Ransomware group hijacks hospital system’s Facebook page amid ongoing cyberattack fallout
Two weeks after a cyberattack knocked out its IT systems, the nonprofit medical system AnMed is sti 2026-8-11 19:32:11 Author: therecord.media(查看原文) 阅读量:3 收藏

Two weeks after a cyberattack knocked out its IT systems, the nonprofit medical system AnMed is still facing closures and the apparent hack of its Facebook page, which on Tuesday began showing ransom demands from the purported hackers. 

The social media page for the medical chain, which has four hospitals and other clinics in Georgia and South Carolina, was removed from Facebook shortly after a series of messages claiming to be from “The Gentlemen” ransomware group appeared. 

The hackers claimed to have exfiltrated 6 terabytes of data, including highly sensitive health information like records related to sexual assault, mental health, abortions and sexual harassment incidents. They did not provide any evidence to back up these claims. On its website, AnMed still says it has not “confirmed the scope of any potential impact to patient information,” nor have they said if patient information was affected.

"Earlier today, AnMed identified unauthorized posts on its social media accounts. The unauthorized content was removed, access through the platform was disabled and we are working with the provider to secure the accounts," a spokesperson said in a statement, adding that the claims contained in the posts have not been verified. "AnMed and its cybersecurity specialists are investigating the matter as part of the organization’s ongoing response to the cybersecurity incident identified on July 26."

When the company announced the initial incident, it said it was “experiencing a cybersecurity disruption involving malware” and was working to restore systems. Since then, AnMed has made daily updates to a list of open and closed offices, and as of Monday 10 facilities remained closed to appointments.

The Gentlemen has become one of the most prolific ransomware-as-a-service groups since it emerged in the second half of 2025. It is believed to have been founded by a former affiliate of the Qilin ransomware group who uses the moniker “hastalamuerte.” 

According to the cybersecurity firm CheckPoint, its ransomware was used to extort 332 victims in the first five months of this year alone. In the second quarter of 2026, the group claimed 125 attacks on industrial organizations, the operational technology firm Dragos said — the third most among ransomware groups. 

Leaked internal files analyzed by CheckPoint showed that it has an unusually generous fee structure, with 90 percent of ransoms going to the affiliates who execute attacks. The hackers typically gain access through edge devices like firewalls, VPN appliances and other internet-facing systems. 

“They combine different methods to achieve this, including credential brute‑forcing against web or VPN panels, exploiting known vulnerabilities, and buying access from third‑party ‘bot’ or access brokers,” CheckPoint said. Once inside, they attempt to get access to administrator accounts and to disable security tools before exfiltrating data and deploying ransomware.  

The group also stands out for offering affiliates sophisticated tools to disable endpoint detection and response (EDR) technology. In one instance observed by the security firm Expel, the group abused a vulnerability in an “obscure” third-party vendor driver to disable the victim’s EDR. 

“What’s notable here isn’t the technique itself,” Expel researcher Marcus Hutchins wrote in June, “but the sophistication of the toolkit they’ve built around it.”

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

Recorded Future

No previous article

No new articles

James Reddick

James Reddick

has worked as a journalist around the world, including in Lebanon and in Cambodia, where he was Deputy Managing Editor of The Phnom Penh Post. He is also a radio and podcast producer for outlets like Snap Judgment.


文章来源: https://therecord.media/ransomware-group-hijacks-hospital-facebook-amid-cyberattack-response
如有侵权请联系:admin#unsafe.sh