Analyst assessment
AnMed experienced a ransomware incident beginning July 26, 2026, when malware disrupted its network and affected patient care across the health system’s South Carolina and Georgia footprint. AnMed’s initial notice said cybersecurity specialists and state and federal authorities were assisting with response and restoration.
AnMed’s Aug. 27 data-security notice says a computer virus locked access to files on its network and that files on certain systems were copied without permission. A confidential source working inside AnMed shared a photograph of a ransom demand displayed on a hospital computer, together with victim-specific access to a private negotiation server identified by the source as Interlock. The demand imposed a 72-hour deadline and threatened publication. Taken together, the confirmed file locking and ransom-demand evidence establish ransomware involvement.
The notice says AnMed’s electronic health records were primarily stored in a separate cloud environment that was not affected. It says some patient-care files may have been stored locally and may include names, contact and demographic details, dates of birth, Social Security numbers, government identifiers, clinical information, insurance information, financial account numbers and payment card numbers. Those are possible contents under review, not confirmed categories in every copied file.
Attribution assessment
Attribution remains disputed. Victim-specific access to the negotiation server supports medium-confidence attribution to Interlock. Amazon threat intelligence has documented Interlock’s use of organization identifiers and private Tor negotiation chats, features consistent with the AnMed evidence.
The Gentlemen separately listed AnMed in a public leak index Aug. 9. Gentlemen-branded messages then appeared through AnMed’s compromised social-media presence Aug. 11, claiming 6 terabytes of exfiltration and highly sensitive medical and identifying information. AnMed confirmed the unauthorized posts but did not validate the actor, volume or claimed categories.
AnMed’s finding that files were copied is consistent with both operations’ extortion narratives but does not resolve who was responsible. No public evidence establishes a relationship between Interlock and The Gentlemen or explains the conflicting attribution signals.
Operational significance
The incident disrupted health care delivery across AnMed’s regional network. Numerous outpatient, imaging and specialty locations closed or operated with limitations, procedures were delayed, some patients were diverted and staff used paper or other downtime workflows while phones, internet access, computers, electronic records and MyChart were unavailable. Emergency departments and selected urgent-care, laboratory and therapy services remained available.
Recovery occurred in stages. AnMed said Aug. 11 that care teams had regained full read/write access to electronic health records. Direct office and department phone service resumed Aug. 12, and patients with active accounts and mobile numbers on file regained access to MyChart, although not all portal features were available.
Current status
The operational incident is resolved. AnMed said Aug. 27 that its computer network had been securely restored. The data review, patient notifications and related follow-up remain ongoing, but those activities do not by themselves establish continuing service disruption.
Aug. 21 remains the latest documented operational-impact date. AnMed’s FAQ that day said provider messaging through MyChart, post-July 26 portal test results and some medical-record functions remained unavailable. Imaging teams were rescheduling patients, the Fant Street laboratory remained closed, other laboratories required printed orders, and the AnMed Federal Credit Union’s regular phone lines remained down.
Confidence and uncertainty
Confidence is high that malicious activity caused material disruption because AnMed confirmed the virus, network impairment and service changes. Ransomware is confirmed by the combination of AnMed’s file-locking finding and the ransom demand with victim-specific negotiation access. Interlock attribution confidence remains medium because AnMed and authorities have not named an actor and the Gentlemen claim remains material contrary evidence.
File copying is confirmed. The copied-file contents and affected-person count remain under review. AnMed says the cloud-hosted electronic health record environment was unaffected, but locally stored patient-care files may contain sensitive identifying, clinical, insurance and financial information.
Analytic gaps
The public record does not establish the initial access vector, malware build, compromised account or host, intrusion start, dwell time, file-locking implementation, affected backups or exact restoration date. It also does not establish the copied-data volume, confirmed data categories, affected-person count; the relationship, if any, between Interlock and The Gentlemen; the validity of the claimed 6-terabyte volume; the demand amount; the negotiation outcome; payment; or public data release.