CyberIntel ⬡ News
★ Saved ◆ Cyber Reads
← Back 🛡 Active Threats Aug 13, 2026

AnMed Investigating Ransomware Group’s Data Theft Claims - The HIPAA Journal

The HIPAA Journal Archived Aug 13, 2026 ✓ Full text saved

AnMed Investigating Ransomware Group’s Data Theft Claims The HIPAA Journal

Full text archived locally
✦ AI Summary · Claude Sonnet


    AnMed Investigating Ransomware Group’s Data Theft Claims Posted By Steve Alder on Aug 13, 2026 AnMed has not disclosed the name of the group behind the attack, but a threat group called The Gentlemen claimed responsibility. The Gentlemen is a ransomware-as-a-service group that is thought to include affiliates and operators from other prominent ransomware groups. The group has claimed several healthcare victims in recent months, and the pace of the attacks is accelerating. According to the Industrial Ransomware Analysis from the operational technology cybersecurity company Dragos, The Gentlemen was the third most active ransomware group in Q2 2026, claiming 125 attacks in the quarter alone, up from 83 attacks in Q1 – the largest gain out of all established ransomware groups. While the group ranked third, there were only 15 attacks separating the top three ransomware groups, with no single ransomware group dominating. In addition to adding AnMed to its dark web data leak site, the group posted a message on AnMed’s Facebook page on August 11, 2026, ramping up pressure on AnMed to negotiate a ransom payment. “Gentlemen, your confidential data has been exfiltrated. 6TB: HIV+ patients, suicide registries, sexual assault & rape victims, mental health, abortions, genetic data, patient SSN/DOB, autopsy & police evidence. Deletion on payment.” The post has since been deleted. “Earlier today, AnMed identified unauthorized posts on its social media accounts,” explained AnMed in an August 11, 2026, statement about the unauthorized activity. “The claims in the unauthorized posts have not been verified and are under investigation.” AnMed previously stated that its main priority has been ensuring patient safety as it investigates the attack and works to safely and securely restore the affected systems. AnMed continues to make progress in its recovery and has reopened most of its facilities, with only 11 remaining closed. Get The FREE HIPAA Compliance Checklist Immediate Delivery of Checklist Link To Your Email Address Business Email * Name * First Last Number * Company Name * Get Free Checklist Please Enter Correct Email Address Your Privacy Respected HIPAA Journal Privacy Policy The patient portal has been partially restored. Patients with an active MyChart account and a mobile number on file can now log in to access their health information, although some MyChart features are still unavailable. “Restoring patient access to health information is another important step forward in bringing services back online,” explained AnMed. An additional security text message verification step has been added, which must be completed before patients can log in. Phone lines have also been restored so patients are able to call their physicians and other departments directly, and read/write access to patients’ electronic health records has been restored, so care teams can view and update patient medical records. It is likely to take some time to determine the full extent of any data theft. If it is established that the attacker’s claims are correct, AnMed said it will provide appropriate notifications and will release additional information as it becomes available. August 3, 2026: Patients Warned About AnMed Communications After Cyberattack Closes 83 Facilities The Anderson, South Carolina-based nonprofit health system AnMed said it is continuing to make progress restoring its systems after a malware-related cyberattack on July 26, 2026. The health system is operating under established downtime procedures and is continuing to provide care at its locations, although some patients are facing delays. Ten AnMed facilities remain closed a week after the attack; outpatient medical imaging services continue to be affected; and there is only limited patient portal access. The health system is keeping patients up to date on its recovery and available services via its website. AnMed has confirmed that its doctors have access to medical records and the provision of safe care is the highest priority. In some cases, appointments have been rescheduled, and some transfers and diversions remain in place, with decisions guided by patient safety. On July 30, 2026, AnMed issued a warning about communications that appear to have been sent by AnMed, such as MyChart appointment reminders. According to the warning, “During our response to the cybersecurity incident, certain appointment reminders generated outside of our internal systems may continue to be delivered by text message. Patients are not required to confirm appointments electronically at this time.” AnMed said it has not found any evidence to suggest that patients are being targeted with malicious intent as a result of the security incident, although patients have been advised to remain cautious with any electronic messages that appear to originate from AnMed. AnMed has not disclosed the name of the group behind the attack, but a threat group called The Gentlemen has claimed responsibility. The Gentlemen is a ransomware-as-a-service group that is thought to include affiliates and operators from other prominent ransomware groups. The group has claimed several healthcare victims in recent months. July 27, 2026: AnMed Closes 83 Facilities While It Grapples with Cyberattack AnMed, formerly AnMed Health, a nonprofit health system serving patients in upstate South Carolina and Northeast Georgia, has been forced to temporarily close 83 of its 106 facilities while it deals with cyberattack-related disruption to its IT systems. Computer systems, phone lines, and Internet connectivity are down. On Sunday, July 26, 2026, the health system confirmed that it had experienced “a cybersecurity disruption involving malware,” which forced it to close AnMed Medical Group offices and AnMed Imaging Services on Monday. AnMed Urgent Care locations, AnMed Kids Care, AnMed Integrated Therapy locations, and AnMed Laboratory Services will open as scheduled on Monday. While offices have been temporarily closed, AnMed said its care teams remain on site and will continue to see patients in the emergency room. The attack has resulted in disruption to patient services, with some scheduled appointments postponed. Patients who had elective procedures scheduled for Monday are being contacted directly to advise them if their procedures will go ahead as planned or will have to be postponed. Decisions about procedures, patient transfers, diversions, and operational processes are being made with patient safety as the guiding principle. AnMed said it is coordinating with the emergency medical services, regional hospitals, and public safety partners to ensure that patients receive the care they need in the most appropriate setting. AnMed is currently unable to provide a timeline for when computer systems will be recovered, when its offices will reopen, and when normal services will resume. Updates will be provided via its website, including operational plans for the coming days. Cybersecurity partners are working on restoring access to systems and data as quickly as possible. An investigation has been launched to determine the nature and scope of the incident, but it is too early to tell to what extent, if any, patient data was involved. No threat group appears to have claimed responsibility for the incident.
    💬 Team Notes
    Article Info
    Source
    The HIPAA Journal
    Category
    🛡 Active Threats
    Published
    Aug 13, 2026
    Archived
    Aug 13, 2026
    Full Text
    ✓ Saved locally
    Open Original ↗