Skip to content
RansomwareOngoing

Ransomware attack forces South Carolina health system AnMed to close dozens of facilities (2026)

AnMed, a nonprofit health system in upstate South Carolina, said a malware attack forced it to close more than 80 facilities, with the ransomware group The Gentlemen linked to the incident.

Victim
AnMed

On 26 July 2026, AnMed β€” a nonprofit health system serving patients across upstate South Carolina and northeast Georgia β€” confirmed it had suffered "a cybersecurity disruption involving malware." The attack knocked out phone systems, internet access, and much of the organisation's network, and forced AnMed to close more than 80 of its facilities, including 83 AnMed Medical Group offices and its imaging services, the following day.

Impact on care

Hospital operations were significantly disrupted while AnMed worked to isolate affected systems and stand up manual workarounds. The closures of outpatient offices and imaging services pushed appointments and diagnostics off schedule for a health system that is a major provider in its region, illustrating how a single ransomware event can ripple across dozens of community care sites at once. Some facilities remained shut more than a week after the intrusion as recovery work continued.

Attribution and data theft

Although AnMed initially declined to name the perpetrators, the ransomware-as-a-service group The Gentlemen was linked to the attack; the group is understood to draw affiliates and operators from other established ransomware crews. In an aggressive extortion tactic, the actors hijacked the hospital system's Facebook page during its response. The group claimed to have exfiltrated a large volume of data β€” reported at several terabytes β€” including highly sensitive health records. AnMed's leadership later confirmed that patient health information had been compromised.

Why it matters

Healthcare remains one of the most heavily targeted sectors for ransomware precisely because downtime translates directly into patient-care disruption, giving attackers leverage. The AnMed case combines that operational pressure with a reputational assault β€” the hijacking of an official social-media channel β€” and the theft of some of the most sensitive categories of personal data, underscoring why regional health systems continue to be prime targets.

Timeline

  1. AnMed confirms a cybersecurity disruption involving malware that affects its phone systems, internet access, and network.

  2. AnMed closes 83 medical-group offices and its imaging services as it works to contain the attack; the ransomware group The Gentlemen is later linked to the incident.

Sources

  1. hipaajournal.comhttps://www.hipaajournal.com/anmed-closes-almost-80-facilities-while-it-grapples-with-cyberattack/
  2. therecord.mediahttps://therecord.media/ransomware-group-hijacks-hospital-facebook-amid-cyberattack-response
  3. healthcaredive.comhttps://www.healthcaredive.com/news/anmed-facilities-remain-closed-week-after-cyberattack/827160/
  4. bankinfosecurity.comhttps://www.bankinfosecurity.com/malware-attack-forces-anmed-to-close-care-facilities-a-32336

Related incidents