Attackers took over AnMed's page and told patients directly what they claimed to be holding, bypassing every channel the health system controlled.
What happened
Messages claiming to come from The Gentlemen ransomware group appeared on AnMed's Facebook page on the morning of August 11, 2026, repeating across roughly half an hour before Facebook took the page down, The Record reported. AnMed is a nonprofit system running four hospitals and clinics across South Carolina and Georgia. The posts claimed six terabytes of exfiltrated data and listed categories including records tied to sexual assault, mental health, abortion, and sexual harassment cases. No evidence accompanied the claims. AnMed removed the content, disabled access to the platform, and said it had not verified the assertions.
Going deeper
AnMed identified a malware incident on July 26 that knocked out internet, phone lines, and network access across its facilities, and ten sites remained closed to appointments as of August 10, according to Becker's Hospital Review. The health system had already warned patients on July 30 about a related problem, telling them that appointment reminders generated outside its internal systems might still arrive by text and that no electronic confirmation was required. Patients were therefore receiving messages the organization could not fully account for, then watching extortion demands appear on its official page, even though the system had not confirmed whether patient data was involved at all.
What was said
"Earlier today, AnMed identified unauthorized posts on its social media accounts," the health system said in a statement, adding that the content was removed, platform access was disabled, and it was working with the provider to secure the accounts, as reported by Fox Carolina. AnMed said the claims in the posts had not been verified and that its cybersecurity specialists were investigating as part of the response to the July 26 incident, and that it would notify individuals if the investigation established that personal information was affected.
In the know
The Gentlemen emerged in the second half of 2025 and has become one of the more prolific ransomware-as-a-service operations since, The Record noted. Its origins sit in a dispute rather than a founding, since the operators split from an established ransomware program after a public arbitration complaint over roughly $48,000 in unpaid commission. The group runs a double extortion model, stealing data before encrypting it, and its victim count climbed sharply through 2026. Hijacking a victim's social media accounts is a departure from the standard leak site approach, and it works on a different pressure point, since the audience becomes patients and local media rather than the organization's negotiators.
The big picture
Communication channels belong on the incident response inventory, and most organizations have never put them there. A health system running a cyberattack response depends on its website, its social accounts, and its text messaging platform to tell patients which clinics are open and what to ignore. Losing control of one of those turns the organization's own voice into the attacker's, at the precise moment patients are looking for authoritative information. Practical steps sit with whoever administers those accounts rather than with the security team, covering which staff hold access, whether those accounts use phishing-resistant authentication separate from the corporate directory, and who can reach the platform's support channel out of hours. Deciding in advance where an organization will post if its primary channels are compromised is worth more during an incident than any statement drafted afterward.
FAQs
Does an unverified extortion claim create notification obligations?
No. Notification duties turn on whether protected health information was accessed or acquired, established through the organization's own investigation rather than an attacker's assertion. Claims about volume and content are routinely inflated, and organizations should avoid confirming figures they have not verified.
How do attackers reach a corporate social media account?
Usually through credentials belonging to a marketing or communications staff member, harvested during the same intrusion or through separate phishing. These accounts often sit outside single sign-on and multifactor requirements because they are administered by departments rather than IT.
What should a health system tell patients during an incident like this?
Which services are running, which are not, what communications to expect, and what to disregard, published through a channel the organization has confirmed it still controls. Silence gets filled by the attacker's version, which is what happened here.
Why would a group name categories like sexual assault and mental health records?
The categories are chosen for pressure rather than accuracy, since disclosure of those records causes disproportionate harm and the prospect alarms patients and local media immediately. Naming them costs the attacker nothing whether or not the data exists.
Should an organization respond publicly to attacker claims?
Confirming or denying specifics before the investigation supports either creates problems in both directions. Most organizations state that claims are unverified, that an investigation is underway, and that notifications will follow if warranted, which is the position AnMed took.
