ALITEQ.

a ransomware gang hijacked a hospital's Facebook page to brag about what it stole

AnMed Health closed 83 facilities after a July cyberattack. Two weeks later, the hackers posted the proof themselves — from AnMed's own account.

Priya NairUpdated 2h ago6 min readWeb story
Hospital entrance signage, representing the AnMed Health ransomware attack

On the morning of August 11, AnMed Health's official Facebook page started posting messages its social media team never wrote. Over a hundred posts went up in a matter of hours, claiming credit for a cyberattack that had already closed 83 of the South Carolina health system's 106 facilities two weeks earlier — and listing, in specific and deliberately upsetting detail, exactly what the attackers say they stole: HIV-status records, a suicide risk registry, sexual assault and rape crisis files, mental health records, abortion records, genetic data, patient Social Security numbers and dates of birth, and autopsy and police evidence.

The posts came from a ransomware-as-a-service group calling itself The Gentlemen, and by AnMed's own account, none of it has been verified. The health system says it still hasn't confirmed the scope of any impact to patient information, or even whether patient data was accessed at all. That gap — between what a ransomware gang claims on a hijacked Facebook page and what a hospital can actually confirm — is the real story here, and it's worth sitting with before reacting to either side of it.

Who The Gentlemen actually are

The Gentlemen isn't a new name. Threat intelligence firm Dragos ranked it the third most active ransomware group of Q2 2026, with 125 claimed attacks — up from 83 in Q1 — and analysts believe its affiliate roster overlaps with several other established ransomware brands, the way most modern ransomware-as-a-service operations do. That's part of what makes attribution and verification so hard in real time: the same infrastructure and the same negotiators show up under different names depending on which brand is currently active, a version of the same rebrand-and-recover pattern DeadLock's blockchain-hosted infrastructure was built to survive.

How the AnMed attack escalated

  1. Jul 26

    AnMed detects a cybersecurity disruption involving malware.

  2. Jul 27

    83 of 106 AnMed Medical Group facilities and imaging offices close; attackers reportedly issue a 72-hour ultimatum.

  3. Aug 3

    About a week on, roughly 10 facilities remain closed as AnMed continues restoring systems.

  4. Aug 10

    The Gentlemen publicly claims responsibility for the attack.

  5. Aug 11

    Over 100 posts hit AnMed's hijacked Facebook page, claiming a 6TB data theft including HIV, mental health, and sexual assault records.

An empty hospital corridor, representing the facility closures during the AnMed cyberattack
83 of AnMed's 106 facilities closed the day after the July 26 attack was detected. · Unsplash

Claim versus confirmed fact — and why that gap matters

Ransomware gangs lie. Not always, but often enough that a claim posted on a leak site — or in this case, hijacked directly from the victim's own social media account — isn't evidence of anything by itself. The Gentlemen didn't publish sample records, didn't publish a file listing, didn't do anything the way groups usually do when they actually want to prove a claim rather than just make one. That doesn't mean the claim is false. AnMed hasn't said that either. The honest answer, right now, is that nobody outside the investigation actually knows what was taken, and anyone telling you otherwise — including the attackers — is guessing or lying.

Why hijacking the hospital's own Facebook page is the newer, meaner tactic

Posting a claim to a dark web leak site is one thing — most people never see it. Posting it through the victim's own verified, trusted channel, in front of every patient and family member who follows that page for appointment updates, is designed to do something a leak site can't: force the story into the open before the hospital can control the narrative or even finish its own investigation. It's a pressure tactic aimed at the hospital's reputation as much as its wallet — the same shift toward public, personal humiliation that showed up when a ransomware group tested whether trusting attackers' word on data deletion was ever rational. The extortion has stopped being purely financial and started being performative.

  • AnMed has confirmed the cyberattack and the facility closures.
  • AnMed has NOT confirmed any patient data was accessed or stolen.
  • The Gentlemen's specific claims (HIV records, suicide registry, abortion records) are unverified and unaccompanied by proof.
  • A parallel payment scam targeting AnMed patients has already been reported separately.

Is AnMed Health still operating?
Most facilities have reopened; roughly 10 of the original 83 closed locations were still shut down about a week after the July 26 attack, according to Healthcare Dive.
Has AnMed confirmed patient data was stolen?
No. As of this writing, AnMed says it has not confirmed the scope of any impact to patient information or whether patient data was affected at all.
What is The Gentlemen ransomware group?
A ransomware-as-a-service operation Dragos ranked the third most active group in Q2 2026, with 125 claimed attacks that quarter, up from 83 in Q1.
Should I worry if I'm an AnMed patient?
It's reasonable to watch for phishing attempts and unsolicited payment demands referencing the breach — a scam exploiting the incident has already been reported — even before AnMed confirms whether your specific data was involved.

I'd treat every specific detail in those hijacked posts as unverified until AnMed or an independent forensics report says otherwise — gangs exaggerate for leverage, and naming HIV status and rape-crisis records is meant to maximize panic, not to be precise. But I'd also take the underlying risk seriously regardless: a health system that had to close 83 buildings for a cyberattack clearly had a real intrusion, and 'we haven't confirmed data was taken' is not the same sentence as 'no data was taken.' Watch this one for an actual forensic update, not the next round of social posts.

Software & Systems Editor

Priya Nair

Priya has daily-driven more Linux distros than she can name and treats her setup like a workshop. She covers the operating systems, apps and settings worth your time — and cheerfully calls out the 'optimizations' that just quietly break your machine.

Work out the hardware

The Aliteq brief

The tech worth knowing — hardware, AI, gaming, deals. No spam, unsubscribe anytime.

Keep reading