Article 7835C The Gentlemen come calling as Nutex confirms sensitive data theft

The Gentlemen come calling as Nutex confirms sensitive data theft

by
from www.theregister.com - Articles on (#7835C)
Story ImageUS hospital operator Nutex Health says attackers stole private or confidential patient, employee, provider, business, and financial information during the cyberattack it disclosed last week. In an updated filing submitted to the Securities and Exchange Commission (SEC) on Monday, Nutex also said an unauthorized third party had threatened to publish the stolen information. Nutex initially disclosed the intrusion on August 24 under Item 8.01 of Form 8-K, the catch-all category for "Other Events." Although it already believed some private or confidential information had been exfiltrated, it had not determined whether the stolen material included patient, employee, provider, business, financial, or intellectual property data. The company has now reported the incident under Item 1.05, the section reserved for material cybersecurity incidents, as its investigation continues to determine precisely what was taken and who was affected. Nutex did not identify the intruders. However, The Gentlemen ransomware-as-a-service (RaaS) operation added the company to its leak site on Monday and claimed responsibility for the attack. The gang offered no evidence or details to substantiate its claim. Naming victims on a leak site and threatening to publish their data is a standard pressure tactic in double-extortion attacks. Nutex's hospital division now operates 28 facilities across 12 states. A proposed class action was filed against the company on August 27 on behalf of people whose personally identifiable information or protected health information was allegedly accessed or acquired during the intrusion. Nutex said it could not predict the litigation's outcome and had not identified any material impact on its operations or financial reporting systems. The Gentlemen emerged in mid-2025, reportedly after former Qilin affiliates fell out with that gang's leadership and launched a rival RaaS operation. Researchers describe it as a primarily Russian-speaking operation whose victims are generally located outside the Commonwealth of Independent States. In May, Microsoft detailed a self-propagating encryptor used by the gang's affiliates. The malware combines multiple lateral-movement techniques, Microsoft warned, "increasing the likelihood of widespread impact once initial access is achieved." (R)
External Content
Source RSS or Atom Feed
Feed Location http://www.theregister.co.uk/headlines.atom
Feed Title www.theregister.com - Articles
Feed Link https://www.theregister.com/
Reply 0 comments