HackMyIP
← Back to News
2026-08-11 The Record

The Gentlemen Ransomware Group Hijacks AnMed Facebook Page

RansomwareData BreachIncident Response

Two weeks after a cyberattack disrupted its IT systems, nonprofit medical provider AnMed is still battling fallout after the threat actors behind the breach hijacked the organization's Facebook page to broadcast ransom demands. The page, representing AnMed's four hospitals and numerous clinics across Georgia and South Carolina, was flooded with messages claiming responsibility from a group calling itself "The Gentlemen" before being removed by the social media platform. The hackers asserted they had exfiltrated roughly 6 terabytes of sensitive data, including medical records tied to sexual assault, mental health, abortion, and harassment cases—though no evidence was provided to substantiate those claims.

In a statement, an AnMed spokesperson confirmed that "unauthorized posts" appeared on the company's social media accounts, that the content was removed, and that platform access was disabled while the organization works with providers to secure the accounts. AnMed has not verified the attackers' claims and continues to state on its website that the scope of any potential impact to patient information remains unconfirmed. The incident, originally disclosed on July 26 as a "cybersecurity disruption involving malware," has forced daily updates to AnMed's facility status, with 10 locations still closed to appointments as of Monday. Patients concerned about exposed credentials can verify exposure using an email breach checker.

The Gentlemen has rapidly emerged as one of the most prolific ransomware-as-a-service operations since its launch in the second half of 2025, believed to have been founded by a former Qilin affiliate operating under the alias "hastalamuerte." According to Check Point, the group's ransomware was used to extort 332 victims in the first five months of 2026 alone, and Dragos reported 125 claimed attacks on industrial organizations in the second quarter of 2026, the third-highest among ransomware groups that quarter. Leaked internal files reviewed by Check Point revealed an unusually generous affiliate model, with 90 percent of ransom proceeds going to the operators who execute intrusions. Defenders should audit exposed services and weak credentials using a password checker and a port scanner to reduce attack surface.

The group typically gains initial access through internet-facing edge devices—including firewalls, VPN appliances, and other perimeter systems—using a combination of credential brute-forcing against web or VPN panels, exploitation of known vulnerabilities, and purchased access from third-party brokers. Once inside a target environment, the operators escalate to administrator accounts, disable security tools, exfiltrate data, and finally deploy ransomware payloads. AnMed has not publicly identified the initial access vector in its July 26 incident, though the tactics align closely with The Gentlemen's documented playbook.

Source: The Record →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a data breach? →Credential stuffing attacks →How to check for an email breach →