Healthcare technology company Veradigm disclosed that an unauthorized party used credentials stolen from a third-party vendor to access a customer-services API and download patient personal data belonging to a limited subset of customers. Some records contained Social Security numbers, but Veradigm said no clinical or medical information was exposed and that its internal network, servers, databases, and operations were not accessed or disrupted.
Veradigm activated its incident-response process, notified law enforcement, and is investigating the scope of the exposure while notifying affected individuals and offering credit monitoring where appropriate. The Gentlemen ransomware group claimed responsibility and alleged it holds 3.5 million patient records, though Veradigm has not attributed the intrusion or verified that claim.

See the actors and campaigns active against you right now.
5 events from the most recent confirmed update back to the earliest known activity.
Veradigm disclosed that stolen credentials from a third-party vendor were used to access a vendor-facing API and download patient personal data, including Social Security numbers in some records. The company said clinical or medical data and its broader internal systems were not accessed, and it initiated incident response, notified law enforcement, and began notifying affected parties and offering credit monitoring where appropriate.
The Gentlemen listed Veradigm on its leak site and claimed to hold 3.5 million patient records. Veradigm did not independently confirm the group’s claim or identify the attacker.
ESET reported that The Gentlemen was using an endpoint-detection-and-response killer named GentleKiller.
Check Point reported that a SystemBC proxy-malware botnet with more than 1,500 hosts was linked to an affiliate of The Gentlemen ransomware group.
The Gentlemen emerged as a double-extortion ransomware group combining data theft and encryption attacks.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
8 references tracked. Mallory keeps watching after this page renders.
hipaajournal.com
Open sourceteiss.co.uk
Open sourcecyberveille.ch
Open sourcetherecord.media
Open sourcecryptika.com
Open sourcecybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourcesec.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.