Quick Summary
AllegedExecutive Summary
TheGentlemen listed Nutex Health on its dark web portal on September 1, 2026. SOCRadar Dark Web Monitoring flagged this listing. Nutex Health is a physician-owned US health system that operates micro-hospitals and emergency facilities across multiple states. The targeting of an emergency care operator by ransomware carries significant patient safety implications beyond the typical data and continuity risks associated with such attacks. In the preceding 60 days, TheGentlemen has claimed 253 other victims, indicating a very high output rate compared to other active ransomware groups. The group’s primary targets are Manufacturing, Technology, and Other industries, with healthcare consistently being a secondary vertical. Geographically, their attacks are concentrated in the United States, United Kingdom, and Germany. Recent US healthcare victims claimed by TheGentlemen include Eyecare Center of Snohomish, First Coast Heart Vascular Center, AnMed, and Hoang Chiropractic Center. Nutex Health’s inclusion aligns with the group’s pattern of targeting the healthcare sector.
Technical Analysis
A query for stealer-log records associated with the domain nutexhealth[.]com returned no results within the investigated dataset. It is important to note that a lack of findings in this specific query does not confirm that the organization is unaffected by compromise. This “no-signal” result means that credentials may still exist under alternate corporate domains, be associated with personal email aliases, or reside in data feeds not included in this particular analysis. Furthermore, credentials may have been accessed and subsequently rotated before being indexed, or the data may not yet be indexed. The potential for credential exposure in healthcare environments is significant due to the common use of VPNs and remote-access portals, which are frequent targets for initial access by threat actors. While this query did not find direct evidence of compromised credentials for Nutex Health through stealer logs, the possibility of such exposure through other pathways remains. This scenario could potentially support ransomware operations if threat actors gain access to corporate accounts or internal systems. Rotate VPN, RDP, and remote-access credentials as a precautionary measure and maintain continuous monitoring of the nutexhealth[.]com domain for any emerging threats or indicators of compromise.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.