‘The Gentlemen’ ransomware gang takes over hospital Facebook after cyberattack

As AnMed, a nonprofit health system serving South Carolina and Georgia, recovers from a July 26 ransomware attack that took its network offline, over 100 posts appeared on its Facebook page claiming to be from hackers calling themselves “The Gentlemen.”

“Gentlemen, your confidential data has been exfiltrated. 6TB: HIV+ patients, suicide registries, sexual assault & rape victims, mental health, abortions, genetic data, patient SSN/DOB, autopsy & police evidence. Deletion on payment," the Aug. 11 posting read, pointing to a link where anyone could send payment, under the promise their personal data would be purged from the trove.

The message was repeatedly published roughly 100 times. There was a much longer posting that preceded the flood of duplicates, but it contained ostensibly the same extortion threat.

The spam was removed a short time later, with AnMed releasing a statement of its own, confirming the message was unauthorized and adding that the “claims contained in the posts have not been verified.”

Access to its Facebook has, for now, been disabled as AnMed said it works to secure its social media accounts.

The July 26 cyberattack on the hospital is still being investigated. As of Aug. 12, some systems at the hospital remain offline. How hackers gained access, and specifically what systems were impacted, remains unknown.

AnMed confirmed that it is working with law enforcement and a third-party cybersecurity firm to investigate the details.

During the downtime AnMed was forced to postpone elective procedures and shut down medical imaging. Some specialty services, such as oncology and radiation, were also closed as the hospital looked to prioritize its emergency rooms and labs.

The post from the hacker group implies the hospital faced a ransom, meaning that protected health data was potentially accessed and moved offsite—but that has not been confirmed.

Subscribe to Health Exec News

An infamous adversary

As for the cybercriminals known as the Gentlemen, they are a prolific hacker gang known for their deployment of their own custom ransomware. The group’s first documented activity dates back to August 2025.

Since then, their list of victims includes multiple healthcare entities, including hospitals and insurers, as well as critical infrastructure and more. The group has been known to evade many forms of top-of-the-line security, developing new tactics for its sophisticated cyberattacks.

The cybercrime syndicate has its own dark web blog where it chronicles its attacks and releases data troves for sale. HealthExec was unable to access the site to determine if there is a posting about AnMed.

The true identity of the Gentlemen is unknown.

Chad Van Alstin Health Imaging Health Exec

Chad is an award-winning writer and editor with over 15 years of experience working in media. He has a decade-long professional background in healthcare, working as a writer and in public relations.

Subscribe to Health Exec News

Subscribe to Health Exec News