AnMad
Incident posture
Timeline
Summary
A ransomware attack on a US healthcare provider resulted in the forced closure of its facilities, representing one of the most significant confirmed incidents during a sharp month-over-month increase in ransomware activity that disproportionately struck the finance, technology, healthcare, and education sectors. The attack underscored the broader pattern of threat actors targeting critical infrastructure by taking down key systems, stealing data, or deleting datasets. Industry analysis noted that two ransomware strains together accounted for one-third of all attacks recorded during the period, continuing their dominance over other active groups.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
AnMad, a US healthcare provider, was the target of a ransomware attack that was significant enough to be highlighted in Comparitech's July 2026 ransomware analysis, which was published on August 5, 2026. Comparitech's broader analysis, published on August 7, 2026, noted that ransomware attacks surged by 19% in July compared to June, with the healthcare sector experiencing a 46% increase in attacks month-by-month. The total number of claimed ransomware attacks in July reached 799, marking the second highest month of 2026 and the third highest month for ransomware attacks over the preceding 17-month period, following a relative lull in April, May, and June. Among the July incidents specifically called out due to their severe impacts, the attack on AnMad was singled out for resulting in the closure of facilities, underscoring the operational disruption that ransomware can inflict on critical healthcare infrastructure. Another prominent July incident involved the Romanian government's land registry agency, which suffered an attack that resulted in an entire database being wiped and significant disruption to the country's real estate market, illustrating the varied tactics employed by ransomware groups. According to Rebecca Moody, head of data research at Comparitech, the AnMad incident and the Romanian land registry attack demonstrated how ransomware groups target organizations in different ways, including taking down key systems, stealing large volumes of data, and deleting massive datasets.
The broader threat landscape in July 2026 was characterized by the continued dominance of The Gentlemen and Qilin ransomware groups, which together accounted for 33% of all attacks during the month. The Gentlemen claimed 135 attacks while Qilin claimed 125, continuing what Comparitech described as a "battle" for supremacy between the two ransomware strains. A separate analysis by ReliaQuest previously found that The Gentlemen had emerged as the most prolific threat actor behind cyber extortion campaigns between March and May 2026, overtaking the previously dominant Qilin outfit. The next most active ransomware groups in July were DragonForce with 41 attacks, INC with 36, CRPx0 with 33, and SafePay with 30, all significantly less active than the two leading groups. The finance sector experienced the largest month-by-month increase in attacks at 71%, followed by technology at 62%, healthcare at 46%, and education at 44%. Attacks targeting US-based organizations also rose by 31% from June to July, reflecting a broader escalation of ransomware activity against American targets during the period.
Sources
Sources available to members: 1 source.