Breaking NewsUpdated as information becomes available
Breach Analysis·14 August 2026·Breaking

AnMed Closes Facilities Following Ransomware Attack and Data Claims

South Carolina health system AnMed was forced to close 83 facilities following a cyberattack. Threat actors subsequently claimed to hold 6 terabytes of sensitive patient records.

Mark Fermor
Mark FermorDirector & Co-Founder, Firevault
4 min read
Share
A modern healthcare facility exterior with patient drop off zone
Breach Analysis

Article record

Breach AnalysisCategory
14 August 2026Published
4 min readReading time
Mark FermorWritten by
A modern healthcare facility exterior with patient drop off zone

Why it matters

What this means for organisations holding critical data

South Carolina health system AnMed was forced to close 83 facilities following a cyberattack. Threat actors subsequently claimed to hold 6 terabytes of sensitive patient records.

According to reporting by HIPAA Journal, South Carolina health system AnMed has been working to restore operational systems following a malware attack that occurred on 26 July 2026. The incident forced the non-profit organisation to temporarily close 83 of its 106 facilities across South Carolina and Georgia as computer systems, telephone lines, and internet connectivity were brought down. While AnMed has reopened most locations and restored access to electronic health records, 11 facilities remained closed into mid-August 2026 as investigations into data theft claims continue.

What happened

On 26 July 2026, AnMed experienced a cybersecurity disruption involving malware that compelled leadership to suspend operations across dozens of clinical sites, including medical group offices and imaging centres. Emergency care remained open, but elective procedures were postponed and patient diversions were put in place. The healthcare provider activated paper downtime procedures while technical teams worked to isolate affected networks and evaluate the damage.

Recovery efforts proceeded in phases. By early August, AnMed had restored read and write access to its electronic health records, reinstated primary telephone lines, and partially brought back its patient portal with additional security verification steps. However, on 11 August 2026, a ransomware group operating under the name The Gentlemen posted a message directly to AnMed's public Facebook page demanding payment. The attackers claimed to have exfiltrated 6 terabytes of sensitive data, including records relating to HIV treatment, suicide registries, mental health notes, sexual assault cases, genetic information, and police evidence. The social media post was subsequently deleted, and AnMed stated that the extortion claims remain unverified and subject to investigation.

Data from cybersecurity firm Dragos highlights that The Gentlemen ranked as the third most active ransomware group in the second quarter of 2026, claiming 125 attacks during that three-month period alone. The group has increasingly targeted healthcare providers using aggressive multi-channel extortion methods.

What the data means for the sector

The incident at AnMed demonstrates the escalating tactics employed by extortion groups targeting the healthcare sector. Cybercriminals are no longer relying solely on network encryption to compel ransom payments. Instead, they are combining operational disruption with targeted public harassment on secondary communication channels such as social media platforms.

When highly sensitive clinical files, such as mental health notes or police evidence, are compromised, the potential harm extends far beyond immediate operational downtime. Healthcare providers face intense scrutiny regarding patient privacy and regulatory compliance. Moreover, operational reliance on live network connections means that when core systems are taken offline to contain an attack, clinical care suffers immediate delay. Healthcare organisations must recognise that active network connections can be compromised simultaneously across multiple operational environments.

The Firevault view

In the healthcare sector, system availability and data integrity directly affect human welfare. When threat actors disrupt live networks and claim to hold terabytes of sensitive files, organisations that rely solely on connected cloud or network-attached backups find themselves facing limited options during recovery.

Offline Secure Storage® (#OSS) provides a vital physical safeguard against these threat vectors. By isolating critical system backups and sensitive data archives entirely from the network, healthcare institutions ensure that a clean, unalterable copy of essential information remains completely out of reach from online attackers. Mark Fermor, senior editor at Firevault, emphasises that keeping critical records in a physically disconnected state prevents cybercriminals from modifying or wiping backup stores during an intrusion. While #OSS does not stop an initial network entry, maintaining physically separated backups guarantees that core records remain intact and recoverable, providing healthcare leaders with a trusted foundation to restore operations without relying on corrupted network infrastructure.

What to do next

Healthcare technology leaders should review their incident response and data protection strategies by taking the following practical steps:

  • Establish routine physical air gaps by storing critical system backups offline using #OSS protocol to prevent remote tampering.
  • Audit social media and external communication accounts to restrict administrative access and prepare pre-approved messaging protocols for crisis events.
  • Conduct regular operational downtime drills to ensure clinical staff can maintain emergency care during extended IT outages.
  • Implement strict verification procedures across all patient and staff portals prior to re-establishing access after an incident.

Sources

Where this reporting comes from

01
Original reportPrimary coverage referenced in this analysisView original article

About the author

Mark Fermor

Mark Fermor

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

How Firevault would handle this

Physical disconnection removes the path an attacker needs

Offline Secure Storage® holds a clean copy of your data on hardware that is physically disconnected, so an intrusion cannot reach it, encrypt it or delete it.

HardwareYour data sits on dedicated encrypted hardware
DisconnectOffline by default, connected only when you say so
CommandAccess windows and retrieval under your control
LocationHeld in a secure Firevault Bunker

Share this article

Breaking News
Breach Analysis14 August 20264 min read

AnMed Closes Facilities Following Ransomware Attack and Data Claims

South Carolina health system AnMed was forced to close 83 facilities following a cyberattack. Threat actors subsequently claimed to hold 6 terabytes of sensitive patient records.

AnMed Closes Facilities Following Ransomware Attack and Data Claims
Mark Fermor
Published by Mark Fermor, Director & Co-Founder

    Your privacy matters

    We use cookies to keep the site running smoothly and to understand how you use it. You are in control. Privacy Charter · Cookie Policy