AnMed has confirmed that patient health information was compromised during the cyberattack that disrupted the South Carolina healthcare system in late July. In a new video statement, AnMed CEO William Kinley acknowledged that cybercriminals gained access to information during the malware attack on the organisation's IT infrastructure.
The healthcare system is still working with cybersecurity specialists to determine exactly what information was taken and which patients may have been affected.
The attack has also continued to disrupt normal operations as AnMed's technical teams work to restore systems.
AnMed Says Attack Was Financially Motivated
Kinley described the incident as a deliberate attack carried out by cybercriminals seeking financial gain.
The incident began on 26 July 2026, forcing AnMed to shut down parts of its technology environment while investigators and security specialists assessed the damage.
Although AnMed has not officially identified the attackers, a ransomware operation known as The Gentlemen previously claimed responsibility.
The group reportedly gained access to one of AnMed's social-media pages on 11 August and published a message claiming it had stolen sensitive patient information.
The post threatened to release information that could potentially include Social Security numbers, home addresses and medical records.
It also claimed possession of particularly sensitive healthcare information involving reproductive health, paediatric care, psychiatric treatment and sexual-assault records.
However, AnMed has not yet independently confirmed the full extent of those claims.
Investigation Into Stolen Data Is Still Ongoing
AnMed says cybersecurity experts are conducting a detailed review to determine exactly what information left its systems.
This can be a lengthy process.
Healthcare organisations typically store enormous amounts of information across electronic medical records, billing systems, administrative databases and other applications.
Investigators therefore need to determine which systems attackers reached, which files were accessed and whether those files contained personal or protected health information.
Only after that review can the health system accurately identify affected individuals.
Kinley said AnMed intends to contact people directly once the investigation determines whose information was compromised.
He also explained that the complexity of the investigation was one reason the organisation had provided relatively limited information since the systems were initially taken offline.
Healthcare Services Have Continued Despite the Disruption
AnMed's IT teams and external security advisers are still working to restore affected systems and return the organisation to normal operations.
Healthcare ransomware incidents can be particularly disruptive because hospitals rely heavily on digital systems for almost every part of patient care.
Electronic medical records contain medication lists, laboratory results, imaging information, clinical histories and treatment plans.
Scheduling, billing, pharmacy systems and communication platforms may also depend on the same infrastructure.
When those systems become unavailable, staff may need to switch to slower manual procedures.
Despite the attack, Kinley said AnMed employees have worked to keep healthcare services available to patients and families throughout the region.
He characterised the incident as an attack affecting the entire community rather than only the organisation's computers.
The Gentlemen Has Become a Significant Ransomware Operation
The incident comes as cybersecurity researchers increasingly track The Gentlemen as a major ransomware group.
According to an August report from security research company Comparitech, the operation had claimed responsibility for 675 ransomware attacks, including more than 600 by the end of July.
Of those, 126 reportedly involved organisations in the United States.
That placed the group behind only Qilin among the ransomware operations tracked in the report.
Comparitech estimates that confirmed attacks attributed to The Gentlemen have exposed more than 787,000 records since the group emerged late last year.
Healthcare has also been a significant target.
The group reportedly claimed 36 attacks involving healthcare providers, although only a portion of those incidents had been independently confirmed at the time of the report.
Healthcare Organisations Remain Attractive Targets
Hospitals and medical organisations are particularly valuable targets for ransomware groups because of the sensitivity of the information they hold.
Medical records can contain far more than basic contact information.
They may include diagnoses, medications, insurance information, financial details and highly personal medical histories.
That makes stolen healthcare data potentially useful for identity theft, fraud, extortion and other criminal activity.
Hospitals are also under enormous pressure to restore systems quickly because prolonged downtime can interfere with patient care.
Attackers understand this.
That combination of valuable data and operational urgency makes healthcare organisations attractive targets for financially motivated ransomware groups.
Modern Ransomware Is About More Than Encrypting Files
Older ransomware attacks often centred almost entirely on encryption.
Attackers would lock an organisation's systems and demand payment for the decryption key.
Modern ransomware groups increasingly use a different strategy known as double extortion.
Before encrypting systems, attackers first steal large quantities of data.
This gives them a second way to pressure the victim.
Even if an organisation can restore everything from backups and does not need a decryption key, criminals can still threaten to publish or sell the stolen information.
Comparitech's Rebecca Moody noted that many ransomware groups now deliberately steal data before beginning the encryption phase.
That gives attackers multiple opportunities to profit from the same intrusion.
Patients Can Become Direct Targets
The AnMed incident also demonstrates another disturbing evolution in ransomware tactics.
Earlier in August, AnMed warned that some patients had reportedly received suspicious communications attempting to arrange fraudulent payments.
Directly contacting patients gives criminals another possible avenue for making money from stolen information.
Instead of only demanding payment from the hospital, attackers may potentially target the people whose data was compromised.
Someone with access to a patient's name, contact information and medical details may be able to create highly convincing scams.
A fraudulent message could pretend to come from the healthcare provider and reference enough real information to appear legitimate.
That is why patients affected by healthcare breaches need to be especially cautious about unexpected phone calls, text messages and emails.
Do Not Trust Unexpected Payment Requests
Patients should be wary of anyone unexpectedly claiming to represent a hospital and demanding immediate payment or asking for sensitive personal information.
Even if the caller appears to know details about a recent appointment or medical service, that does not necessarily prove they are legitimate.
If something seems suspicious, patients should independently contact the healthcare organisation using the phone number published on its official website or existing medical documents.
Avoid relying on contact details supplied inside the suspicious message itself.
Passwords should also be changed if there is reason to believe an account may have been exposed, particularly if the same password is reused across other services.
Monitoring financial accounts and credit reports may also be appropriate once AnMed provides more information about exactly which categories of data were compromised.
Attackers Are Exploiting Known Vulnerabilities
Researchers tracking The Gentlemen say affiliates associated with the group have also been targeting recently discovered vulnerabilities.
These reportedly include a security flaw affecting Erlang that can potentially enable remote code execution, along with an access-control weakness involving Windows SMB that could allow attackers to elevate privileges across a network.
This illustrates another common characteristic of modern ransomware campaigns.
Attackers do not always rely on previously unknown vulnerabilities.
Often they simply move quickly against organisations that have not yet patched publicly documented weaknesses.
Once a vulnerability becomes known, cybercriminals can scan the internet looking for exposed systems that remain outdated.
For healthcare organisations with large and complex IT environments, keeping every server, application and medical system updated can be challenging.
Unfortunately, attackers only need one overlooked entry point.
Why Healthcare Ransomware Is So Difficult to Stop
Healthcare networks are complicated.
Hospitals may operate thousands of endpoints, medical devices, servers and specialised applications.
Some equipment may depend on older operating systems because upgrading could affect regulatory approval or compatibility with medical hardware.
Remote access also needs to exist for clinicians, vendors and support teams.
All of this creates a much larger attack surface than an ordinary office environment.
Healthcare organisations therefore need multiple layers of defence.
That includes patching, network segmentation, multifactor authentication, endpoint protection, secure backups and continuous monitoring for suspicious behaviour.
But even strong security cannot guarantee that an organisation will never be compromised.
How quickly an attack is detected and how well the organisation can recover are equally important.
Stolen Data Remains Valuable Even When Ransoms Aren't Paid
Some governments and organisations have increasingly discouraged ransomware payments because they fund criminal operations and provide no guarantee that stolen information will actually be deleted.
However, refusing to pay does not eliminate the attackers' ability to profit.
Stolen information can still be sold, leaked or used to target individuals with fraud.
That is one reason ransomware remains financially attractive despite increased law-enforcement attention.
Attackers no longer depend entirely on convincing the original victim to pay.
They can potentially monetise the data in several different ways.
For healthcare organisations, this means protecting backups alone is no longer sufficient.
Preventing data exfiltration has become just as important as protecting systems from encryption.
Final Thoughts
AnMed's acknowledgement that patient information was compromised confirms that its July cyberattack was more than an IT outage.
The healthcare system is still determining exactly what information was stolen and who was affected, while its teams continue restoring systems and maintaining patient services.
The Gentlemen ransomware group has claimed responsibility, although AnMed has not formally attributed the incident to the operation.
For patients, the most important step now is to remain alert for official notifications from AnMed and to be extremely cautious about unexpected requests for payments or personal information.
The incident also highlights how ransomware continues to evolve.
Attackers are no longer simply locking computers and waiting for payment. They are stealing information first, threatening organisations with public disclosure and, increasingly, looking for ways to exploit the affected individuals directly.
In healthcare, where the stolen information can be extraordinarily personal, a ransomware attack can continue affecting patients long after hospital computers have been restored.


Comments 0