CSIDB logo
Incident

AnMad

Incident posture

Attack window
Jul 2026
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-03 17:10

Linked entities

Victim
AnMad
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Pending
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A ransomware attack on a US healthcare provider resulted in the forced closure of its facilities, representing one of the most significant confirmed incidents during a sharp month-over-month increase in ransomware activity that disproportionately struck the finance, technology, healthcare, and education sectors. The attack underscored the broader pattern of threat actors targeting critical infrastructure by taking down key systems, stealing data, or deleting datasets. Industry analysis noted that two ransomware strains together accounted for one-third of all attacks recorded during the period, continuing their dominance over other active groups.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

AnMad, a US healthcare provider, was the target of a ransomware attack that was significant enough to be highlighted in Comparitech's July 2026 ransomware analysis, which was published on August 5, 2026. Comparitech's broader analysis, published on August 7, 2026, noted that ransomware attacks surged by 19% in July compared to June, with the healthcare sector experiencing a 46% increase in attacks month-by-month. The total number of claimed ransomware attacks in July reached 799, marking the second highest month of 2026 and the third highest month for ransomware attacks over the preceding 17-month period, following a relative lull in April, May, and June. Among the July incidents specifically called out due to their severe impacts, the attack on AnMad was singled out for resulting in the closure of facilities, underscoring the operational disruption that ransomware can inflict on critical healthcare infrastructure. Another prominent July incident involved the Romanian government's land registry agency, which suffered an attack that resulted in an entire database being wiped and significant disruption to the country's real estate market, illustrating the varied tactics employed by ransomware groups. According to Rebecca Moody, head of data research at Comparitech, the AnMad incident and the Romanian land registry attack demonstrated how ransomware groups target organizations in different ways, including taking down key systems, stealing large volumes of data, and deleting massive datasets.

The broader threat landscape in July 2026 was characterized by the continued dominance of The Gentlemen and Qilin ransomware groups, which together accounted for 33% of all attacks during the month. The Gentlemen claimed 135 attacks while Qilin claimed 125, continuing what Comparitech described as a "battle" for supremacy between the two ransomware strains. A separate analysis by ReliaQuest previously found that The Gentlemen had emerged as the most prolific threat actor behind cyber extortion campaigns between March and May 2026, overtaking the previously dominant Qilin outfit. The next most active ransomware groups in July were DragonForce with 41 attacks, INC with 36, CRPx0 with 33, and SafePay with 30, all significantly less active than the two leading groups. The finance sector experienced the largest month-by-month increase in attacks at 71%, followed by technology at 62%, healthcare at 46%, and education at 44%. Attacks targeting US-based organizations also rose by 31% from June to July, reflecting a broader escalation of ransomware activity against American targets during the period.

Sources

Sources available to members: 1 source.

CSIDB