Home › Intelligence › Brief
BREACH BRIEF 🟠 High Ransomware

Ransomware Gang “Gentlemen” Exfiltrates Patient and Employee Data from Nutex Healthcare Operator

Nutex disclosed that the Gentlemen ransomware group breached its servers, stole PHI, employee data and financial records, and is extorting the company. The incident underscores the need for continuous incident‑response monitoring and defensible audit evidence for compliance and litigation readiness.

Verisq™ Intelligence · 📅 September 01, 2026 · 📰 therecord.media
🟠
Severity
High
RW
Type
Ransomware
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
3 recommended
📰
Source
therecord.media

Ransomware Gang “Gentlemen” Exfiltrates Patient and Employee Data from Nutex Healthcare Operator

What Happened — Nutex, a multi‑state operator of hospitals and outpatient facilities, disclosed that the “Gentlemen” ransomware‑as‑a‑service group breached its servers, stole protected health information (PHI), employee data and confidential financial records, and is now extorting the company.

Why It Matters for Trust & Control Assurance

  • Demonstrates the need for a continuously monitored incident‑response program that can detect, contain, and document a breach in real time.
  • Highlights the importance of maintaining defensible audit evidence (forensic logs, chain‑of‑custody records) to satisfy regulators and potential litigants.
  • Aligns with Verisq’s Control Mapping capability, which helps organizations map incident‑response controls to the Verisq Common Framework and produce ready‑to‑use evidence for audits.

Who Is Affected – Large‑scale healthcare providers, physician networks, and any organization that stores PHI or employee personally identifiable information.

Recommended Actions

  • Activate and test your incident‑response playbook; ensure forensic logging was enabled on all critical systems.
  • Collect and preserve evidence (system logs, network traffic, file hashes) for audit and potential litigation.
  • Map the breach to the relevant control objective (incident response, logging, and evidence preservation) in your continuous‑control assurance platform.

Source: The Record

Technical Notes – The attackers accessed Nutex’s internal servers (method not disclosed), exfiltrated PHI, employee PII, and financial data, and posted a ransom note on their leak site. The “Gentlemen” gang operates as a ransomware‑as‑a‑service outfit, taking a 3 % cut of affiliate ransoms. Source: The Record

📰 Original Source
https://therecord.media/nutex-health-data-breach ↗

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →