AnMed reports data breach following ransomware attack | #ransomware | #cybercrime


In a new video statement, AnMed CEO William Kinley confirmed that cybercriminals breached health information in a malware attack on the South Carolina health system’s IT infrastructure this past month that continues to disrupt care.

This follows a new report about the emergence, dominance and evolving extortion tactics of “The Gentlemen” ransomware gang, which claimed responsibility for the hobbling attack earlier this month.

“It was an attack that was orchestrated by a group of individuals motivated by financial gain,” said Kinley in the video released on Friday.

While the health system has not officially confirmed who was behind the July 26 ransomware attack, The Gentlemen ransomware gang appeared to gain access to an AnMed social media page on Aug. 11.

The social media post claiming to be authored by the cybercriminals was a lengthy note claiming responsibility and threatening to release protected health information – such as Social Security numbers and home addresses, medical histories including reproductive health, pediatric and psychiatric information, and sexual assault records.

Kinley said the health system and outside cybersecurity specialists are working “tirelessly” to verify what information was taken and who may be affected and will then notify individuals directly.

“The review is detailed and ongoing, but as soon as we have more information about it, we will share those details with you,” he explained for “limited” communications since systems were first shut down.

The health system’s IT team and security advisers are also still working to restore and recover systems “to get back to normal operations,” Kinley added.

“Our team has worked hard to keep our services open and available to take care of people’s needs and the needs of all the families in our area,” he said. “Make no mistake, it was an attack on all of us.”

According to an Aug. 20 report from Comparitech, a security research firm, The Gentleman has claimed responsibility for 675 ransomware attacks, with more than 600 attacks by the end of July (126 on US-based organizations), making it the second-most dominant ransomware group behind Qilin with 771 claimed attacks.

More than 787,400 records have been breached in confirmed attacks by The Gentleman since it first emerged late last year, according to the firm’s worldwide ransomware tracker. The group claimed 36 attacks on healthcare providers, with eight confirmed in the report.

Comparitech researchers accounted for three confirmed attacks on US healthcare organizations.

“In May 2026, up to 30,000 Texan residents were potentially affected following an attack on Soniva Dental Care’s remote desktop web services infrastructure,” they said. “In August 2026, the group also claimed the incredibly disruptive July 2026 attack on AnMed. Hooke Laboratories recently started notifying victims of a breach following an attack in June 2026.”

The group’s affiliates are targeting vulnerabilities discovered earlier this year, including a vulnerability in Erlang that could enable remote code execution and unauthorized access to affected systems and improper access control in Windows SMB that could allow an authorized attacker to elevate privileges over a network, the researchers said.

The attack on AnMed in particular highlights the extent of disruption ransomware attacks can have on healthcare organizations, according to Rebecca Moody, Comparitech’s head of data research.

“Many ransomware groups, like The Gentlemen, will ensure they’ve stolen data before they start encrypting systems,” she told Healthcare IT News on Thursday. “That way, they can double their chances of securing a ransom payment, particularly if the organization can restore systems without paying for a decryption key.”

Some AnMed patients reported being contacted to set up scam payments earlier this month, leading the health system to issue a warning, which Moody said indicated the likelihood of a data breach, which Kinley has now acknowledged in the new video.

Contacting patients directly “shows how gangs are constantly evolving and looking to maximize each attack,” said Moody in her email.

In doing so, they open a fourth payment avenue beyond ransoming a decryption key for the locked medical record data, deleting stolen data in exchange for payments and selling stolen data on the dark web.

“Ultimately, all of this highlights why ransomware and the gangs behind it aren’t going anywhere,” she said. “Entities may refuse to pay ransoms or be unable to pay due to regulation, but gangs still have the stolen data to capitalize on.”

“I recognize and appreciate this is a scary situation,” Kinley said in AnMed’s video statement. “The possibility of personal information being involved and shared is deeply concerning.” Healthcare IT News



Click Here For The Original Source.

——————————————————–

..........

.

.