Nonprofit health system AnMed has confirmed that criminals stole information during the July 26, 2026 cyberattack that shut down its IT environment and closed dozens of care sites across upstate South Carolina and northeast Georgia. In a written statement and a video from its CEO released Friday, August 21, the Anderson, South Carolina-based system said the intrusion was "orchestrated by a group of individuals motivated by financial gain" and warned patients to expect direct contact from the attackers. Note that the two outlets covering the video render the chief executive's surname differently: Information Security Media Group reports it as William Kenley, while Healthcare IT News reports William Kinley. The ransomware-as-a-service crew The Gentlemen claims it exfiltrated 6 terabytes of corporate and patient data, a figure AnMed has pointedly refused to validate.
What Happened
AnMed disclosed a "cybersecurity disruption involving malware" on Sunday, July 26, 2026, and pulled systems offline. The outage was not brief. Reporting from The Record described continued facility closures two full weeks later, and the health system maintained a daily-updated list of open and closed offices throughout August.
The scale of the operational hit is described inconsistently across sources. The fintechlaw.ai analysis, citing HIPAA Journal, puts the peak impact at roughly 83 of AnMed's 106 facilities closed. By August 10, The Record counted 10 facilities still closed to appointments; HIPAA Journal and the Anderson Independent Mail both reported 11 still closed as of August 13 and August 11 respectively. The most defensible reading is that the closure count peaked in the dozens in late July and had fallen to roughly 10 to 11 sites by mid-August, with the patient portal only partially restored (MyChart access restricted to users with an active account and a mobile number on file).
On August 11, the attack escalated from an IT incident into a communications crisis. The Gentlemen posted a ransom note directly to AnMed's Facebook page. AnMed confirmed the same day that it had "identified unauthorized posts on its social media accounts," removed the content, disabled platform access and engaged the provider to secure the accounts. The page itself was taken down shortly afterward.
AnMed has still not publicly named the group behind the attack. The Gentlemen has claimed responsibility and added AnMed to its dark web leak site.
What Was Taken
Two very different tiers of claim are in circulation, and they should not be blended.
The attacker's claim: the Facebook post, quoted verbatim by HIPAA Journal, the Independent Mail and Healthcare Compliance Journal, read "Gentlemen, your confidential data has been exfiltrated. 6TB: HIV+ patients, suicide registries, sexual assault & rape victims, mental health, abortions, genetic data, patient SSN/DOB, autopsy & police evidence. Deletion on payment." Information Security Media Group's account of the leak-site listing adds reproductive care, genetic testing and cancer records; Healthcare IT News adds home addresses, pediatric and psychiatric information. The Record and fintechlaw.ai both note plainly that the group provided no evidence to support any of this.
AnMed's own position: per the health system's notice cited by Becker's on August 27, files copied during the incident may have included patients' Social Security numbers, driver's license numbers and financial account information. That is the only categorical statement of stolen data types that carries the victim's own name. On the broader claims, AnMed's statement is unusually direct: the criminals' public characterizations "are general and do not provide a sufficient basis for determining what information was actually affected or whose information may be involved," and the system "will not rely on those characterizations and will instead complete a comprehensive, independent review before drawing conclusions or providing notifications."
No record count has been published by anyone. No volume figure other than the attacker-supplied 6TB exists. Treat both as unverified.
Why It Matters
The novel element here is not the encryption or the exfiltration. It is that the attackers seized the victim's own outbound communication channel at precisely the moment the victim needed it most. AnMed had been using daily public updates to tell patients which clinics were open; The Gentlemen took over that channel to broadcast a ransom note referencing HIV status, suicide registries and sexual assault records. As fintechlaw.ai frames it, a breach communications plan that assumes your owned channels remain yours is not a plan.
The second point is the data category itself. The claimed holdings are not generic PII. Records tied to HIV status, psychiatric care, abortion, sexual assault and genetic testing carry coercion value against individual patients that survives any credit monitoring offer. That is why AnMed's warning about follow-on scams matters: the CEO explicitly told patients that criminals may contact them directly with fraud and payment lures, and that the "possibility of personal information being involved and shared is deeply concerning."
Third, the actor is scaling fast. HIPAA Journal and Healthcare Compliance Journal both cite Dragos' Industrial Ransomware Analysis ranking The Gentlemen the third most active ransomware group of Q2 2026 with 125 claimed attacks, up from 83 in Q1, the largest quarter-over-quarter gain among established groups. Only 15 attacks separated the top three. The Record reports the group emerged in the second half of 2025 and is believed to have been founded by a former Qilin affiliate; both HIPAA Journal and Healthcare Compliance Journal describe it as a RaaS operation staffed with operators and affiliates from other established brands. Healthcare is a repeat target.
The Attack Technique
Initial access remains undisclosed. No source identifies an exploited CVE, a phishing lure, a compromised VPN appliance or a third-party vendor path. AnMed has described the incident only as "involving malware," and its forensic review with outside specialists is ongoing.
What can be stated about tradecraft is the extortion side. The pattern visible across the reporting is double extortion with an aggressive pressure ladder: encrypt and disrupt, post to a dark web leak site, then escalate to hijacking the victim's social media presence on day 16 to force negotiation. The Facebook takeover is worth noting as a tradecraft data point in its own right. Whether the attackers obtained page credentials from the compromised network, from an administrator's session, or by separate means is not established in any source, but organizations should assume that credentials for cloud and social platforms sitting inside a breached environment are in scope.
Where Accounts Differ
Three things are genuinely unsettled and are reported here as such. First, the CEO's name is spelled Kenley in one outlet and Kinley in another. Second, facility closure counts vary between roughly 83 at peak and 10 or 11 in mid-August, reflecting different reporting dates rather than a contradiction, though the peak figure comes to us secondhand. Third, and most consequentially, the gap between what The Gentlemen claims it holds and what AnMed has confirmed remains wide and unresolved. AnMed has confirmed that data was taken and that SSNs, driver's license numbers and financial account data may be among it. Everything beyond that is an attacker assertion with no published proof.
What Organizations Should Do
- War-game the hijacked-megaphone scenario. Build and document out-of-band patient and staff notification paths now, including a pre-registered alternate domain, SMS or IVR fallback, and local media contacts. Assume your website, portal and social accounts may be broadcasting the ransom note.
- Inventory and harden non-domain identity. Social media, marketing platforms, DNS registrars and cloud consoles are frequently outside the enterprise IAM perimeter. Enforce hardware-backed MFA, remove standing admin sessions, tie ownership to a break-glass account not stored in the breached environment, and know your provider's emergency account-recovery contact before you need it.
- Separate forensic truth from attacker marketing in your comms policy. AnMed's refusal to notify off a leak-site boast is the correct posture and worth copying verbatim. Publish what evidence supports, treat the claim as an urgent investigative priority, and do not let a countdown timer force you to concede facts you cannot substantiate.
- Push exfiltration detection ahead of encryption detection. The leverage in this case is the data, not the downtime. Instrument egress volume baselines, alert on bulk reads from clinical archives and imaging stores, and monitor for cloud storage and file-transfer utilities appearing on clinical subnets.
- Segment the highest-sensitivity record classes. Behavioral health, HIV and STI, reproductive care, genetic testing and forensic or sexual assault records deserve tighter access controls, separate audit trails and stricter retention limits than general EHR data, precisely because their extortion value is highest.
- Prepare patients for direct contact. Hospitals in this position should issue proactive scam guidance early, as AnMed did, covering fake payment demands, bogus breach-notification calls and requests to "verify" data. Give patients a single verified channel to check against.
- Track The Gentlemen specifically if you are in healthcare. Given Dragos' Q2 volume data and the group's affiliate pedigree, feed known indicators into detection content and review Qilin-lineage TTPs as a starting hypothesis for initial access.
Sources: AnMed Confirms Data Theft, Warns Patients of Criminal Scams | Patient data was breached in AnMed attack - Healthcare IT News | AnMed says stolen files may include SSNs, financial data | AnMed Investigating Ransomware Group's Data Theft Claims | Ransomware group hijacks hospital system’s Facebook page amid ongoi... | AnMed Investigates The Gentlemen Data Theft Claims - Healthcare Com... | AnMed responds to hackers claim of having patient data in social post | AnMed Ransomware: The Breach Notification Clock Explained