AnMed says cyberattack is still disrupting hospitals and clinics as The Gentlemen ransomware group posts ransom demands on its Facebook page

Nonprofit health system AnMed is still dealing with fallout from a July 26 cyberattack that knocked out IT systems and left multiple facilities closed to appointments. The group calling itself The Gentlemen posted ransom demands on AnMed's Facebook page and claimed to have stolen 6 terabytes of data, including sensitive patient and HR records, though AnMed says it has not yet confirmed the scope of any patient-data impact. The incident was initially described by AnMed as a malware-related cybersecurity disruption affecting four hospitals and clinics in Georgia and South Carolina.
Why it matters: This is a significant healthcare ransomware event because it is disrupting care delivery and may involve highly sensitive medical data. Patients and partners should watch for official breach notices and phishing, while healthcare defenders should review exposure of internet-facing systems, privileged accounts, and social media administration access.

Sources

Ransomware group hijacks hospital system’s Facebook page amid ongoing cyberattack fallout
2026.08.11 100% relevant
This article establishes a distinct new ransomware incident centered on AnMed, adding concrete operational impact and a new development in which the alleged attackers hijacked the hospital system's Facebook page to publish extortion messages.
← Back to all stories