TechNewsReel
Live

Ransomware Group Hijacks AnMed Facebook Page to Extort Health System

Attackers seized a nonprofit provider's social media account after a malware attack forced the closure of 83 facilities across South Carolina and Georgia.

TechNewsReel Newsroom · August 21, 2026

AnMed, a nonprofit health system serving South Carolina and Georgia, was targeted in a massive cybersecurity attack that crippled its operations and culminated in a public extortion attempt. The incident underscores a growing trend of ransomware groups using a victim's own communication channels to pressure leadership into paying ransoms.

The disruption began on July 26, 2026, when AnMed confirmed it was dealing with a cybersecurity event involving malware. The operational impact was immediate and severe; at the height of the crisis on July 27, 83 of the system's 106 facilities were forced to close. To maintain basic care, the organization shifted to downtime procedures, which included postponing elective procedures while keeping emergency departments operational to handle critical patients.

Operational Collapse

AnMed operates a regional network consisting of four hospitals and a wide array of clinics. The scale of the facility closures indicates a systemic failure of the network's digital infrastructure, leaving staff to rely on manual processes during the peak of the malware infection. While the system worked to restore services, the attackers shifted their strategy from internal disruption to public coercion.

On August 11, 2026, a ransomware group known as 'The Gentlemen' hijacked AnMed's verified Facebook page. Rather than communicating through private encrypted channels, the group used the public platform to post an extortion note. In the post, the group claimed to have exfiltrated 6TB of sensitive patient data and offered "deletion on payment," according to the group's statement.

A New Coercive Tactic

This attack highlights an escalating tactic in the ransomware landscape: the hijacking of verified social media accounts. By seizing a victim's official voice, attackers can bypass corporate PR filters and communicate their demands directly to patients and the public. This creates a level of reputational pressure that traditional ransomware attacks—which typically remain hidden until a leak site is used—do not achieve.

Furthermore, the claim of stealing 6TB of data suggests a massive breach of patient privacy. While the group has made specific claims regarding the nature of the stolen files, the actual contents of the exfiltrated data have not been independently verified by forensic sources. However, the sheer volume of the claimed theft poses a significant risk to the thousands of patients served by the South Carolina and Georgia network.

Future Outlook

Industry analysts view this incident as part of a broader pattern, as 'The Gentlemen' have increasingly targeted mid-market healthcare providers across the U.S. Southeast. The shift toward public social media extortion suggests that attackers are seeking more immediate leverage to force payments.

It remains unconfirmed whether a ransom was paid or if the 6TB of data has been leaked to the dark web. Healthcare providers are now being urged to secure not only their clinical databases but also their external communication assets to prevent similar hijackings.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.