SYS::ONLINE
Wasteland.
Briefs1888
Issues23
SinceFeb 2026
LIVE
█ Ransomware ANMED-HEALTH-THE 2026-08-12

AnMed Health: The Gentlemen Ransomware Claim Follows Weeks of Care Disruption

"The Gentlemen ransomware group claimed responsibility on August 10, 2026 for the cyberattack that has disrupted AnMed, a nonprofit health system serving upstate South Carolina and northeast Georgia, since Sunday, July…"

The Gentlemen ransomware group claimed responsibility on August 10, 2026 for the cyberattack that has disrupted AnMed, a nonprofit health system serving upstate South Carolina and northeast Georgia, since Sunday, July 26. The claim, first reported by threat intelligence vendor DeXpose, came roughly two weeks into an incident that forced the closure of more than 80 AnMed facilities, knocked out phone, internet and electronic health record access, and delayed surgeries and other planned treatments. On August 11, suspected attackers posted nearly 100 ransom messages to AnMed's own Facebook page claiming six terabytes of data had been stolen. AnMed publicly stated the same afternoon that those claims "have not been verified." No regulatory filing or victim breach notification confirming data theft has been published at the time of writing.

What Happened

AnMed identified the incident on Sunday, July 26. In a statement posted to its website and reported by TechTarget and Healthcare IT News, the Anderson, South Carolina based system described a malware incident that had impacted its network, IT systems and internet access.

The operational hit was immediate and broad. TechTarget reported that more than 80 facilities would be closed on Monday, July 27; both the TechTarget headline and HIPAA Journal put the figure at 83 facilities. Modern Healthcare, summarized by KFF Health News, described the closures more conservatively as affecting "several" AnMed facilities. AnMed Medical Group and all imaging services closed, elective procedures scheduled for Monday were cancelled, and Healthcare IT News reported that oncology and radiation services were also shut, with infusions running on a limited basis. Urgent care, emergency services, general laboratory services, integrated therapy locations and AnMed Kids Care stayed open.

Recovery has been slow and uneven. Healthcare Dive reported on August 5 that 10 AnMed facilities remained closed a full week after the attack. By July 31, WYFF was reporting day six of the shutdown with AnMed saying teams were working "around the clock" and that federal, state and third-party investigations remained ongoing. KFF Health News, citing Modern Healthcare's July 27 reporting on the system's news release, noted a forensic investigation underway to determine, among other things, whether patient data had been compromised.

The extortion timeline is where accounts diverge. Healthcare IT News reported that AnMed was given 72 hours to respond to demands in what it characterized as an apparent extortion attempt. DeXpose dates The Gentlemen's public claim to August 10, quoting the group's statement: "The full leak will be published soon, unless a company representative contacts us via the channels provided." WYFF reported that the Facebook flood came the morning of Tuesday, August 11. DeXpose is the only source among the eight that names The Gentlemen at all; the attribution should be treated as vendor-reported rather than confirmed.

That same August 11 update carried the first substantive recovery news. AnMed said care teams had regained full read/write access to patient electronic health records, and that beginning at 7 a.m. Wednesday, August 12, patients could again call doctors' offices and departments directly.

What Was Taken

Nothing has been confirmed stolen. What exists is a claim and a denial.

The ransom messages posted to AnMed's Facebook page on August 11 claimed six terabytes of critical information, including patient records, had been leaked. WYFF reported that the first post appeared around 9:40 a.m., was labeled as AI generated content, was littered with grammatical errors, and was taken down shortly after. Roughly 100 such posts went up before AnMed removed the unauthorized content and disabled access through the platform.

AnMed's response was measured and explicitly non-confirmatory: the claims in the posts have not been verified, its cybersecurity specialists are investigating the Facebook incident as part of the broader July response, and "if the investigation determines personal information was affected, AnMed will provide appropriate notifications and additional information as it becomes available."

That is the correct read for now. A six terabyte claim from an extortion group with no released sample, no leak site listing described in any source, and an active forensic investigation that has not concluded is an unproven assertion. It is also worth noting that the six terabyte figure comes from the attackers via a local news report, while DeXpose's account of the August 10 claim quotes only a generic threat to publish with no volume attached. The two accounts of the same extortion campaign do not corroborate each other on scale.

Independent of the ransom claim, AnMed warned patients on July 30 that some were receiving communications, including MyChart appointment reminders, that appeared to come from AnMed. The system flagged these during its incident response, and the pattern is worth watching as a fraud vector regardless of what the forensics ultimately show.

Why It Matters

The AnMed incident is a clean case study in the second phase of modern healthcare extortion: when the encryption leverage fails, the attacker attacks the victim's public voice.

Taking over the victim's own Facebook page and flooding it with ransom notes is a pressure tactic aimed squarely at patients and the local community, not at the security team. It converts a contained IT incident into a public panic event, and it does so at a moment when AnMed's own phone lines and communication channels were degraded, making it harder for the organization to correct the record quickly. The posts being AI generated and error-riddled did not blunt the effect; nearly 100 of them reached a health system's followers before takedown.

The operational damage is the more concrete lesson. Two weeks of disruption, 10 facilities still closed at the one week mark, cancelled elective procedures, shuttered oncology and radiation services, and clinicians reverting to workflows without electronic health records is patient safety impact measured in weeks, not hours. Cybersecurity expert Phil Yanov of Tech After 5, speaking to WYFF, put the targeting logic plainly: a hospital feels urgent, and holds names, medical records and highly sellable personal data on large populations.

For defenders, the takeaway is that the blast radius of a healthcare ransomware event now routinely includes owned social media accounts, patient-facing messaging systems such as MyChart, and the organization's ability to communicate truthfully at speed. Those assets rarely appear in an incident response plan.

The Attack Technique

Initial access has not been established publicly. Across all eight sources, no vector is named. AnMed has consistently described the July 26 event as a malware incident affecting phone, internet and computer systems, and says it is working with unnamed third-party cybersecurity specialists alongside state and federal authorities. The forensic investigation remains open.

What can be observed from the reporting:

Anyone stating a specific initial access vector for this incident today is speculating.

What Organizations Should Do

  1. Put owned social and patient-communication accounts inside your incident response plan. Inventory every official Facebook, X, Instagram and LinkedIn account, enforce phishing-resistant MFA on all administrators, remove stale admin access, and pre-establish an escalation contact at each platform. Rehearse the takedown path before you need it at 9:40 a.m. on a Tuesday.

  2. Prepare an out-of-band communications channel now. AnMed lost phone and internet while needing to correct attacker claims in public. Maintain a status page on infrastructure entirely separate from your production network, plus a pre-drafted holding statement, and make sure patients and partners know where to look.

  3. Assume exfiltration until forensics say otherwise, and say so carefully. AnMed's language, that claims are unverified and notification will follow if the investigation determines personal information was affected, is the right public posture. Internally, run the data-theft assumption in parallel with recovery so that notification obligations under HIPAA and state law are not discovered late.

  4. Validate that backups survive the attacker, not just the failure. Keep backups immutable, offline or logically air-gapped, and separately credentialed from production identity. Then actually test restoration of clinical systems end to end, including the dependency chain between EHR, imaging, lab and telephony.

  5. Segment clinical operations so one intrusion cannot close 80 facilities. Network segmentation between administrative IT, clinical systems and site-level infrastructure is what determines whether an incident is a bad week at one campus or a regional care disruption. Verify that imaging, oncology and infusion systems can operate independently.

  6. Build and drill downtime clinical procedures. Paper workflows for medication administration, orders, transfers and diversion decisions need to be current, printed and practiced. AnMed's stated principle, that decisions on procedures, transfers and diversions be made with patient safety as the guiding principle, only works if the mechanics exist beforehand.

  7. Watch for follow-on fraud against your patients. The MyChart reminder confusion AnMed flagged is exactly the seam attackers and opportunists exploit after a public breach. Warn patients proactively about unsolicited contact, and monitor for lookalike domains and impersonation.

Sources: The Gentlemen Ransomware Attack on AnMed Health System - DeXpose | Cyberattack forces temporary closure of 83 AnMed facilities TechTa... | 10 AnMed facilities remain closed a week after cyberattack Healthc... | AnMed given 72 hours to respond to demands in ... | Patients Warned About AnMed Communications After Cyberattack Closes... | AnMed says hacker ransom posts on Facebook page are unverified - WYFF | AnMed Centers In South Carolina Remain Closed A Week After Malware... | AnMed continues to suffer from cyberattack - WYFF