Cyber & AI intelligence
Wasteland.
Briefs indexed2441
Issues26
Published Mondays07:30 CT
█ Ransomware VERADIGM-THEGENTLE 2026-09-06

Veradigm: The Gentlemen Ransomware Leak Site Listing

"Veradigm Inc., the Chicago-based healthcare technology and payments firm formerly known as Allscripts, was added to the leak site of the ransomware-as-a-service operation known as The Gentlemen (also written…"

Veradigm Inc., the Chicago-based healthcare technology and payments firm formerly known as Allscripts, was added to the leak site of the ransomware-as-a-service operation known as The Gentlemen (also written thegentlemen) on 2026-09-05. The listing claims more than 3.5 million personal patient records containing full names, addresses, Social Security numbers, email addresses, phone numbers and guarantor PII. As of this writing the claim is an actor assertion and not a confirmed disclosure: Veradigm has issued no public statement, and no regulator filing has surfaced. HookPhish records the underlying breach date as 2026-09-04 and discovery as 2026-09-05; UndercodeNews notes independent tracking that also dates the listing to September 4. The only PRIMARY-tier material available concerns the threat group itself, not the victim.

What Happened

Veradigm's name appeared on The Gentlemen's dark web leak site with a victim card naming veradigm.com, a ZoomInfo company profile, and a claimed haul of "3.5+ million personal patient records." HookPhish (S1) timestamps the incident at 2026-09-04T17:26:38Z with discovery at 2026-09-05T18:29:58Z. UndercodeNews (S3) covered the same listing on September 5 and was explicit that it could not verify the figure, writing that "available independent tracking has not confirmed the exact number of affected individuals or the complete contents of the alleged stolen data."

That caveat is the story's center of gravity. Every source describing the Veradigm incident is OTHER-tier, and all of them are ultimately reading the same leak-site post. There is no second, independent count of records to compare against 3.5 million, so the figure should be treated as the attacker's claim rather than a measured total. Note also that the leak-site card mixes claimed haul with scraped corporate background: the "200M+ patient records" and "450,000 connected providers" figures reproduced in the HookPhish table describe Veradigm's overall data network, not the volume of data allegedly stolen. Conflating the two would overstate the incident by roughly two orders of magnitude.

Veradigm (OTC: MDRX) was founded in 1986, renamed from Allscripts in January 2023, and employs roughly 2,300 to 2,600 people. Its 2024 segment revenue breaks down as Provider $473M, Payer $67.3M and Life Sciences $54M. Its position as a multi-EHR data aggregator is precisely what makes a credible intrusion consequential well beyond its own perimeter.

What Was Taken

The claimed data categories, per the leak-site listing as reproduced by HookPhish and summarized by UndercodeNews, are:

The record count claimed is 3.5 million or more. No source provides an alternate count, and no source provides a data volume in terabytes for Veradigm specifically. Neither a sample set nor a countdown timer state is described in the available reporting, and there is no indication in these sources of whether encryption accompanied exfiltration.

The guarantor field is the detail worth flagging. Guarantor records extend exposure past the patient to whoever is financially responsible for the account, frequently a parent, spouse or adult child who never received care and would not expect to appear in a health system's breach notification. If the claim holds, the affected population is meaningfully larger than the patient population.

For calibration on how this group describes its hauls elsewhere: in the AnMed case, The Gentlemen claimed 6TB including HIV status, mental health records, sexual assault and suicide registry data, and genetic data, and posted the claim directly to AnMed's Facebook page on 11 August 2026 (Healthcare Compliance Journal). AnMed confirmed unauthorized posts on its social accounts but stated the claims were unverified and under investigation, and that establishing the true extent of any theft would take time. RecentBreaches, tracking the same listing from 9 August, likewise carried it as an unverified claim with affected individuals listed as unknown. That is the realistic timeline shape here too.

Why It Matters

The Gentlemen is not a marginal actor. Sophos Counter Threat Unit, which tracks the operators as GOLD SHERWOOD, documented 683 victim names on the leak site by the end of July 2026, with July alone accounting for 169, making it the most active leak site that month. Comparitech's independent count for the same window is close but not identical: 675 total claimed attacks since mid-2025, 600 of them in 2026 through July, an average of 2.8 attacks per day, placing the group second only to Qilin (771). Dragos, cited by Healthcare Compliance Journal, ranked it the third most active ransomware group in Q2 2026 with 125 attacks, up from 83 in Q1, the largest quarter-over-quarter increase among established groups. The counts differ by methodology; the trajectory does not.

Comparitech's confirmation rate is the number defenders should internalize. Of 600 claimed 2026 victims, only 68 were confirmed by the organization involved. For healthcare specifically, 36 claimed attacks yielded 8 confirmations. Leak-site listings are marketing collateral for an extortion business, and roughly one in nine gets corroborated by the named victim. That cuts both ways: it is a reason not to treat 3.5 million as fact, and not a reason to assume nothing happened.

Sector focus matters for prioritization. Comparitech found manufacturers made up 24 percent of 2026 victims, with US-based organizations at 21 percent, notably lower than Qilin's 47 percent US concentration. Healthcare is a recurring but not dominant target: Security Arsenal's analysis of a 15-victim single-day dump on 2026-08-14 found a US healthcare provider (First Coast Heart Vascular Center) mixed in with technology, manufacturing, retail, hospitality and professional services victims across 8+ countries. UndercodeNews recorded the listing of Eyecare Center of Snohomish on 23 August. The pattern is opportunistic volume, not sector strategy, which means a healthcare IT firm's defense posture cannot rely on being an unlikely target.

The aggregator angle is what elevates this above a routine listing. Veradigm sits upstream of hundreds of thousands of providers. A compromise there is a supply chain event for the practices, payers and life sciences customers connected to its network, and downstream organizations should be asking about their own exposure regardless of whether the 3.5 million figure survives scrutiny.

The Attack Technique

No source identifies the initial access vector for the Veradigm intrusion specifically. What follows is the group's documented playbook and should be read as a threat profile, not as an account of this incident.

Sophos CTU, the strongest source here, analyzed 15 intrusions and found a consistent post-exploitation sequence: rapid privilege escalation, adaptive tooling, and aggressive defense evasion, with ransomware deployment sometimes within 24 hours of the first identified post-compromise activity. Affiliates lean on legitimate administrative tools and compromised credentials rather than custom malware, which is what makes the tradecraft hard to catch on signature-based controls. GOLD SHERWOOD has run the scheme as double extortion since mid-2025, stealing data before encrypting, with victim names first posted in September 2025 and an affiliate recruitment ad on the RAMP forum that same month offering a 90/10 split.

Comparitech reports the origin story that the group formed when a Qilin affiliate, ArmCorp, split off after a payment dispute, and that the 90 percent affiliate cut sits well above the 70 to 80 percent industry norm. It attributes the May 2026 onward surge to a BreachForums partnership plus rumored exploitation of CVE-2025-32433 and CVE-2025-33073, and labels that exploitation as rumored rather than established. Security Arsenal separately correlates the ecosystem's initial access profile to CISA KEV entries for a Check Point Security Gateway authentication bypass (CVE-2026-50751) and a ConnectWise ScreenConnect path traversal (CVE-2024-1708), and characterizes typical vectors as edge device exploitation, exposed or brute-forced RDP, macro-lure phishing, and abuse of remote access tooling. Security Arsenal also lists typical ransom demands in the $150K to $2M range scaled to victim revenue, though for a target of Veradigm's size that band is likely a floor rather than a guide.

Treat the CVE correlations as ecosystem-level pattern matching from OTHER-tier sources, not as confirmed exploitation in any named breach.

What Organizations Should Do

  1. Harden and inventory remote access first. Sophos names this as the top control. Enumerate every VPN concentrator, security gateway, RDP endpoint and remote management agent reachable from the internet, and patch the edge devices flagged in KEV correlation for this ecosystem, including the ConnectWise ScreenConnect and Check Point gateway issues cited by Security Arsenal.
  2. Enforce phishing-resistant MFA everywhere, especially on administrative and remote access accounts. The playbook runs on valid compromised credentials; MFA is the control that breaks it before privilege escalation begins.
  3. Alert on exfiltration tooling and staging directories, not just encryption. Sophos specifically calls out anomalous data exfiltration tool usage and staging directories. With a sub-24-hour dwell time in some intrusions, detection that only fires at encryption fires too late to prevent the extortion leverage.
  4. Monitor administrative activity for anomalies. Because affiliates use legitimate tools, behavioral baselines on admin account usage, new service creation and security tool tampering will outperform signature detection.
  5. Assess third-party exposure to Veradigm and comparable health data aggregators. Providers, payers and partners on connected EHR networks should be asking their vendor account teams direct questions now rather than waiting for a notification cycle that, based on the AnMed precedent, may take months.
  6. Prepare the notification and legal track in parallel with technical response. If a claim of this scale is substantiated, HIPAA breach notification, state AG obligations and near-certain class action exposure follow. The Atrium Health $1.8M pixel settlement and Deanco Healthcare $1.55M breach settlement noted by Healthcare Compliance Journal illustrate the baseline cost of healthcare data litigation even absent ransomware.
  7. Do not pay on the strength of a leak-site claim. With a roughly 11 percent victim-confirmation rate across this group's 2026 listings, actor-stated volumes and data categories should be independently validated against your own telemetry before any negotiation posture is set.

Sources: Ransomware Group thegentlemen Hits: Veradigm | Ungentlemanly behavior: Insights into a ransomware operation SOPHOS | Veradigm Faces a Major Healthcare Cybersecurity Crisis as The Gentl... | AnMed Investigates The Gentlemen Data Theft Claims - Healthcare Com... | The Gentlemen ransomware: stats on attacks, ransoms & data breaches... | TheGentlemen and Eclipse Ransomware Groups Reportedly Add Healthcar... | THEGENTLEMEN Ransomware Gang: 15 Victims in a Single-Day Surge — Se... | AnMed Ransomware Claim (2026) — What’s Alleged & Am I Affected?