The Gentlemen ransomware group has posted Eva Care, a post-acute care operator, on its leak site, according to HookPhish and ransomware.live.
The listing appeared August 10 at 08:09 UTC, with the breach dated the prior evening, August 9. Trackers describe Eva Care as a healthcare provider in the post-acute care industry that operates and manages a network of nursing homes and rehabilitation facilities, delivering clinical, financial, operational, and environmental management across its locations.
No data volume or file samples were detailed in the tracker reports, and Eva Care has not confirmed any incident. Class action investigators at classaction.org opened a case page on the claim the same day, noting the alleged attack was first reported by the HookPhish platform.
Ransomware claims against care facilities carry particular weight because the organizations hold medical records, medication schedules, and personal data for elderly and vulnerable residents, and outages can disrupt daily clinical operations. Even an unverified listing justifies defensive steps: review backups, check identity provider logs for unusual access, and prepare patient notification workflows in case the claim is confirmed. The Gentlemen has been one of the most active extortion operations of 2026, and post-acute care chains have become a recurring target.
