ZeroHour
Story · 4 sources · 4 articlesfirst updated ()

Veradigm discloses patient data breach via stolen vendor API credentials as Gentlemen ransomware gang claims 3.5 million records

highData breachexploited in the wildimportance 78
What's new: Nothing substantively new relative to the previous summary: the four merged reports are consistent with prior coverage, with no source disagreement beyond the varying descriptions of the accessed API. Veradigm has still not confirmed the 3.5 million record count, and no report confirms whether the Gentlemen gang published the stolen data by the September 11 deadline or whether any ransom…
Merged summary · glm-5.3 · rewritten as coverage arrives

Electronic health records vendor Veradigm told the SEC that attackers used credentials stolen from a third-party vendor to download patient personal data including Social Security numbers through a limited API; the Gentlemen ransomware gang claims 3.5 million…

Veradigm (formerly Allscripts), an electronic health records company serving thousands of hospitals and doctors with $594M in 2024 revenue (The Record), filed a Form 8-K with the SEC on September 8, 2026 disclosing that an unauthorized party obtained credentials from a third-party vendor's environment and used them to access a limited Veradigm API, downloading patients' personal data including Social Security numbers for some individuals. Veradigm states no clinical or medical data was compromised, its internal infrastructure was not breached directly, access was confined to the API with no operational disruption, and it does not expect a material business impact. The company activated incident response, notified law enforcement, is notifying affected individuals, and is offering credit monitoring. Sources describe the accessed interface differently: a customer-service API (BleepingComputer), a vendor-facing API (Cyber Security News), a customer-facing API (The Record), and simply an API (The Register). The Gentlemen ransomware group added Veradigm to its leak site claiming theft of 3.5 million patient records — a gang claim, not a figure confirmed by Veradigm — and threatened to publish the data by September 11 unless ransom negotiations began. Per BleepingComputer, the gang has been active since mid-2025, runs double extortion across Windows, Linux, NAS, BSD and ESXi, lists 800+ victims in 86 countries, and is linked to a 1,500-host SystemBC proxy botnet and the GentleKiller EDR killer. No report confirms whether the data was published by the deadline or whether negotiations occurred. Context from The Record: Veradigm was previously hit by SamSam ransomware in 2019 and disclosed a December 2024 breach affecting 2,672,036 people; the incident comes amid a healthcare breach wave including Aesto (9 million), Baylor Genetics (2.8 million) and CareCloud (3.7 million). In related coverage (The Register), Have I Been Pwned added records leaked by ShinyHunters from medical supplier McKesson confirming its August 2026 attack affected roughly 6.4 million people, with leaked data including names, email and physical addresses, dates of birth, phone numbers, employer details and sensitive health information; ShinyHunters claimed SSNs and 284 million documents were stolen and issued a $55.2 million extortion demand that was apparently unpaid — though HIBP found no SSNs, a source disagreement. Boston Scientific separately expects to miss Q3 sales and earnings…

  • Veradigm filed a Form 8-K with the SEC on September 8, 2026 disclosing the breach.
  • Attackers used credentials stolen from a third-party vendor's environment to access a limited Veradigm API and download patient data.
  • Exposed data includes Social Security numbers and personal details for some individuals; Veradigm states no clinical or medical data was compromised.
  • Veradigm's internal infrastructure was not breached directly; there was no operational disruption and no expected material business impact.
  • The Gentlemen ransomware gang claims 3.5 million patient records stolen and set a September 11 publication deadline unless ransom negotiations began — unconfirmed by Veradigm.
  • Sources describe the accessed API differently: customer-service (BleepingComputer), vendor-facing (Cyber Security News), customer-facing (The Record), unspecified (The Register).
  • The Gentlemen gang, active since mid-2025, runs double extortion across Windows, Linux, NAS, BSD and ESXi, lists 800+ victims in 86 countries, and is linked to a 1,500-host SystemBC proxy botnet and GentleKiller EDR killer.
  • Veradigm activated incident response, notified law enforcement, is notifying affected individuals and offering credit monitoring.

Coverage timeline

  1. · 6d ago
    BleepingComputer· 76
    Veradigm warns of patient data breach after ransomware gang claims attack

    Healthcare vendor Veradigm disclosed a patient data breach via a third-party vendor's credentials, which the Gentlemen ransomware gang claims involved 3.5 million records.

  2. · 6d ago
    Cyber Security News· 55
    Veradigm Confirms Patient Data Exposed in Third-Party Data Breach

    Veradigm disclosed a third-party vendor breach exposing patient data including Social Security numbers via stolen vendor API credentials.

  3. · 6d ago
    The Record· 78
    Electronic health record company says customer data stolen in breach

    Veradigm disclosed that attackers used stolen vendor credentials via an API to steal patient data including Social Security numbers, as the Gentlemen ransomware gang claims 3.5 million patients' records.

  4. · 5d ago
    The Register · Security· 78
    ShinyHunters expose 6.4M in attack on medical supplier McKesson

    ShinyHunters leaked stolen McKesson data exposing roughly 6.4 million individuals after the medical supplier reportedly declined a $55.2 million extortion demand.