AnMed was already weeks into a malware incident detected on July 26 when its Facebook presence became a new front on August 11. Ransom demands attributed to the Gentlemen group were posted to the page that day. The episode underscores how ransomware operators will extend a pressure campaign into any public channel a healthcare organization uses to keep patients informed during an outage.
The posts described a 6-terabyte haul spanning records tied to sexual assault, mental health, abortion, and sexual harassment, the kind of sensitive data whose exposure carries acute consequences for patients and liability for providers.
A spokesperson said the unauthorized content was removed and access through the platform disabled, with the system working to secure the accounts while cybersecurity specialists continue the investigation.
AnMed has stressed that the claims remain unverified and that it has not confirmed whether patient information was affected.
The takeover came as the network kept ten facilities closed to appointments as of August 10, part of a two-week outage the system has documented with daily updates. The Gentlemen has been one of the most active ransomware-as-a-service operations since late 2025, with CheckPoint counting 332 victims in the first five months of 2026 and researchers linking its creation to a former Qilin affiliate.
