AnMed Cyberattack: Ransomware Group 'The Gentlemen' Claims Massive Data Exfiltration, Healthcare Services Disrupted
The **AnMed** medical system continues to grapple with the aftermath of a severe cyberattack that has crippled its IT infrastructure for two weeks. The disruption escalated when purported ransomware group **The Gentlemen** claimed responsibility, posting ransom demands and alleged exfiltrated data on **AnMed**'s Facebook page, raising urgent concerns about patient data privacy.
Two weeks after a cyberattack first disrupted its IT systems, the nonprofit medical system **AnMed**, serving Georgia and South Carolina, is still facing significant operational challenges. The incident took a dramatic turn when its official Facebook page displayed ransom demands from the purported attackers.
The social media page, representing **AnMed**'s four hospitals and multiple clinics, was quickly removed after a series of messages from a group identifying itself as **The Gentlemen** ransomware group appeared.
### Claims of Massive Data Exfiltration
**The Gentlemen** claimed to have exfiltrated 6 terabytes of sensitive data, including highly confidential health information related to sexual assault, mental health, abortions, and sexual harassment incidents. However, no independent evidence has been provided to substantiate these claims.
**AnMed** has yet to confirm the scope of any potential impact on patient information, stating on its website that it has not βconfirmed the scope of any potential impact to patient information.β
An **AnMed** spokesperson addressed the social media breach, stating: "Earlier today, **AnMed** identified unauthorized posts on its social media accounts. The unauthorized content was removed, access through the platform was disabled and we are working with the provider to secure the accounts." They added that the claims within the posts remain unverified and are part of an ongoing investigation into the cybersecurity incident identified on July 26.
### Ongoing Operational Disruptions
The initial incident was described by **AnMed** as a βcybersecurity disruption involving malware.β Since then, **AnMed** has provided daily updates on facility statuses, with 10 facilities still closed for appointments as of Monday.
### The Rise of The Gentlemen Ransomware Group
**The Gentlemen** has rapidly emerged as a prominent ransomware-as-a-service (RaaS) group since its appearance in the second half of 2025. It is believed to have been founded by a former affiliate of the **Qilin** ransomware group, operating under the moniker βhastalamuerte.β
According to cybersecurity firm **CheckPoint**, **The Gentlemen**'s ransomware was used to extort 332 victims in the first five months of this year alone. In the second quarter of 2026, the group claimed 125 attacks on industrial organizations, ranking third among ransomware groups, as reported by operational technology firm **Dragos**.
### Sophisticated Tactics and Affiliate Model
Leaked internal files analyzed by **CheckPoint** reveal an unusually generous fee structure, with affiliates reportedly receiving 90 percent of the ransoms. The group typically gains initial access through edge devices such such as firewalls, VPN appliances, and other internet-facing systems.
**CheckPoint** elaborated on their access methods: βThey combine different methods to achieve this, including credential brute-forcing against web or VPN panels, exploiting known vulnerabilities, and buying access from third-party βbotβ or access brokers.β Once inside, they aim to gain administrator privileges and disable security tools before exfiltrating data and deploying ransomware.
Notably, **The Gentlemen** provides affiliates with sophisticated tools designed to disable Endpoint Detection and Response (**EDR**) technology. In one instance, observed by security firm **Expel**, the group exploited a vulnerability in an βobscureβ third-party vendor driver to neutralize the victimβs **EDR**.
**Expel** researcher Marcus Hutchins commented on this in June: βWhatβs notable here isnβt the technique itself, but the sophistication of the toolkit theyβve built around it.β
