Nutex Health, a Houston, Texas-based healthcare operator that runs 27 micro-hospitals, specialty hospitals and outpatient departments across twelve states, first disclosed unauthorised activity on its computer network to the US Securities and Exchange Commission on 24 August 2026. At that point the company said it did not believe the incident would have a material impact on its operations. A week later, on 31 August, it filed a second disclosure. The assessment had changed: an unauthorised third party had accessed and exfiltrated patient, employee, credentialed provider, business and financial information, and the attacker was threatening to publish it externally.
The group that claimed the intrusion, calling itself The Gentlemen, has been operating since September 2025 and is assessed by researchers to have been founded by a disgruntled former affiliate of the Qilin ransomware operation. It has launched more than 350 attacks since it emerged, offering affiliates a choice between full ransomware deployment or data-theft-only extortion, for which it takes a smaller cut of the proceeds. Nutex has not disclosed how the attacker first reached its network. No phishing email, no compromised vendor, no exploited appliance has been named. What is confirmed is the outcome: files containing patient records, employee data, provider credentials and financial information left the company's servers and reached an attacker who is now using their release as leverage.
This is not an isolated incident for the group. Two weeks earlier, The Gentlemen shut down the IT systems of the nonprofit health system AnMed, hijacking the organisation's Facebook page in the process and forcing the temporary closure of 83 facilities. Researchers at Dragos ranked the group third by volume of claimed attacks on industrial organisations in the second quarter of 2026, with 125 incidents. Nutex, which earned $427.2 million in revenue in the first half of the year, became the latest healthcare operator added to the group's leak site on 1 September, days after its own disclosure to regulators.
Within days of the SEC filing, a class action complaint was filed in Texas on behalf of everyone whose personal or health information was allegedly accessed in the breach. Nutex says it cannot yet estimate the financial impact or predict the outcome of the litigation. Healthcare has become one of The Gentlemen's most reliable targets, and the sector as a whole has spent 2026 absorbing a steady drumbeat of exfiltration-driven extortion, from regional hospital systems to national record platforms. Each case follows the same arc: data leaves before anyone outside the security team knows it is happening, and the company finds out it has been breached only when the extortion demand arrives.
Nutex says it activated its incident response plan and brought in forensic investigators the moment it detected the intrusion. Those are the right reactive steps, and the company deserves credit for disclosing quickly and escalating to a material incident filing within a week of the first one. Detection and forensics, however, operate after the theft. By the time Nutex's team was assessing what had been taken, the data had already left. The defences that failed here were not weak by conventional standards, they were aimed at the wrong moment. Everything Nutex had was built to work out what happened. Nothing was built to stop it from happening.
A bulk export of patient records, employee files and financial data is not routine network traffic. It is an execution event, a high-impact action that should never complete without a named human authority confirming it in real time. Under GoFirm, that export triggers a real-time push notification to the designated security authority's registered device, requiring biometric confirmation before the transfer is permitted to proceed. No confirmation, no export.
This does not depend on knowing how the attacker got in. Whether access came through a phishing email, a compromised vendor credential, an exposed remote-access tool or something Nutex has not yet identified, the control point is the same: the moment data starts moving out of the environment in volume. An attacker holding a valid session, a stolen password or even a live remote connection cannot produce a biometric confirmation on the named authority's own registered device through a separate channel. The execution boundary holds regardless of how the access was obtained.
GoFirm is The Authority Platform. Stop unauthorised action. Every time.
In association with Osinto.ai, the collective intelligence and governance network for Security, Resilience & Defence teams.
References
1. Alder, S. 2026. Nutex Health Confirms Sensitive Data Stolen in August Cyberattack. The HIPAA Journal, 2 September 2026.
2. Greig, J. 2026. Healthcare facilities operator Nutex says patient, employee data stolen in August incident. The Record from Recorded Future News, 1 September 2026.
Back to Blog
Case Studies·4 min read
The Gentlemen took patient records from 27 hospitals. Nutex Health still doesn't know how they got in.
By GoFirm
