AnMed, a nonprofit healthcare system serving South Carolina and Georgia, is dealing with prolonged disruption after a malware-related cyberattack that the The Gentlemen ransomware group has claimed as its own. Reports say the incident affected hospitals and clinics, with some facilities remaining closed, and the group later used AnMed’s Facebook page to post ransom demands. AnMed said the social media posts were unauthorized, removed them, disabled access to the platform, and continues to investigate whether patient information was compromised.
The attackers also claimed to have stolen 6 TB of sensitive data, although AnMed said those assertions have not been verified. The incident comes amid a broader rise in ransomware activity, with Comparitech reporting 799 claimed attacks in July and identifying The Gentlemen and Qilin as the most active groups, together accounting for roughly 33% of all claims. Healthcare was among the sectors seeing the sharpest increase, underscoring continued pressure on U.S. medical organizations.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
AnMed said it identified a cybersecurity incident involving malware on July 26, which knocked out IT systems and began causing operational disruption across its hospitals and clinics.
Comparitech said claimed ransomware attacks rose to 799 in July 2026, up 19% from June, with healthcare among the sectors seeing the largest increases. The report also said The Gentlemen and Qilin together accounted for 33% of claimed attacks in July, with The Gentlemen claiming 135 incidents.
On Tuesday, AnMed's Facebook page was apparently compromised and briefly showed ransom demands from actors claiming to be The Gentlemen, who also alleged they stole 6 terabytes of data without providing proof. AnMed said the posts were unauthorized, removed the content, disabled platform access, and said the claims had not been verified.
Two weeks after the July 26 incident, AnMed was still dealing with operational disruption, and as of Monday 10 facilities remained closed to appointments.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
cysecurity.news
Open sourcetherecord.media
Open sourcehookphish.com
Open sourceinfosecurity-magazine.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.