AnMed, an independent not-for-profit health system serving Upstate South Carolina and northeast Georgia, reported a malware-related cybersecurity disruption that knocked out phone and internet services across all hospital locations and caused widespread network outages. The incident affected four hospitals and disrupted communications and clinical operations as the organization worked to restore systems and determine the scope of the attack.
The outage forced dozens of departments and facilities to close, including imaging, OBGYN, primary care clinics, and medical group offices, while emergency rooms and urgent care locations remained open and continued seeing patients. AnMed said it was coordinating with emergency medical services, regional hospitals, and public safety partners to maintain patient care during the disruption.

See attribution, scope, and your downstream exposure.
2 events from the most recent confirmed update back to the earliest known activity.
AnMed disclosed that malware affected its networks, causing widespread operational outages and forcing dozens of departments and facilities to close, including imaging, OBGYN, primary care clinics, and medical group offices. The health system said urgent care remained open and that it was working to restore systems, assess the scope of the incident, and coordinate with emergency services and regional partners.
AnMed reported that all hospital locations were experiencing a phone and internet outage, while emergency rooms remained open and continued seeing patients. The disruption affected the health system's four hospitals serving Upstate South Carolina and northeast Georgia.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
therecord.media
Open sourcemalware.news
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.