News Analysis: AnMed Still Working to Restore Services, Repair Ransomware Damage

Greg Wilson/Anderson Observer

More than two weeks after a ransomware attack disrupted AnMed Health, the system has begun to restore some of the digital machinery that modern medicine depends upon so completely that its absence can feel almost surreal. For a time, clinicians worked without normal access to much of their patients’ electronic information; online prescription fulfillment, scheduling systems, and many of the ordinary tools used to diagnose and treat patients were impaired or unavailable.

The consequences did not remain inside the computer network. Some patients were rerouted to other hospitals for treatment, while others saw procedures postponed or placed on hold as AnMed sought to restore its systems. A hospital can continue functioning during a cyberattack, but it does so under a kind of administrative weather: paper records, uncertain communications, interrupted schedules, and the constant effort to distinguish what is urgent from what can safely wait.

On Tuesday night, AnMed said it had made “significant progress” in restoring systems and communications following the July 26 incident. The health system said care teams now have full read-and-write access to electronic health records, allowing clinicians to view and update patient information electronically rather than relying on temporary workarounds. Beginning at 7 a.m. Wednesday, patients will again be able to call physicians’ offices and other departments directly during regular service hours with questions about their care.

AnMed said its investigation remains ongoing and that additional information will be released as it becomes available. The organization thanked patients, employees, and community partners for their patience as it continues trying to restore operations fully and safely.

The announcement came after a series of social-media posts appeared on AnMed’s Facebook page Tuesday morning. The posts, allegedly made by the people responsible for the attack, claimed that the group had obtained more than six terabytes of patient data and could publish personal information if its demands were not met. The claims have not been independently verified, and the posts themselves do not establish what data, if any, was accessed, copied, or released.

The group used the name “The Gentlemen,” a moniker that may offer a clue but not a certainty. Cybersecurity researchers have associated that name with a structured ransomware organization rather than an improvised collective. According to multiple intelligence reports, the group is believed to be led by a Russian-speaking operator known as “hastalamuerte” or “zeta88,” a former affiliate leader in the Qilin ransomware program.

The operator is believed to run a ransomware-as-a-service platform, take part in attacks, and manage affiliates. The organization reportedly has about nine core operators and at least eight affiliate teams using separate TOX messaging identities. Researchers have also said the group follows a CIS-exclusion policy, avoiding organizations in Russia and allied Commonwealth of Independent States countries.

Microsoft tracks the group as Storm-2697. Researchers say it emerged in mid-2025 after a payment dispute within the Qilin ransomware operation and rapidly became a significant global threat. By 2026, some cybersecurity reporting attributed roughly 10 percent of global ransomware activity to the organization. Still, one cybersecurity source cautioned that the use of “The Gentlemen” name could be a red herring, and the identity of the AnMed attackers remains unconfirmed.

Whatever the source of the posts, their message was unmistakably threatening. They claimed to possess records containing patient names, dates of birth, Social Security numbers, addresses, identification and insurance-related information, medical histories, prescriptions, laboratory results, and other clinical records. The posts also asserted possession of more sensitive materials, including mental- and behavioral-health records, substance-use testing, cancer diagnoses, HIV-related treatment information, prenatal and genetic-testing records, reproductive-health and abortion-related information, and pediatric and psychiatric files.

The posters further claimed to have forensic and autopsy records, biometric information, sexual-assault and harassment case materials, and records involving suicide attempts. They said the data would be deleted and kept confidential if payment were made by a stated deadline. Those assertions, too, should be treated as unverified claims by the attackers rather than independently established facts.

The broader pattern is familiar to cybersecurity specialists, if not yet to the public that must live with its consequences. Ransomware attackers commonly gain entry through phishing emails, stolen credentials, exposed remote-access services, or software vulnerabilities. Once inside, they can move through networks, encrypt systems, and steal data before demanding payment both to restore operations and to prevent publication.

In a healthcare system, those attacks can shut down much more than ordinary office technology. Electronic records, scheduling, billing, laboratory interfaces, pharmacy workflows, imaging systems, and communication tools may all be affected at once. The result can be postponed procedures, delayed tests, ambulance diversions, and clinicians forced into manual processes that are slower and more difficult to manage.

The Anderson Observer reported July 30 that attacks on medical organizations had increased by more than 24 percent this year, as criminals sought targets where operational disruption could be translated quickly into financial pressure. The FBI identified healthcare as the most-targeted sector for ransomware in 2025, with 460 ransomware attacks and 182 data breaches, according to figures cited in that report. A tracker recorded 410 healthcare ransomware attacks in the first half of 2026, most directed at hospitals, clinics, and direct-care providers.

The use of artificial-intelligence tools has added new speed and scale to the threat. Attackers can use such tools to improve reconnaissance, generate more convincing phishing messages, automate pieces of an intrusion, and sharpen social-engineering tactics. But the older weaknesses remain: reused or weak credentials, exposed vendors, outdated software, and systems that cannot easily be taken offline because patient care depends on them. AnMed’s vulnerability has been reported as involving a weak point in telephone-security connections to other data sources, although the health system has not publicly detailed the source of the intrusion.

AnMed’s public communication has been sparse, consisting largely of brief updates. Last week, the organization attempted to establish phone numbers that patients could call for information, but some callers reported receiving no answer or a “mailbox is full” message. The restoration of direct calls to physician offices and departments is therefore likely to be one of the most visible signs, for patients, that the health system is moving back toward ordinary operations.

Still, restoring access to electronic records is not the same as completing recovery. Healthcare organizations affected by ransomware often regain critical services within days or weeks, but full restoration can take a month or longer. Systems must be rebuilt, records validated, clinical workflows normalized, and investigators allowed time to determine what information may have been accessed or removed.

A 2025 healthcare ransomware survey found that 58 percent of affected providers recovered within a week. Other reporting has placed average ransomware-related downtime for U.S. healthcare organizations at roughly 19 days, while one industry estimate put average full recovery at about 36 days. The timetable varies according to the scale of the attack, the security and availability of backups, the number of connected systems involved, and whether the organization can safely sustain patient care while repairs continue.

The visible outage may end long before the investigation does. Healthcare-breach studies have found that identifying and containing an incident can take months, a period that includes not only the recovery phase but also the time an attacker may have remained undetected within a network.

For AnMed, the immediate picture is clearer than it was a week ago: electronic records are beginning to be accessible again, and direct calls are set to resume. But the questions that matter most — how the attackers entered, what they obtained, whether patient information was taken, how it will be used, and how long the full recovery will require — remain open.

Previous
Previous

Graham/Norman Senate Seat Candidates in Aug. 25 Runoff

Next
Next

City Moves Ahead on Annexation, Development Standards