Security3 distinct publishers2 min readPublished
The Gentlemen gave the Houston hospital operator nine days to pay after an August 31 filing confirmed patient, employee and provider files were taken, and a class action had already landed on August 27.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Extortion without encryption leaves the operations line clean. Nutex says it has identified no material impact on its business operations or financial reporting systems to date [7], which is the signature of a theft-only intrusion: nothing stops, and the loss sits entirely in copies that are already off the network. The contrast inside the same gang's victim list is AnMed, the nonprofit medical system whose IT The Gentlemen shut down and whose Facebook account it took over, forcing dozens of facilities to close for several days before AnMed confirmed patient information was stolen [21]. One operator, two very different outage profiles.
Scale sets the notification problem. Nutex runs 27 hospital and outpatient facilities in 12 states and booked $427.2m in the first half of 2026 [19], and it reportedly served nearly 100,000 patients over that same period [20]. If the files taken from its servers track recent care, the letter population is a six-figure exercise, and it cannot begin until the review names individuals.
On the actor, the public record is two different tallies. The Record reports The Gentlemen operating since September 2025 with at least 350 attacks [15]. SecurityWeek dates emergence to mid-2025 and counts more than 580 victims in over 75 countries [16]. Subtract and the gap is 230 victims for the same ransomware-as-a-service brand [17], which is what happens when leak-site posts stand in for a census. The Record also reports experts assessing the group as a spinoff run by a disgruntled former Qilin affiliate, with Russian operators inferred from its ban on targeting CIS countries and its Russian-language forum posts [18]. That is assessment, not confirmation, and Nutex's filing names no group at all [24].
The defensive read comes from Sophos, which published on September 1 that healthcare accounts for 9% of The Gentlemen's victims, second to manufacturing at 10%, and that affiliates typically gain initial access by exploiting firewall vulnerabilities and abusing VPN services [12][13]. No one has published the entry point at Nutex, so internet-facing security appliances and remote access accounts are the working hypothesis rather than a finding. Gambit Security separately reported seeing a Gentlemen affiliate using Claude Code during intrusions at six or more organizations [23].
For hospital groups the sequence Nutex just ran is the one to plan against: an 8-K on detection, a class action three days later, a leak-site countdown, and patient letters last.
Ranked by verification strength, evidence, and original report placement.
Nutex Health disclosed in an 8-K filing to the SEC on August 31 that it believes information on its servers, including patient, employee, credentialed provider, business and financial information, was accessed and exfiltrated by an unauthorized third party.
Nutex said the third party has threatened to post the stolen information externally.
A class action complaint was filed in Texas on August 27 on behalf of a putative class of all individuals whose personally identifiable information and/or protected health information was allegedly accessed or acquired in connection with the incident.
Nutex said it is unable to predict the outcome of the litigation or estimate the potential impact of the incident on its business strategy, operations, financial condition, results of operations or the trading price of its common stock.
The Gentlemen ransomware group claimed responsibility on Monday, the same day as the filing, adding the Houston-based company to its Tor leak site and threatening to leak allegedly stolen data within nine days.
Nutex first informed the SEC on August 24 that it had detected unauthorized activity involving data stored on its computer network.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 2, 2026
1 article · September 1, 2026
1 article · September 1, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
build
The $559M-versus-$12.3B quarter matters more than the $65B run rate4 distinct publishers
security
CareCloud's breach count grew almost 11x, five months after the first filing1 distinct publisher
security
The Gentlemen affiliates encrypt within a day of logging into a VPN with a stolen password1 distinct publisher
security
CareCloud's Breach Went From 350,000 to 3.7 Million, and the State Filings Still Say 350,0003 distinct publishers
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One filing, three faithful readings
Strip the coverage back and almost everything about the breach itself comes from a single document: Nutex's August 31 8-K. Three outlets quote the same two sentences accurately, which is reliability rather than corroboration — no reporter has seen the stolen files, a record count, or the leak-site post beyond noting the listing exists. The attacker material is firmer where a vendor did the work, with Sophos naming firewall and VPN entry points, and softest where two outlets simply printed different victim totals and neither reconciled them.
Consequences already landed, scope still open
The downstream machinery is visibly moving: a suit on August 27, a plaintiff firm recruiting by September 1, a countdown on a leak site, and a same-group precedent at AnMed where dozens of facilities went dark and patient data was ultimately confirmed stolen. What nobody can yet size is the thing that determines the eventual bill — how many of the roughly 100,000 patients Nutex reportedly treated in the first half of 2026 are in those files.
Sober on the victim, generous to the gang
The reporting on Nutex is if anything drier than the facts warrant — three outlets stay inside the filing's own careful language, and none dresses up the harm. The stretch is on the other side of the story, where an unverified criminal résumé does a lot of narrative work: 'notorious', 580 victims or 350 attacks depending on the outlet, a Russia attribution sourced to unnamed experts. Numbers a ransomware crew publishes about itself are marketing, and here they are printed as scale.
Four interested parties, no disinterested one
Nutex is writing for the SEC and its shareholders, which is exactly why 'no material impact' and 'unable to predict' sit in the same document. The Gentlemen's leak-site post is a pressure tactic, so its nine-day clock and its victim count both serve the extortion. Sophos and Gambit Security are security vendors publishing research about a threat they sell against. Edelson Lechtzin is a plaintiff firm advertising free case evaluations. Every claim in this story arrives from someone with a position, and Nutex has stopped taking questions.
Confident on what was filed, not on what was taken
Dates, quotes and the litigation sequence are solid enough to build on — three independent outlets, no contradictions among them on the Nutex facts. Confidence drops sharply past the filing's edge: the volume of exfiltrated records, whether the leak deadline was met, and the attacker's true scale all remain outside what our coverage can settle.