Houston-based healthcare facilities operator Nutex Health disclosed that unauthorized actors accessed its network and exfiltrated files containing patient, employee, provider, business, and confidential financial information. The company said it is investigating the incident, including the affected data volume and operational impact, and reported no identified material impact to business operations or financial-reporting systems.
Attackers are extorting Nutex and have threatened to publish the stolen data. The Gentlemen ransomware-as-a-service group, also tracked as Storm-2697, claimed responsibility by listing Nutex on its leak site, though Nutex has not independently confirmed the attribution. A proposed Texas class-action lawsuit alleges that personally identifiable information and protected health information were compromised.

See the actors and campaigns active against you right now.
5 events from the most recent confirmed update back to the earliest known activity.
The Gentlemen, also tracked as Storm-2697, added Nutex Health to its Tor-based leak site and claimed responsibility for the breach. The group threatened to release allegedly stolen Nutex data within nine days; Nutex did not independently identify the group as responsible.
In an August 31 SEC filing, Nutex Health confirmed that an unauthorized party exfiltrated private or confidential patient, employee, provider, business, and financial information. The company said it would notify affected patients, monitor for online leaks, and had not identified a material effect on operations or financial-reporting systems.
Nutex Health initially disclosed to the SEC that cybercriminals breached its servers and stole data. The company said it had engaged cybersecurity experts and was investigating the scope and business impact, with no material impact on operations or financial-reporting systems identified at that time.
A proposed class-action complaint was filed in Texas on behalf of people whose personally identifiable information or protected health information was allegedly compromised in the incident. Nutex said it could not predict the litigation's outcome or financial and operational effects.
Unauthorized actors accessed Nutex Health's network and exfiltrated files containing patient, employee, provider, business, and financial information. The attackers threatened to publish the stolen data externally.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
6 references tracked. Mallory keeps watching after this page renders.
teiss.co.uk
Open sourcesecuritymagazine.com
Open sourceinfosecurity-magazine.com
Open sourcetherecord.media
Open sourcesecurityweek.com
Open sourcecyberveille.ch
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.