Skip to content
Flash Briefing high Healthcare

The Gentlemen Ransomware Hijacks Hospital's Facebook Page to Pressure AnMed Health

AnMed, a nonprofit medical system operating four hospitals and associated clinics across Georgia and South Carolina, is contending with an extortion campaign that has moved beyond its network and onto the open internet. The Gentlemen ransomware group, which first breached AnMed’s systems around July 26, seized control of the health system’s official Facebook page on August 11 and used it to publish ransom demands directly to the hospital’s patient and community audience. AnMed says the posts were removed and access to the platform disabled, but not before the group’s message reached the public. Ten AnMed facilities remained closed to scheduled appointments as of August 10, and the organization has been issuing daily operational updates since the breach was discovered.

Context

The Gentlemen is a relatively new ransomware-as-a-service operation founded by a former affiliate of Qilin, and it inherited much of that lineage’s operational playbook: initial access through edge devices such as firewalls and VPN appliances, credential-based intrusion rather than novel exploits, and endpoint-detection-evasion tooling supplied to affiliates as part of the RaaS package. CISA and independent trackers have linked the group to roughly 332 extortion cases in the first half of 2026 alone, spanning healthcare, manufacturing, and professional services. What sets the AnMed incident apart is not the intrusion method but the pressure tactic: rather than relying solely on a dark-web leak site, the group commandeered a verified, public-facing social media account to put its demands in front of the victim’s own patients and community, a visibility play that dark-web-only extortion cannot match.

The group claims to have exfiltrated approximately 6 terabytes of data from AnMed’s systems, including records described as covering sexual assault cases, mental health treatment, abortion care, and sexual harassment complaints, categories of health information that carry outsized reputational and legal exposure if genuine. AnMed has not confirmed the scope or authenticity of the claimed data, and the figure should be treated as an unverified extortion claim pending independent confirmation.

Sector Impact

For healthcare, the operational disruption is the immediate concern: ten facilities unable to take scheduled appointments represents a direct patient-care impact, not just a data-confidentiality one. Beyond AnMed, the incident sets a precedent that other healthcare-focused ransomware affiliates are likely to copy. Hospital systems typically maintain official social media presences with large local followings and comparatively weak dedicated security controls around those accounts, since they’re managed by marketing or communications staff rather than IT security teams. A ransomware group that can seize a hospital’s Facebook page has found a new, low-effort amplification channel for extortion pressure that most incident response plans do not currently account for.

Healthcare security and communications teams should treat social media account credentials as a protected asset on par with core network credentials: enforce phishing-resistant MFA on all official platform accounts, restrict administrative access to a minimal named group, and pre-stage an incident response plan specifically for account takeover that includes rapid platform-level lockout requests to Meta and other providers. Organizations should also review whether marketing and communications teams are included in existing ransomware tabletop exercises, since the AnMed case shows extortion pressure is no longer confined to the network perimeter. Given The Gentlemen’s reliance on edge-device credential attacks, patching and MFA enforcement on firewalls and VPN appliances remains the highest-leverage control against the initial intrusion vector.