Ransomware Group Hijacks Hospital Facebook Page Amid Data Exfiltration Claims
The Gentlemen ransomware group claimed to have stolen 6 terabytes of sensitive patient data from AnMed and used the hospital's Facebook page to post ransom demands.

The nonprofit medical system AnMed is still grappling with the fallout from a cyberattack that knocked out its IT systems two weeks ago, now facing system closures and the apparent hijacking of its Facebook page by the ransomware group claiming responsibility. The social media page for the medical chain, which operates four hospitals and several clinics across Georgia and South Carolina, was taken down shortly after a series of messages attributed to "The Gentlemen" ransomware group appeared.
The attackers claimed to have exfiltrated a staggering 6 terabytes of data, including highly sensitive health information pertaining to sexual assault, mental health, abortions, and harassment incidents. However, they have not provided any evidence to substantiate these claims. AnMed's official website continues to state that it has not "confirmed the scope of any potential impact to patient information," nor has it confirmed whether patient data was affected.
A spokesperson for AnMed confirmed the unauthorized posts, stating, "Earlier today, AnMed identified unauthorized posts on its social media accounts. The unauthorized content was removed, access through the platform was disabled and we are working with the provider to secure the accounts." The spokesperson added that the claims made in the posts have not been verified and that AnMed and its cybersecurity specialists are investigating the matter as part of the ongoing response to the cybersecurity incident first identified on July 26.
When the initial incident was announced, AnMed described it as a "cybersecurity disruption involving malware" and indicated efforts were underway to restore systems. Since then, the organization has been providing daily updates on the operational status of its facilities, with 10 locations remaining closed to appointments as of Monday.
The Gentlemen ransomware-as-a-service group has emerged as a significant threat since its appearance in the latter half of 2025, reportedly founded by a former affiliate of the Qilin ransomware group. Cybersecurity firm CheckPoint reported that the group's ransomware was used to extort 332 victims in the first five months of the current year alone. In the second quarter of 2026, the group claimed 125 attacks against industrial organizations, making it the third most active ransomware group during that period, according to the operational technology firm Dragos.
Analysis of leaked internal files by CheckPoint revealed an unusually generous revenue-sharing model, where affiliates executing attacks receive 90 percent of ransoms. The group typically gains initial access through internet-facing edge devices such as firewalls and VPN appliances. Methods employed include brute-forcing credentials against web or VPN panels, exploiting known vulnerabilities, and purchasing access from third-party brokers.
Once inside a victim's network, The Gentlemen actors focus on obtaining administrator privileges and disabling security tools before proceeding with data exfiltration and ransomware deployment. The group is also noted for providing affiliates with sophisticated tools designed to disable endpoint detection and response (EDR) technologies. In one observed instance, the group exploited a vulnerability in a third-party vendor driver to bypass a victim's EDR, a technique highlighted by security firm Expel for its sophistication.
This incident underscores the evolving tactics of ransomware groups, which now extend beyond system encryption and data theft to include public disruption and psychological pressure through social media hijacking. The sensitive nature of the alleged stolen data further emphasizes the severe privacy and reputational risks faced by healthcare organizations in the face of such attacks.