CSIDB logo
Incident

Veradigm

Incident posture

Attack window
Sep 2026
Location
United States of America
Status
Ongoing
CIA posture
Available to members
Updated
2026-09-24 19:25

Linked entities

Victim
Veradigm
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Sep 2026
Discovered
Undetermined
Disclosed
Sep 2026
Resolved
Pending

Summary

Veradigm disclosed a data breach after attackers obtained credentials from a third‑party vendor’s environment for a limited API used by the company’s customer service, allowing them to copy patient personal data including names, addresses and Social Security numbers while clinical information remained unaffected. The company stated the compromised credentials did not grant access to its broader network, servers or databases, and it activated incident‑response procedures, notified law enforcement and is informing affected individuals, offering credit‑monitoring where appropriate. The Gentlemen ransomware group claimed responsibility for the intrusion, alleging possession of millions of patient records and threatening to leak the data unless a ransom negotiation begins.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

Veradigm, formerly known as Allscripts Healthcare Solutions, disclosed a data breach after a cybersecurity incident at one of its third‑party vendors exposed patients’ personal data. The company stated that the incident did not cause operational disruptions and affected only a small number of its customers. According to its SEC filing, an attacker obtained credentials from the vendor’s environment for a Veradigm API reserved for customer services and used those credentials to copy patient data. The compromised credentials provided access only through that limited API interface and did not grant entry to any other part of Veradigm’s network, servers, databases, or other systems.

Veradigm said the stolen data includes personal details and Social Security numbers for some patients, while clinical or medical information remained safe. After discovering the breach, the company initiated its incident‑response procedures, notified law enforcement, and began an investigation to determine the full scope. Affected customers and individuals are being notified, and credit‑monitoring services are being offered where applicable. Veradigm noted that, based on current information, it does not believe the incident is reasonably likely to materially affect its business, operations, financial condition, or results.

The Gentlemen ransomware group claimed responsibility for the intrusion on September 5 and listed Veradigm on its data leak site, alleging possession of 3.5 million patient records containing full names, home addresses, SSNs, email addresses, phone numbers, and other personally identifiable information. The group threatened to leak the stolen data by Friday, September 11 unless Veradigm engaged in ransom payment negotiations. The Gentlemen, which emerged around mid‑2025, operates as a double‑extortion group that combines data theft with encryption on Windows, Linux, NAS, BSD, and ESXi systems, and has listed more than 800 victims from 86 countries across various sectors on its leak site. In April 2026 Check Point reported a SystemBC proxy malware botnet with over 1,500 hosts linked to an affiliate of the gang, and in June 2026 ESET noted that the group was using a new endpoint detection and response killer called GentleKiller.

Sources

Sources available to members: 1 source.

CSIDB