Healthcare services and operations company Nutex Health has confirmed that personal and business information was stolen in a recently disclosed data breach.
Last week, the company notified the US Securities and Exchange Commission (SEC) that it identified unauthorized access to its network and that hackers had stolen certain files from its servers.
In a new filing with the SEC, the company has confirmed that the exfiltrated data includes patient, employee, provider, business, and financial information.
“The third party has threatened to post such information externally. To date, the company has not identified any material impact on its business operations or financial reporting systems,” Nutex said.
The company continues to investigate the scope, extent, and impact of the data breach and has notified the SEC that a purported class-action complaint was filed against it in Texas.
“At this stage, the company is unable to predict the outcome of the litigation or estimate the potential impact of the incident on the company’s business strategy, operations, financial condition, results of operations or the trading price of the company’s common stock,” Nutex said.
While Nutex has not named the threat actor behind the data breach, the Gentlemen ransomware group claimed responsibility on Monday.
The gang has added the Houston, Texas-based company to its Tor leak site, threatening to leak data allegedly stolen from it within nine days.
Operating as a ransomware-as-a-service (RaaS), The Gentlemen (also known as Storm-2697) emerged in mid-2025 and has made over 580 victims in more than 75 countries. The group engages in double extortion, both encrypting the victims’ data and exfiltrating it to use as leverage for extortion.
Related: 9.5 Million Impacted by Aesto Health Data Breach
Related: Extortion Group Claims Manchester Airports Group Data Breach
Related: ATF Confirms Cyber Incident After Ransomware Group Claims Attack
Related: Ransomware Attack Shuts Down Mills of Australia’s Second-Largest Sugar Producer
