CSIDB logo
Incident

Veradigm

Incident posture

Attack window
Sep 2026
Location
United States of America
Status
Ongoing
CIA posture
Available to members
Updated
2026-09-10 09:23

Linked entities

Victim
Veradigm
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Undetermined
Discovered
Undetermined
Disclosed
Sep 2026
Resolved
Pending

Summary

Veradigm disclosed that compromised credentials from a third-party vendor allowed an attacker to access a limited customer-services API and copy patient data. The incident affected a small number of customers but caused no operational disruptions, and the compromised interface did not provide access to the company’s broader network, servers, databases, or other systems. Stolen information included personal details and, for some patients, Social Security numbers, while clinical and medical information remained unaffected. The Gentlemen ransomware group claimed responsibility, alleging possession of millions of records containing names, addresses, contact details, Social Security numbers, and guarantor information, and threatened to publish the data unless ransom negotiations began. Veradigm activated incident-response procedures, notified law enforcement, began notifying affected customers and individuals, and is offering credit monitoring where applicable.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

Veradigm, formerly known as Allscripts Healthcare Solutions, disclosed a data breach after a cybersecurity incident involving one of its third-party vendors exposed patients’ personal data. The Chicago-based healthcare technology company provides electronic health records, e-prescribing, patient-engagement, practice-management, and revenue-cycle software to medical practices, hospitals, clinics, and biopharmaceutical firms across the United States. Veradigm stated that the incident did not cause operational disruptions and affected a small number of customers. In a filing with the U.S. Securities and Exchange Commission, the company said an attacker obtained credentials from a vendor’s environment for a Veradigm API reserved for customer services.

The attacker used the compromised vendor credentials to access the limited API interface and copy patient data. Veradigm said the stolen data included personal details and Social Security numbers for some patients. The company stated that clinical or medical information remained safe. Veradigm also said the compromised credentials provided access only through that limited interface and did not provide access to any other part of the company’s environment, including its broader network, servers, databases, or other systems.

After discovering the breach, Veradigm initiated its incident-response procedures and notified law enforcement. The company began an investigation to determine the scope of the incident. Veradigm said affected customers and individuals were being notified, and credit-monitoring services were being offered where applicable. The investigation remained ongoing at the time of the disclosure. Based on the information available at that point, Veradigm said it did not believe the incident was reasonably likely to materially affect its business, operations, financial condition, or results.

The Gentlemen ransomware group claimed responsibility for the intrusion on September 5 and listed Veradigm on its data leak site. The group alleged that it had obtained 3.5 million patient records. It claimed the stolen data included full names, home addresses, Social Security numbers, email addresses, phone numbers, and personally identifiable information or guarantors. The group threatened to leak the stolen data by Friday, September 11, if Veradigm did not engage in a ransom payment negotiation. Veradigm’s disclosure did not identify the attacker, but the claim by The Gentlemen group followed the company’s notice of the vendor-related credential compromise and patient data exposure.

The Gentlemen ransomware group emerged around mid-2025 and operates as a double-extortion group, combining data theft with data encryption across Windows, Linux, NAS, BSD, and ESXi systems. Its data leak site listed more than 800 victims from 86 countries and multiple sectors, including manufacturing, technology, healthcare, transportation, and financial services. In April 2026, Check Point reported discovering a SystemBC proxy malware botnet with more than 1,500 hosts and linked it to an affiliate of The Gentlemen ransomware gang. In June 2026, ESET reported that The Gentlemen group was using a new endpoint detection and response killer called GentleKiller.

Sources

Sources available to members: 1 source.

CSIDB