Skip to content

AnMed ransomware disrupts systems and patient care

Summary

AnMed logo

A ransomware incident beginning July 26, 2026, disrupted AnMed’s network and patient care across South Carolina and Georgia. AnMed now says a virus locked access to network files, files were copied without permission and its network was securely restored; its review of potentially affected patient information continues. Victim-specific negotiation access supports medium-confidence Interlock attribution, but a conflicting Gentlemen claim remains unresolved.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Malware

    Malicious software other than ransomware used to compromise or disrupt systems.

  • Ransomware

    Malware that encrypts systems or data, typically accompanied by a ransom demand.

  • Data extortion

    Threats to publish or sell stolen data without evidence of encryption.

  • Credential compromise

    Theft, exposure, or abuse of user or administrator credentials.

Data impacts

  • Data theft or exfiltration

    Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.

  • Data encryption

    Data was rendered inaccessible through unauthorized encryption, including ransomware-related encryption.

  • Data unavailable

    Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.

Operational impacts

  • Healthcare operations disrupted

    Clinical, diagnostic, pharmacy, patient-care, medical-record, or other healthcare operations were materially affected.

  • Facility closure

    One or more offices, schools, clinics, stores, plants, branches, or other facilities closed because of the incident.

  • Network outage

    Internal or external network connectivity was unavailable or materially impaired.

  • Internet access disruption

    The organization lost or materially restricted internet connectivity.

  • Phone service disruption

    Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.

  • Service delay

    Services continued but with longer processing, response, delivery, or completion times.

  • Online portal unavailable

    A public, customer, employee, student, patient, vendor, or partner portal was unavailable or materially impaired.

  • Records access disruption

    Staff, customers, patients, students, residents, or other users could not access records or case information normally.

  • Records processing disruption

    The organization could not create, update, search, file, approve, transmit, or otherwise process records normally.

  • Scheduling disruption

    Appointment, booking, reservation, dispatch, staffing, or other scheduling functions were unavailable or impaired.

  • Event or activity cancellation

    Scheduled events, meetings, hearings, classes, procedures, programs, or other activities were canceled.

  • Manual workaround required

    Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.

  • Alternate service channel required

    The organization redirected users to a different website, office, telephone number, email address, provider, or service channel.

  • Staff unable to work normally

    Employees or contractors were unable to perform normal duties because systems, data, facilities, or communications were unavailable.

  • Customer or public access restricted

    Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.

Extortion indicators

  • Countdown or payment deadline

    The actor imposed a deadline or public countdown before increasing the demand, publishing data, deleting keys, or taking another threatened action.

  • Ransom demand

    The victim received a demand for payment in exchange for restoring access, decrypting systems, preventing disclosure, or stopping another threatened action.

  • Encryption-based extortion

    The extortion activity involved unauthorized encryption of systems or data, with restoration or decryption conditioned on payment.

  • Data-theft extortion

    The actor threatened to disclose, sell, distribute, or otherwise misuse stolen data unless the victim paid or complied with demands.

  • Public leak threat

    The actor explicitly threatened to publish or publicly release victim data or incident details.

  • Direct victim contact

    The actor directly contacted the victim through a ransom note, email, chat portal, telephone call, messaging platform, or other communication channel.

  • Third-party pressure

    The actor contacted customers, employees, partners, regulators, media organizations, or other third parties to pressure the victim.

  • Negotiation portal or ransom chat

    A dedicated portal, chat system, or communication channel was used for ransom negotiation or victim instructions.

Incident narrative

Analyst assessment

AnMed experienced a ransomware incident beginning July 26, 2026, when malware disrupted its network and affected patient care across the health system’s South Carolina and Georgia footprint. AnMed’s initial notice said cybersecurity specialists and state and federal authorities were assisting with response and restoration.

AnMed’s Aug. 27 data-security notice says a computer virus locked access to files on its network and that files on certain systems were copied without permission. A confidential source working inside AnMed shared a photograph of a ransom demand displayed on a hospital computer, together with victim-specific access to a private negotiation server identified by the source as Interlock. The demand imposed a 72-hour deadline and threatened publication. Taken together, the confirmed file locking and ransom-demand evidence establish ransomware involvement.

The notice says AnMed’s electronic health records were primarily stored in a separate cloud environment that was not affected. It says some patient-care files may have been stored locally and may include names, contact and demographic details, dates of birth, Social Security numbers, government identifiers, clinical information, insurance information, financial account numbers and payment card numbers. Those are possible contents under review, not confirmed categories in every copied file.

Attribution assessment

Attribution remains disputed. Victim-specific access to the negotiation server supports medium-confidence attribution to Interlock. Amazon threat intelligence has documented Interlock’s use of organization identifiers and private Tor negotiation chats, features consistent with the AnMed evidence.

The Gentlemen separately listed AnMed in a public leak index Aug. 9. Gentlemen-branded messages then appeared through AnMed’s compromised social-media presence Aug. 11, claiming 6 terabytes of exfiltration and highly sensitive medical and identifying information. AnMed confirmed the unauthorized posts but did not validate the actor, volume or claimed categories.

AnMed’s finding that files were copied is consistent with both operations’ extortion narratives but does not resolve who was responsible. No public evidence establishes a relationship between Interlock and The Gentlemen or explains the conflicting attribution signals.

Operational significance

The incident disrupted health care delivery across AnMed’s regional network. Numerous outpatient, imaging and specialty locations closed or operated with limitations, procedures were delayed, some patients were diverted and staff used paper or other downtime workflows while phones, internet access, computers, electronic records and MyChart were unavailable. Emergency departments and selected urgent-care, laboratory and therapy services remained available.

Recovery occurred in stages. AnMed said Aug. 11 that care teams had regained full read/write access to electronic health records. Direct office and department phone service resumed Aug. 12, and patients with active accounts and mobile numbers on file regained access to MyChart, although not all portal features were available.

Current status

The operational incident is resolved. AnMed said Aug. 27 that its computer network had been securely restored. The data review, patient notifications and related follow-up remain ongoing, but those activities do not by themselves establish continuing service disruption.

Aug. 21 remains the latest documented operational-impact date. AnMed’s FAQ that day said provider messaging through MyChart, post-July 26 portal test results and some medical-record functions remained unavailable. Imaging teams were rescheduling patients, the Fant Street laboratory remained closed, other laboratories required printed orders, and the AnMed Federal Credit Union’s regular phone lines remained down.

Confidence and uncertainty

Confidence is high that malicious activity caused material disruption because AnMed confirmed the virus, network impairment and service changes. Ransomware is confirmed by the combination of AnMed’s file-locking finding and the ransom demand with victim-specific negotiation access. Interlock attribution confidence remains medium because AnMed and authorities have not named an actor and the Gentlemen claim remains material contrary evidence.

File copying is confirmed. The copied-file contents and affected-person count remain under review. AnMed says the cloud-hosted electronic health record environment was unaffected, but locally stored patient-care files may contain sensitive identifying, clinical, insurance and financial information.

Analytic gaps

The public record does not establish the initial access vector, malware build, compromised account or host, intrusion start, dwell time, file-locking implementation, affected backups or exact restoration date. It also does not establish the copied-data volume, confirmed data categories, affected-person count; the relationship, if any, between Interlock and The Gentlemen; the validity of the claimed 6-terabyte volume; the demand amount; the negotiation outcome; payment; or public data release.

Threat actors and claims

Listed as: AnMedSource: ransomware.livePublished: Discovered:

Claim details

Ransomware.live indexed an AnMed entry attributed to The Gentlemen, listing anmed.org and a publication time of Aug. 9. Gentlemen-branded messages later appeared through AnMed’s compromised social-media presence, linking to thegentlemen.st and claiming full network access and 6 terabytes of highly sensitive medical, identity, reproductive-health, behavioral-health, forensic and sexual-assault records. The messages offered samples and promised deletion and confidentiality in exchange for cooperation and payment.

AnMed confirmed that unauthorized posts appeared on its social-media accounts. Its Aug. 27 notice says a virus locked access to network files and files on certain systems were copied without permission, but it does not attribute the incident to The Gentlemen or validate the claimed volume, categories, encryption implementation or public release. Earlier victim-specific access to an Interlock negotiation server remains material contrary evidence.

Screenshot documenting The Gentlemen claim
Source: otherDiscovered:

Claim details

A confidential source working inside AnMed provided a photograph of a ransom demand displayed on a hospital screen, including a victim-specific Tor address for a negotiation chat server and a unique access code used to establish a negotiation account. The Tor address resolved to infrastructure associated with Interlock. The ransom note claims encryption and data theft, imposes a 72-hour deadline and threatens publication, but the visible text does not identify either AnMed or Interlock by name. The victim-specific negotiation infrastructure provides substantive evidence supporting medium-confidence attribution to Interlock.

That assessment is complicated by later, materially conflicting evidence. The Gentlemen subsequently listed AnMed on its leak site, and Gentlemen-branded messages were posted through AnMed’s compromised social-media accounts. AnMed’s Aug. 27 notice says a virus locked access to network files and files on certain systems were copied without permission, but it does not identify a threat actor or establish the encryption implementation.

The Tor address and negotiation code are withheld to protect private victim communications.

Screenshot documenting Interlock claim

Organizations involved

Impacted locations

  • Hartwell, Georgia

    AnMed Primary Care-Hartwell was closed, while AnMed Integrated Therapy-Hartwell was listed as open.

  • Anderson, South Carolina

    AnMed Medical Center, the North Campus and numerous specialty, primary care, pediatric, imaging and medical group locations are based here. Many were closed, outpatient infusion was limited, and the Medical Center emergency department remained open.

  • Clemson, South Carolina

    AnMed listed closed arrhythmia, cardiology, imaging, pediatric, primary care, pulmonary, surgical and specialty-care locations. Its Clemson laboratory and urgent care remained open.

  • Pickens, South Carolina

    AnMed Orthopedics and Sports Medicine-Pickens, Specialty Care-Pickens and Surgical-Pickens were closed. AnMed Cannon's emergency department and laboratory remained open.

  • Piedmont, South Carolina

    AnMed listed several Piedmont services as closed, including imaging, obstetrics and gynecology, occupational medicine, orthopedics, pediatrics, primary care and specialty care. The emergency department, laboratory and integrated therapy location remained open. AnMed Primary Care-Wren, with a Piedmont mailing address, was also closed.

Sources

AnMed malware disruption closes clinics and imaging services

Our reporting documented that AnMed confirmed malware after a systemwide phone and internet outage. Numerous outpatient, imaging and specialty locations were closed or limited while emergency departments and selected urgent, laboratory and therapy services remained available.

Amazon threat intelligence teams identify Interlock ransomware campaign targeting enterprise firewalls

Amazon threat intelligence attributed an observed campaign to Interlock and documented ransom notes and Tor negotiation portals consistent with Interlock branding and infrastructure. It described campaign-specific organization identifiers and pressure based on data-protection laws, features that align with the supplied AnMed-screen image but do not independently identify AnMed as a victim.

AnMed Systems Disruption

AnMed said malware was affecting its network and published a detailed list of closed, limited and open services across communities in South Carolina and Georgia while cybersecurity specialists and authorities assisted with response and restoration.

AnMed speaks out after outage, confirms malware caused disruption

FOX Carolina’s updated report said many AnMed computer systems remained offline July 30. A nurse described paper patient records, handwritten orders and results, slower laboratory, imaging and medication workflows, unavailable internal phones and staff use of personal cell phones; staff had not been told who was responsible.

AnMed given 72 hours to respond to demands in ransomware incident

Healthcare IT News described the system takedown as an apparent extortion attempt and reported that AnMed was given 72 hours to respond to demands while surgeries and other planned treatments were delayed.

AnMed Systems Disruption Update 02

AnMed said physician offices would reopen July 28 for scheduled appointments, but phones, internet and computers remained offline. Patients were asked to bring medication lists and confirm medical histories, urgent refills required in-person visits, and staff continued downtime procedures while forensic work remained in an early stage.

Service & Practice Openings and Closings: Fri., Jul. 31, 2026

AnMed’s July 31 service plan said most practices had reopened, but multiple imaging, cardiovascular diagnostic, laboratory, radiation-oncology, women’s diagnostic and related services remained closed, while outpatient infusion operated on a limited basis.

AnMed Systems Disruption Update 05

AnMed said open locations continued caring for patients, electronic appointment confirmation was not required, there was no evidence patients were being targeted through disruption-related communications, and teams were working around the clock to restore full secure access while investigations continued.

AnMed Systems Disruption Update 08

AnMed said temporary downtime procedures continued to delay requests, check-in, registration and documentation. Outpatient imaging remained closed, patients needed printed laboratory orders, some refills required in-person visits and temporary support lines were used for patient and billing questions.

AnMed Systems Disruption Update 10

AnMed said it was continuing work to fully restore systems and expanded patient-support-line hours through August 9 to assist patients who had difficulty reaching physician offices or had care questions.

International Cyber Digest post on AnMed Facebook compromise claim

International Cyber Digest reported that AnMed’s Facebook page was hijacked Aug. 11 to publish messages attributed to The Gentlemen. The post says the actor claimed 6 terabytes of data and listed highly sensitive patient and identity information; it says AnMed considered the claims unverified and 10 facilities remained closed Aug. 10. The attached image shows The Gentlemen branding and a link to thegentlemen.st.

Archive platform: Screenshot
AnMed Systems Disruption Update 11

AnMed said it identified unauthorized posts on its social-media accounts on August 11, removed the content and disabled platform access while working to secure the accounts. It said the claims in the posts had not been verified and were being investigated as part of the ongoing incident response.

AnMed Systems Disruption Update 12

AnMed said on August 11 that care teams had regained full read/write access to patients’ electronic health records. It said direct office and department phone service would resume the next morning while full restoration of systems and communications continued.

AnMed Systems Disruption Update 13

AnMed said patients with active MyChart accounts and mobile numbers on file could again log in to access health information, although not all portal features were available. Direct phone lines and electronic health-record access had also returned, while additional systems and services remained in restoration.

Service, Practice Openings and Closings

AnMed’s August 13 status list showed most services open, but five imaging locations, Heart & Vascular Diagnostics-Clemson, Laboratory Services-Anderson-Fant Street, Lung & Sleep Center, TMS & Sleep Diagnostics and Women’s Diagnostics remained closed. Radiation Oncology remained limited.

AnMed Latest Updates and Frequently Asked Questions

AnMed’s latest-updates page links its Aug. 27 Notice of Data Security Event and retains an Aug. 21 service FAQ. The FAQ documented unavailable MyChart provider messaging and post-July 26 test results, affected medical-record functions, imaging rescheduling, printed laboratory-order workarounds, the Fant Street laboratory closure and a regular-phone outage at AnMed Federal Credit Union.

AnMed Systems Disruption Update 14

AnMed confirmed Aug. 21 that cybercriminals obtained information and said it was reviewing the affected data to identify people who might require notification. Phones, read/write electronic health records and patient MyChart access had been restored, but additional systems and services remained in restoration.

Notice of Data Security Event

AnMed said a computer virus locked access to network files July 26 and that files on certain systems were copied without permission. It said the network was securely restored, electronic health records in a separate cloud environment were unaffected and locally stored patient-care files may contain identifying, clinical, insurance and financial information still under review.

Ransom demand displayed on an AnMed computer (screenshot)

A person working inside AnMed supplied a photograph of a ransom demand displayed on a hospital computer, together with a victim-specific Tor link and unique code used to establish a negotiation account on a server the source identified as Interlock. The note claims encryption and extraction, gives a 72-hour deadline and threatens publication. The image does not visibly name AnMed or Interlock. The Tor link and code are withheld because they could provide unauthorized access to private victim communications.

Archive platform: Screenshot

See something that needs correction?

Signed-in members can report an error, update, or missing source.