Cyber Incident Victim: AnMed
Timeline
Summary
AnMed's Facebook page was taken down after hackers posted nearly 100 ransom messages claiming to have exfiltrated six terabytes of patient data, including medical histories, Social Security numbers, and sensitive health records. The cyberattack, first reported earlier, prompted the health system to notify patients of a network disruption caused by malware and to establish a website and phone line for inquiries while working with third‑party specialists and authorities.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On July 26, AnMed announced that it was experiencing a cybersecurity disruption involving malware that was affecting its network and said it was working with third‑party cybersecurity specialists and state and federal authorities to restore normal operations. In the days that followed, the health system created a website and a telephone line for patients who had questions about the incident. On the morning of Tuesday, August 10, 2026, the AnMed Facebook page began to receive posts from an unknown source. The first of these posts appeared at approximately 9:40 a.m. and was removed shortly thereafter. After 10:00 a.m., a shorter message was posted repeatedly, eventually appearing nearly one hundred times before the page was taken offline.

The initial post contained a ransom note in which the actors claimed to have exfiltrated six terabytes of confidential data from AnMed’s systems. The note listed a wide range of patient information that allegedly had been taken, including dates of birth, Social Security numbers, addresses, medical histories, prescriptions, laboratory results, mental and behavioral health records, pediatric and psychiatric reports, HIV‑related data, reproductive and abortion records, prenatal and non‑invasive prenatal testing results, genetic and molecular pathology data, biometric data, identification documents, forensic and autopsy records, sexual assault and harassment victim records, and details of suicide attempts. The message stated that the attackers would delete the data and keep it confidential if AnMed cooperated and paid a ransom before a deadline, and offered to provide sample files as proof of possession. The subsequent shorter posts repeated the demand for payment and the threat of releasing the alleged data. No further technical details about how the breach occurred were provided in the article.
In response to the ongoing incident, AnMed maintained the patient‑directed website and telephone line that had been set up after the July 26 notice and continued to work with external cybersecurity experts and government agencies. The health system also launched a dedicated patient phone line to address concerns as the recovery effort proceeded. Local news outlet WYFF 4 reported that it continued to seek additional information about the attack and its impact on the facility. The article does not indicate when normal Facebook access was restored or whether any ransom payment was made.
