HackerFeeds
All ransomware incidents
nutexhealth.com

Ransomware group thegentlemen hits Nutex Health

MEDIUM
·Healthcare·US·2026-08-31

Nutex Health — a healthcare target operating in US has been listed by the thegentlemen ransomware group on 2026-08-31. The information below reflects what the threat actor has publicly claimed on their leak site; the details have not been independently verified.

Incident Report

Target OrganizationNutex Health
Threat Group
thegentlemen
Summarynutexhealth.com zoominfo.com/c/nutex-health-inc/372032478 (NUTX, Nasdaq) — US healthcare company, based in Houston, Texas, founded in 2011 by Dr. Thomas Vo. It runs 27 small "micro-hospitals" in 12 states — small hospitals with full 24/7 emergency rooms. Model: fast, cheaper ER care between urgent care and giant hospitals; most revenue comes from Texas. Q2 2026: net income $65.8M (vs loss a year ago), EBITDA $90M, cash $205M, debt only $31M. Profit exploded because it wins 85%+ of insurance arbitrations (IDR) and got paid at higher out-of-network rates. Plans: 7 new hospitals by 2027 plus two share buyback programs. Main risk: the whole profit engine depends on the arbitration system — new regulation could cut it. Cheap-looking: P/E around 6, but volatile small-cap with thin analyst coverage.
Date of Breach2026-08-31
Discovery Date2026-09-01
RegionUS
Target Domainnutexhealth.com
Business SectorHealthcare
Severity
MEDIUM

Claim by thegentlemen

nutexhealth.com zoominfo.com/c/nutex-health-inc/372032478 (NUTX, Nasdaq) — US healthcare company, based in Houston, Texas, founded in 2011 by Dr. Thomas Vo. It runs 27 small "micro-hospitals" in 12 states — small hospitals with full 24/7 emergency rooms. Model: fast, cheaper ER care between urgent care and giant hospitals; most revenue comes from Texas. Q2 2026: net income $65.8M (vs loss a year ago), EBITDA $90M, cash $205M, debt only $31M. Profit exploded because it wins 85%+ of insurance arbitrations (IDR) and got paid at higher out-of-network rates. Plans: 7 new hospitals by 2027 plus two share buyback programs. Main risk: the whole profit engine depends on the arbitration system — new regulation could cut it. Cheap-looking: P/E around 6, but volatile small-cap with thin analyst coverage.

Posted by the thegentlemen threat actor on its public leak site. This is the group's own statement and has not been independently verified by HackerFeeds.

Disclaimer

HackerFeeds does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.