AnMed is investigating claims by the ransomware group The Gentlemen that it exfiltrated 6TB of sensitive patient data, including PHI, and other data during a cyberattack against the healthcare organization.
AnMed has not disclosed the name of the group responsible for the attack. The Gentlemen, however, has claimed responsibility and added AnMed to its dark web data leak site. The Gentlemen is identified as a ransomware-as-a-service group with affiliates and operators from other popular ransomware groups. The group has attacked several healthcare entities in recent months and remains very active.
An Industrial Ransomware Analysis from Dragos identified The Gentlemen as the third most active ransomware group during Q2 2026. The group claimed 125 attacks during the quarter, compared with 83 attacks in Q1 2026. The increase was the largest among established ransomware groups.
Claims of Sensitive Data Exfiltration
The Gentlemen posted a message on AnMed’s Facebook page on August 11, 2026 claiming that confidential data had been exfiltrated. The claim states that 6TB of stolen data related to HIV-positive patients, mental health, sexual assault and rape victims, suicide registries, abortions, genetic data, patient Social Security numbers and birth dates, autopsy and police evidence. Payment is required to delete the data. The message has since been deleted. AnMed posted on August 11, 2026 that it had identified unauthorized posts on its social media accounts. The claims made in those posts were not verified and were being investigated.
The extent of any data theft has not been established. AnMed stated that determining the full extent of any data theft could take time. If the attacker’s claims are established as accurate, AnMed said it will provide appropriate notifications and release additional information as it becomes available.
AnMed System Recovery
AnMed previously stated that its main priority was ensuring patient safety while investigating the attack and working to restore affected systems safely and securely. AnMed has continued its recovery and has reopened most of its facilities. Eleven facilities remained closed at the time of the report.
The patient portal has been partly restored. Patients who have an active MyChart account and a registered mobile number can log in to view their health information, although some MyChart features remain unavailable. An additional security text message verification step has been added for patients logging into MyChart. Phone lines have also been restored, allowing patients to call their physicians and other departments directly.
Read and write access to patients’ electronic health records has also been restored. Care teams can view and update patient medical records. The recovery of patient access to health information represents another step in restoring services affected by the attack.