ZeroHour
The Recordpublished ()ingested

Ransomware group hijacks hospital system’s Facebook page amid ongoing cyberattack fallout

highRansomware exploited in the wildimportance 58
AI summary · glm-5.3-flash

'The Gentlemen' ransomware group hijacked AnMed's Facebook page, claiming theft of 6TB of sensitive patient data during an ongoing cyberattack on the hospital system.

AnMed, a nonprofit medical system with four hospitals in Georgia and South Carolina, is still responding to a July 26 cyberattack involving malware, with 10 facilities remaining closed as of Monday. On Tuesday its Facebook page displayed unauthorized posts claiming 'The Gentlemen' ransomware group exfiltrated 6 terabytes of data, including records on sexual assault, mental health, abortions and harassment; AnMed said the claims are unverified and patient data impact has not been confirmed. The Gentlemen, believed founded by a former Qilin affiliate using the moniker 'hastalamuerte,' extorted 332 victims in the first five months of 2026 per CheckPoint and claimed 125 industrial attacks in Q2 2026 per Dragos. The group typically breaches networks through edge devices, credential brute-forcing and known vulnerabilities, and offers affiliates tools to disable EDR.

  • AnMed's Facebook page showed ransom demands from 'The Gentlemen' group.
  • Hackers claim 6TB exfiltrated; AnMed has not verified patient data impact.
  • 10 facilities remained closed two weeks after the July 26 incident.
  • The Gentlemen extorted 332 victims in five months, per CheckPoint.
  • Group gains access via edge devices, brute-forcing and known vulnerabilities.
Full article567 words · extracted from therecord.media · click to collapse

Two weeks after a cyberattack knocked out its IT systems, the nonprofit medical system AnMed is still facing closures and the apparent hack of its Facebook page, which on Tuesday began showing ransom demands from the purported hackers. 

The social media page for the medical chain, which has four hospitals and other clinics in Georgia and South Carolina, was removed from Facebook shortly after a series of messages claiming to be from “The Gentlemen” ransomware group appeared. 

The hackers claimed to have exfiltrated 6 terabytes of data, including highly sensitive health information like records related to sexual assault, mental health, abortions and sexual harassment incidents. They did not provide any evidence to back up these claims. On its website, AnMed still says it has not “confirmed the scope of any potential impact to patient information,” nor have they said if patient information was affected.

"Earlier today, AnMed identified unauthorized posts on its social media accounts. The unauthorized content was removed, access through the platform was disabled and we are working with the provider to secure the accounts," a spokesperson said in a statement, adding that the claims contained in the posts have not been verified. "AnMed and its cybersecurity specialists are investigating the matter as part of the organization’s ongoing response to the cybersecurity incident identified on July 26."

When the company announced the initial incident, it said it was “experiencing a cybersecurity disruption involving malware” and was working to restore systems. Since then, AnMed has made daily updates to a list of open and closed offices, and as of Monday 10 facilities remained closed to appointments.

The Gentlemen has become one of the most prolific ransomware-as-a-service groups since it emerged in the second half of 2025. It is believed to have been founded by a former affiliate of the Qilin ransomware group who uses the moniker “hastalamuerte.” 

According to the cybersecurity firm CheckPoint, its ransomware was used to extort 332 victims in the first five months of this year alone. In the second quarter of 2026, the group claimed 125 attacks on industrial organizations, the operational technology firm Dragos said — the third most among ransomware groups. 

Leaked internal files analyzed by CheckPoint showed that it has an unusually generous fee structure, with 90 percent of ransoms going to the affiliates who execute attacks. The hackers typically gain access through edge devices like firewalls, VPN appliances and other internet-facing systems. 

“They combine different methods to achieve this, including credential brute‑forcing against web or VPN panels, exploiting known vulnerabilities, and buying access from third‑party ‘bot’ or access brokers,” CheckPoint said. Once inside, they attempt to get access to administrator accounts and to disable security tools before exfiltrating data and deploying ransomware.  

The group also stands out for offering affiliates sophisticated tools to disable endpoint detection and response (EDR) technology. In one instance observed by the security firm Expel, the group abused a vulnerability in an “obscure” third-party vendor driver to disable the victim’s EDR. 

“What’s notable here isn’t the technique itself,” Expel researcher Marcus Hutchins wrote in June, “but the sophistication of the toolkit they’ve built around it.”

No previous article

No new articles

James Reddick

has worked as a journalist around the world, including in Lebanon and in Cambodia, where he was Deputy Managing Editor of The Phnom Penh Post. He is also a radio and podcast producer for outlets like Snap Judgment.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/ransomware-group-hijacks-hospital-facebook-amid-cyberattack-response