Infosecurity
Nutex confirms patient and employee data stolen in August cyberattack
Published
45 minutes agoon

Nutex confirms data theft in SEC filing
Houston-based healthcare operator Nutex has confirmed that hackers made off with patient and employee data during a cyberattack disclosed last week. In an 8-K filing with the Securities and Exchange Commission (SEC) on Monday, the company said it is being extorted by cybercriminals who broke into its servers and exfiltrated sensitive information.
The stolen data includes patient records, employee details, information from external providers, and confidential financial documents. Nutex said the attackers have threatened to post the information publicly if their demands are not met.
“The third party has threatened to post such information externally,” the company stated, adding that it is still investigating the full scope of the breach and its potential impact.
What we know about the Nutex cyberattack
Nutex initially disclosed the attack to the SEC on August 24, saying it had hired cybersecurity experts to respond. The company operates 27 hospital and outpatient facilities across 12 states and a physician network focused on primary care. It generated $427.2 million in revenue in the first half of 2026.
Monday’s filing also revealed that a class action lawsuit has been filed in Texas. The complaint was brought on behalf of individuals whose personally identifiable information or protected health information may have been accessed during the incident.
Nutex said it is “unable to predict the outcome of the litigation or estimate the potential impact of the incident on the Company’s business strategy, operations, financial condition, results of operations or the trading price of the Company’s common stock.”
The Gentlemen ransomware gang takes credit
The 8-K filing did not name a specific cybercrime group, but on Monday The Gentlemen ransomware gang added Nutex to its leak site, claiming responsibility for the attack.
The ransomware-as-a-service operation has been active since September 2025. Experts believe it was created by a disgruntled former affiliate of the Qilin ransomware group. The gang has launched at least 350 attacks since emerging and is thought to be based in Russia, as it prohibits attacks on Commonwealth of Independent States (CIS) countries and its forum posts are written in Russian.
The Gentlemen allows affiliates to conduct both ransomware attacks and data exfiltration-only incidents, taking just a 3% cut of ransoms from the latter. The group recently made headlines for shutting down the IT system of nonprofit medical system AnMed and taking over its Facebook page, forcing dozens of facilities to close for days.
Rising threat to healthcare
In the second quarter of 2026, The Gentlemen claimed 125 attacks on industrial organizations, according to the operational technology firm Dragos — the third most among ransomware groups. Two weeks ago, experts at Gambit Security reported seeing an affiliate using Claude Code during intrusions into at least six organizations.
Healthcare remains a prime target for ransomware gangs because of the sensitive nature of patient data and the operational chaos caused by system shutdowns. For hospitals, a breach can mean cancelled procedures, delayed care, and long-term reputational damage.
Nutex has not responded to requests for comment. The company said it is working with cybersecurity experts and law enforcement to address the incident.
For more on how ransomware groups operate, see our coverage of ransomware attack trends and healthcare cybersecurity best practices.
You may like
Infosecurity
Cyber Insurance Payouts Skyrocket Even as Claims Plummet — Here’s Why
Published
7 hours agoon
September 2, 2026
Cyber Insurance Losses Surge Despite Fewer Claims in 2025
The cost of cyber insurance losses is climbing at a startling pace — even as the number of claims filed actually falls. That’s the headline from Chubb’s 2026 Cyber Claims Report, which paints a picture of a market where severity, not frequency, is the real problem.
For large US companies, the average cost per claim doubled in 2025 compared to the prior year. Middle-market firms saw a 22% jump. And the story repeats across the Atlantic, where large UK and European businesses faced a 98% increase in average claim severity.
The driving force? It’s not more attacks. It’s the aftermath — specifically, the soaring expense of data breach litigation, privacy-related lawsuits, and business interruption costs.
Why Average Claim Costs Are Exploding
Chubb’s report, released on August 25, points to a perfect storm of legal and regulatory pressure. In the US, third-party litigation expenses are a major factor. Companies hit by a breach increasingly face class-action lawsuits, and the administrative costs alone can be staggering.
Consider this example from the report: in a suit involving 10,000 claimants, non-refundable filing fees can exceed $10 million — before the case is even heard. That’s a massive chunk of any cyber insurance payout, regardless of whether the claim has merit.
Privacy Laws Add New Burdens
A growing web of privacy legislation in the US and EU is also stacking obligations on businesses that store or transfer personal data. These include the right to opt out of profiling, disclosure requirements for AI-driven processing, and other compliance hurdles that didn’t exist a few years ago.
The result: even a relatively contained data incident can trigger a cascade of legal exposure.
Ransomware Tactics Are Making Things Worse
Ransomware actors have changed their playbook. Instead of just encrypting data, they now leak it. That doubles the damage — victims face not only operational disruption but also litigation risk under data protection laws for exposing personal information.
This shift is a key reason why cyber insurance losses are rising even as the frequency of claims drops. One successful attack now carries a much heavier price tag.
US vs. UK and Europe: A Tale of Two Markets
There’s a stark difference in claim costs between regions. In 2025, the average claim in the US was far more expensive than in the UK and Europe. Chubb attributes this to the absence of material third-party litigation expenses in the latter region — both for data breach and non-data breach privacy claims.
European companies simply don’t face the same class-action culture. That keeps average payouts lower, even as severity trends upward.
SMEs: A Different Pattern Entirely
Small and medium-sized enterprises tell a different story. For SMEs, the frequency of claims actually went up in both regions during 2025.
- US SMEs: Average claim cost fell from $215,297 to $141,931
- UK and European SMEs: Average claim cost rose from $51,095 to $82,621
That divergence suggests US SMEs are experiencing less severe incidents — or perhaps they’re simply reporting smaller breaches more often. Either way, the trend lines are moving in opposite directions.
What This Means for Businesses Buying Cyber Insurance
If you’re shopping for cyber coverage, the takeaway is clear: premiums may not track claim frequency. Insurers are pricing for severity, and severity is climbing.
Businesses should also recognize that data breach costs are no longer just about IT recovery. Legal defense, regulatory fines, and privacy compliance are now major line items in any claim.
And with ransomware attack tactics evolving, the risk profile keeps shifting. A single incident can now trigger multiple layers of liability.
The bottom line: cyber insurance losses are rising because the consequences of a breach are more expensive than ever. Fewer claims doesn’t mean less risk — it means the risk is concentrating into bigger, costlier events.
For a deeper look at how much a breach actually costs, check out our coverage of data breach cost trends.
Infosecurity
Four in Five AI Tools Operate With Zero IT Oversight, New Research Warns
Published
8 hours agoon
September 2, 2026The Numbers Are Starker Than You Think
Eighty percent of AI tools in enterprise environments operate with no IT oversight whatsoever. That’s the headline finding from Reco‘s new report, The State of Agent Security 2026, which analyzed anonymized telemetry from large enterprises, public Model Context Protocol servers, and vulnerability data from the National Vulnerability Database.
For small and midsize businesses, the picture is even worse: an estimated 414 unsanctioned tools per 1,000 employees. That’s not a rounding error. That’s a shadow ecosystem running on autopilot.
Ofer Klein, CEO of Reco, put it bluntly: “AI agents have moved from experimentation into daily business workflows, but our findings show only 20% of AI tools in enterprise ecosystems are currently governed by IT oversight.”
The result? Agents embedded in applications can operate through existing permissions, OAuth grants, and workflow access. Klein calls these “toxic combinations” that expose data and trigger actions beyond what any owner approved.
MCP Servers: A Backdoor With No Lock
The lack of governance is especially alarming when you look at what Reco found in its analysis of 500 MCP servers—the connectors that give AI agents access to data and actions.
Exactly half can execute shell commands directly. That turns a prompt-injection trick into full operating system access. More than eight in ten can read or write local files. Roughly three-quarters can make outbound network calls.
These aren’t hardened enterprise tools. They’re often loaded by the thousands from marketplaces with no review step. And they rarely guard themselves: just over a quarter expose a network endpoint rather than running locally, and half of those ship with no authentication at all. A remotely reachable tool with host-level reach and no lock on the door.
The Toxic Trio
Here’s the scariest part: nearly two-thirds (62%) of agents combine command execution, file access, and network egress in a single package. That’s an end-to-end toolkit to find data, act on it, and move it off the machine—all in one unwitting download.
This isn’t theoretical. It’s the default configuration of the tools agents are built to load.
Vulnerabilities Are Piling Up Faster Than Fixes
The report also tracked 637 vulnerabilities across agents and LLM tools. Of those, 525 were disclosed in the past 18 months, including at least 111 rated critical with CVSS scores of 9.0 or higher.
The pace is accelerating. The average monthly disclosure rate was under five during 2023 and 2024. Since January 2025, it’s jumped to around 29 per month. That’s a six-fold increase in a year.
Reco warns that vulnerabilities are being published faster than patching programs can absorb. You don’t need to be a security expert to see the problem: if the bad guys are shipping exploits faster than your team can apply patches, you’re already behind.
What This Means for Your Organization
The takeaway isn’t that AI agents are inherently dangerous. It’s that they’re being deployed with the same trust we once gave to floppy disks. The governance hasn’t caught up with the adoption.
If you’re running AI tools in your enterprise, here’s a practical starting point:
- Inventory everything. You can’t govern what you can’t see. Run a discovery scan to find every AI tool and agent in your environment—including the ones employees installed without asking.
- Audit MCP servers. Check which of your agents can execute shell commands or make outbound calls. If a tool doesn’t need that access, strip it.
- Enforce authentication. If any of your MCP servers expose a network endpoint without auth, that’s an emergency, not a TODO item.
- Patch aggressively. With disclosure rates climbing, treat AI-related vulnerabilities like you would a zero-day in your core infrastructure.
For more context on how agents are becoming an attack surface, read our piece on AI agents as the fastest growing exposed attack surface. And if you’re wondering how to secure your own deployments, our guide to AI agent security best practices covers the essentials.
The Bottom Line
AI agents aren’t going away. They’re becoming the backbone of daily workflows. But the research is clear: most organizations are flying blind.
Twenty percent oversight isn’t oversight. It’s a gamble. And with 62% of agents packing command execution, file access, and network egress into one package, the house odds aren’t in your favor.
The good news? You can fix this. Start with an inventory, audit your MCP servers, and patch like your business depends on it. Because it does.
Infosecurity
Berlin refuses to pay ransom after Rhysida hackers steal government data
Published
1 day agoon
September 1, 2026
Berlin refuses to pay ransom after Rhysida hackers claim massive data theft
Berlin’s government has drawn a hard line: it won’t pay a cent to the hackers who say they’ve stolen terabytes of official data. Governing Mayor Kai Wegner made that clear on Friday, calling the situation outright blackmail.
“The state of Berlin is being blackmailed,” Wegner said, adding that the government would not comply with the attackers’ demands. His remarks came as the Rhysida ransomware group claimed responsibility for the breach, which was discovered in mid-August.
What Rhysida claims to have stolen
According to several dark-web monitoring sites, Rhysida has posted Berlin on its leak site, claiming to have grabbed a staggering 5.79 terabytes of government data. That’s a lot of documents. The group says the haul includes 46,500 contracts, plus emails, phone numbers, passwords, and classified information.
They’ve put the dataset up for auction, with a starting price of 30 bitcoin — roughly $2.3 million at current rates. A countdown of about seven days was posted, adding urgency to an already tense situation.
Berlin authorities have confirmed that data was indeed stolen and that an extortion demand was received. But they’ve stopped short of officially blaming Rhysida or verifying the group’s claims about the volume or contents of the stolen files. Investigators are still digging into the scope and nature of the breach. They haven’t ruled out that personal data or other non-public information was compromised.
The data is believed to have been taken between August 7 and August 12. Wegner had earlier said there was no indication that sensitive information was compromised, but that assessment may change as the investigation unfolds.
The attack’s impact on city services
Berlin disconnected the affected systems from the wider state network on August 14, the day the breach came to light. Two ministries were cut off: one handling urban development, construction, and housing, and another overseeing mobility, transport, climate protection, and the environment.
Both ministries stayed operational, but employees lost access to their usual IT systems. That meant no email, no internet services. Some staff had to fall back on telephone, text messages, and even fax machines. Yes, fax. In 2026.
The disruption rippled outward. Some district offices couldn’t process applications for housing benefits or education and participation assistance, because those processes rely on systems run by the affected urban development ministry. Berlin’s state-owned IT provider, ITDZ Berlin, wasn’t hit. The two ministries share some IT infrastructure and run their section of the state network independently of ITDZ, according to local media.
Election security under the microscope
The timing couldn’t be worse. Berlin holds elections to its House of Representatives on September 20 — less than a month after the breach. That’s raised obvious questions: could the attackers disrupt election infrastructure?
Interior Senator Iris Spranger sought to calm those fears on Friday. “According to what we know at this point, no data has been exfiltrated from there,” she said. “According to our security officials, the election environment is secure.”
Who is Rhysida?
Rhysida isn’t a new player. The group has been active since at least May 2023, targeting governments, hospitals, schools, manufacturers, and tech companies. Their playbook is familiar: steal data, encrypt systems, then demand cryptocurrency payments.
They’ve hit a string of high-profile public-sector and healthcare organizations worldwide. Cybersecurity researchers have assessed that the group is likely Russian-speaking or operating from the broader Russian region, though the operators’ identities and exact location remain murky.
For Berlin, the refusal to pay is a statement. But it also means the leaked data could end up public. The city is bracing for that possibility. In the meantime, officials are working to restore normal operations and reassure residents that their information is safe. Whether that holds remains to be seen.

Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure

Nutex confirms patient and employee data stolen in August cyberattack

Sevii Fights AI-Speed Attacks With Preemptive Autonomous Defense

LeakBase Data Breach Forum Seized in Major Europol Operation

The Truth About Fast Charging Apps for Android: Can They Speed Up Your Battery?
Zero-Day Attacks Hit Record High as Enterprise Software Becomes Prime Target

The Shocking Truth About PC Upgrades in 2026: RAM and SSD Prices Are Out of Control

Old vs. New IT Certification Exams: A Strategic Guide to Choosing the Right Path

Samsung Issues Emergency Update for Millions of Galaxy Phones: Here’s What You Must Do
Trending
CyberSecurity6 months agoLeakBase Data Breach Forum Seized in Major Europol Operation
How To5 months agoThe Truth About Fast Charging Apps for Android: Can They Speed Up Your Battery?
CyberSecurity6 months agoZero-Day Attacks Hit Record High as Enterprise Software Becomes Prime Target
CyberSecurity6 months agoRussian Hackers Target WhatsApp and Signal in Global Espionage Campaign
Social Media6 months agoYouTube Live Streaming API: A Developer’s Guide to Managing Live Broadcasts
Video4 months agoSamsung One UI 8.5 Official Update Is Here: Release Timeline, Eligible Devices & Key Features
Infosecurity6 months agoCybersecurity Communication: Why Fear-Based Messaging Fails and What Works
CyberSecurity6 months agoContextCrush Vulnerability: How a Trusted AI Tool Became an Attack Vector
