On August 11, 2026, patients following AnMed on Facebook saw an extortion note.

The nonprofit health system — four hospitals and a network of clinics serving upstate South Carolina and northeast Georgia — had been dealing with a cyberattack for more than two weeks. The Gentlemen ransomware group, unsatisfied with the pace of negotiation, took control of AnMed’s social media accounts and published its demands where the health system’s own patients would read them.

The post claimed 6TB of exfiltrated data. The categories it listed were chosen for maximum coercive pressure: HIV-positive patient lists, suicide registries, sexual assault and rape victim records, mental health files, abortion records, genetic data, patient Social Security numbers and dates of birth, autopsy reports and police evidence.

It ended with two words: “Deletion on payment.”

AnMed removed the posts, disabled account access and said it is investigating. The health system’s position on the substance is unchanged: the claims have not been verified, and AnMed “has not confirmed the scope of any potential impact to patient information.”

The group provided no evidence to support the 6TB claim.

The Timeline

  • July 26, 2026 — AnMed confirms “a cybersecurity disruption involving malware”
  • July 27, 202683 of AnMed’s 106 facilities close
  • July 30, 2026 — AnMed warns patients about unauthorized appointment reminder messages
  • August 10, 2026 — 15 days in, facilities are still closed
  • August 11, 2026 — The Gentlemen hijack AnMed’s Facebook page
  • August 13, 202611 facilities remain closed; patient portal partially restored, phone lines back, read/write EHR access restored

Through the outage AnMed operated under established downtime procedures. Emergency departments continued accepting patients. Elective procedures were postponed, and some patient transfers and diversions stayed in effect.

Closing 78% of your facilities is not a downtime procedure. It is a shutdown with a clinical triage attached.

Extortion Through the Victim’s Own Audience

Ransomware groups have spent three years escalating the pressure channel. Leak sites came first, then countdown timers, then emails to customers, then calls to journalists, then regulatory complaints filed against the victim on the victim’s behalf.

Hijacking the victim’s verified social media account is a further step, and it works for a specific reason: it collapses the distance between the extortion demand and the people whose data is at stake. A leak-site listing reaches security researchers. A post on AnMed’s Facebook page reaches the patients in Anderson County who are wondering why their appointment was cancelled.

The data categories in the post were selected on the same logic. Nobody lists autopsy reports and suicide registries because they are commercially valuable. They are listed because a health system reading that list has to imagine explaining it to the individuals named in it.

Whether The Gentlemen actually hold 6TB of that data is unproven, and the group’s incentive to overstate is total. But the asymmetry favors the attacker either way. AnMed cannot rebut the claim without completing a forensic review it has not finished, and every day it says “unverified” reads to a frightened patient as evasion.

What We Know About The Gentlemen

This is not an unfamiliar group here. The Gentlemen operate as ransomware-as-a-service, with affiliates and operators drawn from other established crews — a staffing model that makes their tradecraft inconsistent and their targeting opportunistic.

We covered the leak of their backend infrastructure by Check Point in May, which exposed the internals of their affiliate panel. In June, Krebs attributed the operation to Yapaev. Later that month they hit South Texas Spinal Clinic and Soniva Dental — smaller healthcare targets, same sector focus.

AnMed is a significant escalation in target size for them. It is also consistent: healthcare, mid-market to regional, US southeast, and a victim whose operational fragility guarantees the attack produces visible public consequences within days.

Their affiliate structure being publicly exposed in May did not slow them down. That is worth noting for anyone who believes infrastructure leaks are a meaningful disruption mechanism against RaaS operations.

The Categories Are the Point

If any part of the 6TB claim is accurate, the specific data types matter beyond the usual identity-theft calculus.

A Social Security number can be monitored, frozen and eventually replaced. An HIV diagnosis, a record of a sexual assault examination, a psychiatric admission, an abortion — those are permanent facts about a person that carry legal, employment, family and physical-safety consequences depending on where that person lives and who learns them. There is no credit-monitoring product for the disclosure of a suicide attempt.

We made this same argument about the market in stolen therapy records: the harm model that healthcare breach response is built around — fraud, monitoring, remediation — does not fit this data at all. AnMed will offer credit monitoring. It will be the correct standard response and it will be almost entirely beside the point for the patients whose records are actually in the archive, if the archive exists.

Where This Sits

Two weeks of degraded operations, 83 facilities closed at peak, 11 still closed at 18 days, an unverified 6TB claim, and an extortion note published on the health system’s own Facebook page.

AnMed’s handling of the operational side has been credible — downtime procedures held, emergency departments stayed open, restoration is progressing in a sensible order. The information side is where it is losing. The gap between “we have not confirmed the scope” and a specific, graphic list of data categories posted to the patients themselves is a gap the attacker chose deliberately, and the only thing that closes it is a completed forensic determination AnMed does not yet have.

That is the position every ransomware victim in healthcare now finds itself in, and the groups have figured out how to sit in it.

Sources