromised credentials aren't fully remediated after the first incident.
In this on-demand webinar, a panel of cybersecurity experts who will offer perspective and best practices for understanding and addressing this...
Episode 62 of HIPAA Critical features an interview with Hector Rodriguez, Principal Industry Specialist, Healthcare & Life Sciences - AWS.
Episode 65 of HIPAA Critical features an interview with Aja Anderson on this month’s Paubox HIPAA Breach Report.
Every Friday we bring you the most important news from Paubox. Our aim is to make you smarter, faster.