---
title: "AnMed Closes Facilities Following Ransomware At… | Firevault"
description: "South Carolina health system AnMed was forced to close 83 facilities following a cyberattack. Threat actors subsequently claimed to hold 6 terabytes of…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/anmed-facility-closures-following-ransomware-cyberattack#webpage",
      "url": "https://fire-vault.com/news/anmed-facility-closures-following-ransomware-cyberattack",
      "name": "AnMed Closes Facilities Following Ransomware At…",
      "description": "South Carolina health system AnMed was forced to close 83 facilities following a cyberattack. Threat actors subsequently claimed to hold 6 terabytes of…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/anmed-facility-closures-following-ransomware-cyberattack-1786723492583.png"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/news/anmed-facility-closures-following-ransomware-cyberattack#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/news/anmed-facility-closures-following-ransomware-cyberattack#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Knowledge Vault",
          "item": "https://fire-vault.com/learn/knowledge"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "AnMed Closes Facilities Following Ransomware Attack and Data Claims",
          "item": "https://fire-vault.com/news/anmed-facility-closures-following-ransomware-cyberattack"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "NewsArticle",
      "headline": "AnMed Closes Facilities Following Ransomware Attack and Data Claims",
      "description": "South Carolina health system AnMed was forced to close 83 facilities following a cyberattack. Threat actors subsequently claimed to hold 6 terabytes of sensitive patient records.",
      "url": "https://fire-vault.com/news/anmed-facility-closures-following-ransomware-cyberattack",
      "image": [
        {
          "@type": "ImageObject",
          "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/anmed-facility-closures-following-ransomware-cyberattack-1786723492583.png",
          "width": 1200,
          "height": 1200
        },
        {
          "@type": "ImageObject",
          "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/anmed-facility-closures-following-ransomware-cyberattack-1786723492583.png",
          "width": 1200,
          "height": 900
        },
        {
          "@type": "ImageObject",
          "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/anmed-facility-closures-following-ransomware-cyberattack-1786723492583.png",
          "width": 1200,
          "height": 675
        }
      ],
      "thumbnailUrl": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/anmed-facility-closures-following-ransomware-cyberattack-1786723492583.png",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Director & Co-Founder",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@type": "NewsMediaOrganization",
        "name": "Firevault",
        "url": "https://fire-vault.com",
        "logo": {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/logo.png",
          "width": 600,
          "height": 60
        }
      },
      "datePublished": "2026-08-14T16:04:27.299+00:00",
      "dateModified": "2026-08-28T08:03:22.256672+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/news/anmed-facility-closures-following-ransomware-cyberattack"
      },
      "inLanguage": "en-GB",
      "articleSection": "Breach Analysis",
      "wordCount": 668,
      "keywords": "AnMed, Breach Analysis, data breach, cyber security, offline secure storage, data protection, physical air gap",
      "articleBody": "According to reporting by HIPAA Journal, South Carolina health system AnMed has been working to restore operational systems following a malware attack that occurred on 26 July 2026. The incident forced the non-profit organisation to temporarily close 83 of its 106 facilities across South Carolina and Georgia as computer systems, telephone lines, and internet connectivity were brought down. While A",
      "dateline": "United Kingdom",
      "speakable": {
        "@type": "SpeakableSpecification",
        "cssSelector": [
          "h1",
          ".article-summary",
          "h2"
        ]
      },
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2026
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

Buy your Vault

Overview

What happenedWhat the data means for the sectorThe Firevault viewWhat to do nextMore Resources

[Knowledge Vault](/learn/knowledge)/ [News](/learn/knowledge?filter=news)

News · Breach Analysis · 14 August 2026 

# AnMed Closes Facilities Following Ransomware Attack and Data Claims

South Carolina health system AnMed was forced to close 83 facilities following a cyberattack. Threat actors subsequently claimed to hold 6 terabytes of sensitive patient records.

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

4 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fanmed-facility-closures-following-ransomware-cyberattack)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fanmed-facility-closures-following-ransomware-cyberattack&text=AnMed%20Closes%20Facilities%20Following%20Ransomware%20Attack%20and%20Data%20Claims%0A%0ASouth%20Carolina%20health%20system%20AnMed%20was%20forced%20to%20close%2083%20facilities%20following%20a%20cyberattack.%20Threat%20actors%20subsequently%20claimed%20to%20hold%206%20terabytes%20of%20sensitive%20patient%20records.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Fanmed-facility-closures-following-ransomware-cyberattack)[](mailto:?subject=AnMed%20Closes%20Facilities%20Following%20Ransomware%20Attack%20and%20Data%20Claims&body=South%20Carolina%20health%20system%20AnMed%20was%20forced%20to%20close%2083%20facilities%20following%20a%20cyberattack.%20Threat%20actors%20subsequently%20claimed%20to%20hold%206%20terabytes%20of%20sensitive%20patient%20records.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Fnews%2Fanmed-facility-closures-following-ransomware-cyberattack)

![A modern healthcare facility exterior with patient drop off zone](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/anmed-facility-closures-following-ransomware-cyberattack-1786723492583.png)

A modern healthcare facility exterior with patient drop off zone

Why it matters

## What this means for organisations holding critical data

South Carolina health system AnMed was forced to close 83 facilities following a cyberattack. Threat actors subsequently claimed to hold 6 terabytes of sensitive patient records.

In this analysis

1.  01 [What happened](#section-0)
2.  02 [What the data means for the sector](#section-1)
3.  03 [The Firevault view](#section-2)

**On this page**[What happened](#section-0)[What the data means for the sector](#section-1)[The Firevault view](#section-2)

According to reporting by HIPAA Journal, South Carolina health system AnMed has been working to restore operational systems following a malware attack that occurred on 26 July 2026. The incident forced the non-profit organisation to temporarily close 83 of its 106 facilities across South Carolina and Georgia as computer systems, telephone lines, and internet connectivity were brought down. While AnMed has reopened most locations and restored access to electronic health records, 11 facilities remained closed into mid-August 2026 as investigations into data theft claims continue.

## What happened

On 26 July 2026, AnMed experienced a cybersecurity disruption involving malware that compelled leadership to suspend operations across dozens of clinical sites, including medical group offices and imaging centres. Emergency care remained open, but elective procedures were postponed and patient diversions were put in place. The healthcare provider activated paper downtime procedures while technical teams worked to isolate affected networks and evaluate the damage.

Recovery efforts proceeded in phases. By early August, AnMed had restored read and write access to its electronic health records, reinstated primary telephone lines, and partially brought back its patient portal with additional security verification steps. However, on 11 August 2026, a ransomware group operating under the name The Gentlemen posted a message directly to AnMed's public Facebook page demanding payment. The attackers claimed to have exfiltrated 6 terabytes of sensitive data, including records relating to HIV treatment, suicide registries, mental health notes, sexual assault cases, genetic information, and police evidence. The social media post was subsequently deleted, and AnMed stated that the extortion claims remain unverified and subject to investigation.

Data from cybersecurity firm Dragos highlights that The Gentlemen ranked as the third most active ransomware group in the second quarter of 2026, claiming 125 attacks during that three-month period alone. The group has increasingly targeted healthcare providers using aggressive multi-channel extortion methods.

## What the data means for the sector

The incident at AnMed demonstrates the escalating tactics employed by extortion groups targeting the healthcare sector. Cybercriminals are no longer relying solely on network encryption to compel ransom payments. Instead, they are combining operational disruption with targeted public harassment on secondary communication channels such as social media platforms.

When highly sensitive clinical files, such as mental health notes or police evidence, are compromised, the potential harm extends far beyond immediate operational downtime. Healthcare providers face intense scrutiny regarding patient privacy and regulatory compliance. Moreover, operational reliance on live network connections means that when core systems are taken offline to contain an attack, clinical care suffers immediate delay. Healthcare organisations must recognise that active network connections can be compromised simultaneously across multiple operational environments.

## The Firevault view

In the healthcare sector, system availability and data integrity directly affect human welfare. When threat actors disrupt live networks and claim to hold terabytes of sensitive files, organisations that rely solely on connected cloud or network-attached backups find themselves facing limited options during recovery.

[Offline Secure Storage](/offline-secure-storage)® (#OSS) provides a vital physical safeguard against these threat vectors. By isolating critical system backups and sensitive data archives entirely from the network, healthcare institutions ensure that a clean, unalterable copy of essential information remains completely out of reach from online attackers. Mark Fermor, senior editor at Firevault, emphasises that keeping critical records in a physically disconnected state prevents cybercriminals from modifying or wiping backup stores during an intrusion. While #OSS does not stop an initial network entry, maintaining physically separated backups guarantees that core records remain intact and recoverable, providing healthcare leaders with a trusted foundation to restore operations without relying on corrupted network infrastructure.

## What to do next

Healthcare technology leaders should review their incident response and data protection strategies by taking the following practical steps:

-   Establish routine physical air gaps by storing critical system backups offline using #OSS protocol to prevent remote tampering.
-   Audit social media and external communication accounts to restrict administrative access and prepare pre-approved messaging protocols for crisis events.
-   Conduct regular operational downtime drills to ensure clinical staff can maintain emergency care during extended IT outages.
-   Implement strict verification procedures across all patient and staff portals prior to re-establishing access after an incident.

Sources

## Where this reporting comes from

01 

**Original report**Primary coverage referenced in this analysis [View original article](https://www.hipaajournal.com/anmed-closes-almost-80-facilities-while-it-grapples-with-cyberattack/)

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

[![Firevault Bunker, the protected physical location for Offline Secure Storage hardware](/__l5e/assets-v1/75208f4e-fc6f-46d8-80b9-606c43dfef28/firevault-bunker-building.webp)](/why-oss)

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

[![The nine Control modules arranged around the Firevault platform](/__l5e/assets-v1/829a8768-a871-41d0-8a79-3645ca7f5e83/platform-wheel.jpg)](/solutions/control)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

[![Firevault 2TB Vault hardware](/__l5e/assets-v1/ed09bfc1-2f0f-491d-b1aa-861542a5fb33/hero-vault-2tb.png)](/get-started)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## A recovery copy an attacker cannot reach

Offline Secure Storage® keeps a clean copy of your data on hardware that is physically disconnected, so backup and recovery do not depend on systems an intruder can touch.

[Get started](/get-started)[Talk to the team](/demo)

**Hardware**Your copy sits on dedicated encrypted hardware 

**Disconnect**Offline by default, connected only when you say so 

**Recovery**A known-clean copy to rebuild from, on your timetable 

**Location**Held in a secure Firevault Bunker 

Related Reading

## You may also find these useful

[

![Vulnerable children's health records caught up in HCRG Care Group cyber attack, families told 18 months later](/news/hcrg-care-group-children-records-cyber-attack-2026.jpg)

Breach Analysis 

### Vulnerable children's health records caught up in HCRG Care Group cyber attack, families told 18 months later

Families of vulnerable children in Wiltshire, Bath and North East Somerset have been told their personal health information may have been accessed in a cyber attack on HCRG Care Group in February 2025, more than 18 months after the incident.

20 Sept 2026 4 min 







](/news/hcrg-care-group-children-records-cyber-attack-2026)[

![FBI and Coast Guard board oil tankers after suspected foreign cyberattacks on ships entering US waters](/news/us-coast-guard-tanker-cyberattacks-2026.jpg)

Breach Analysis 

### FBI and Coast Guard board oil tankers after suspected foreign cyberattacks on ships entering US waters

US authorities boarded two foreign-flagged oil tankers in the Gulf of Mexico after indications their networks were compromised by foreign cyber actors. Mark Fermor on why a ship is a floating lesson in what happens when operational technology is reachable.

17 Sept 2026 4 min 







](/news/fbi-coast-guard-probe-cyberattacks-oil-tankers-us-waters-2026)[

![FBI investigates 153 million drivers licenses put up for sale on a criminal forum](/news/fbi-drivers-licenses-dark-web-2026.jpg)

Breach Analysis 

### FBI investigates 153 million drivers licenses put up for sale on a criminal forum

A dark web service claimed to be selling scans of more than 153 million drivers licenses, apparently taken from a Louisiana identity verification company used by household names. The FBI has opened an inquiry, and the case shows how long retention turns a routine check into national-scale exposure.

16 Sept 2026 4 min 







](/news/fbi-investigates-153-million-drivers-licenses-dark-web-2026)[

![CenterPoint Energy confirms hackers stole customer data through an exposed API](/news/centerpoint-energy-cyberattack-2026.jpg)

Breach Analysis 

### CenterPoint Energy confirms hackers stole customer data through an exposed API

CenterPoint Energy has confirmed that criminals stole customer data through one of its external facing systems, after a threat actor advertised 7.49 million files on a dark web forum. Mark Fermor on what an unsecured API says about the way critical infrastructure treats connected data.

16 Sept 2026 4 min 







](/news/centerpoint-energy-confirms-cyberattack-data-theft-2026)[

![Southampton council reported seven serious data breaches in a year, including a lost notebook with 224 residents' details](/news/southampton-council-data-breaches-2026.jpg)

Breach Analysis 

### Southampton council reported seven serious data breaches in a year, including a lost notebook with 224 residents' details

Southampton City Council referred seven incidents to the Information Commissioner's Office in 2025/26, including a social worker's lost notebook containing the names, addresses and key safe numbers of 224 people. Mark Fermor on what a notebook, a miscatalogued archive and a curious officer tell us about the data organisations still cannot control.

16 Sept 2026 5 min 







](/news/southampton-council-seven-serious-data-breaches-2026)[

![Southport court files breach: the access was authorised, the purpose was not](/__l5e/assets-v1/8c5ecf7a-e4db-4dcb-b6dd-3585f89078ee/southport-court-files-insider-access-2026.jpg)

Breach Analysis 

### Southport court files breach: the access was authorised, the purpose was not

The Ministry of Justice has confirmed that courts staff accessed files relating to victims, survivors and families of the Southport attack without authorisation. It is the third insider access case connected to the attack, and it shows why perimeter security alone cannot protect the most sensitive records.

16 Sept 2026 5 min 







](/news/southport-court-files-insider-access-breach-2026)

## Suggested Reading

-   [What is Offline Secure Storage The foundation of physical disconnection ](/how-it-works/offline-secure-storage)
-   [Why Offline Secure Storage The case for physical control ](/why-oss)
-   [Ransomware Defence Hold gold copies offline ](/oss-for-ransomware-recovery)
-   [Control Physical path control for IT and OT ](/solutions/control)
-   [Knowledge Vault All articles, guides and whitepapers ](/learn/knowledge)
-   [Book a Demo See Firevault in action ](/demo)

[Back to Knowledge Vault](/learn/knowledge)