CSIDB logo
Incident

AnMed

Incident posture

Attack window
Jul 2026
Location
United States of America
Status
Ongoing
CIA posture
Available to members
Updated
2026-09-04 09:56

Linked entities

Victim
AnMed
Threat actors
0 actors
Sources
7 sources

Timeline

Occurred
Jul 2026
Discovered
Jul 2026
Disclosed
Jul 2026
Resolved
Pending

Summary

AnMed experienced a malware cyberattack that disrupted its network, leading to the closure of numerous facilities, loss of phone and internet service, and the takedown of its MyChart patient portal. Emergency departments remained open while the health system operated under downtime procedures, using paper forms and rescheduling appointments, with some patients diverted to nearby hospitals. Suspicious communications resembling appointment reminders were reported to have originated outside the system, prompting warnings for patients to remain cautious. The FBI and state law enforcement are assisting an ongoing investigation to determine whether any patient data was compromised, though no evidence of malicious targeting has been found. Recovery efforts continue as specialists work to restore systems and normal services.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On July 26, 2026, AnMed experienced a cybersecurity disruption involving malware that caused a phone and internet outage across all hospital locations, prompting the health system to close its facilities while keeping emergency rooms open and care teams on site. The attack forced AnMed to take down its MyChart patient portal and other computer systems, leading to the initial closure of 83 facilities including outpatient imaging services, urgent care locations, kids care centers, integrated therapy sites, and laboratory services. Patients reported being unable to obtain discharge paperwork and described heightened anxiety due to the loss of electronic communications and records. AnMed announced the postponement of a groundbreaking ceremony for the AnMed Education and Technology Center, noting that construction remained on schedule despite the disruption.

In the days following the attack, AnMed implemented established downtime procedures, switching to manual processes such as paper forms and records to continue providing care where possible. By August 5, ten facilities remained closed a week after the incident, while others had reopened under limited operations, with patients experiencing delays, limited portal access, and rescheduled appointments. The health system warned patients on July 30 that appointment reminders generated outside of its internal systems might continue to be delivered by text message, advising that electronic confirmation was not required at that time. AnMed also launched a centralized phone line on August 2, staffed weekdays from 9 a.m. to 4 p.m., to handle scheduling, prescription refill, and non‑urgent medical concerns, and added dedicated billing numbers effective August 4 for patient inquiries.

To manage the situation, AnMed coordinated with emergency medical services, regional hospitals, and public safety partners to ensure patients received appropriate care, including ambulance diversions to other facilities when necessary. The health system provided ongoing updates via its website and stated that its doctors retained access to medical records, emphasizing that safe care remained the highest priority. AnMed reported that it had found no evidence of patients being targeted with malicious intent as a result of the incident, though it urged caution regarding electronic messages appearing to originate from the organization. The FBI’s Columbia field office and the South Carolina Law Enforcement Division were confirmed to be assisting with the investigation, which remained ongoing with no threat group claiming responsibility and no determination yet made about the extent of any patient data involvement.

Sources

Sources available to members: 7 sources.

CSIDB