Threat reportRansomwareTL-2026-1727
AnMed Health Ransomware/Malware Disruption Closes 79-83 South Carolina/Georgia Facilities, Extortion Note Demands Payment Within 72 Hours
AnMed Health Ransomware/Malware Disruption Closes 79-83 (TL-2026-1727) is a high-severity ransomware operation, first published 2026-07-27. It has no confirmed attribution, affects AnMed Health Corporation AnMed enterprise network (phone systems, maps to 25 MITRE ATT&CK techniques (T1003, T1005, T1018), and is covered by 9 detection rules and 30 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 25MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 30Indicators of compromise
Key facts for TL-2026-1727
- Threat ID
- TL-2026-1727
- Severity
- HIGH
- Status
- ACTIVE
- Category
- RANSOMWARE
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- health
- Target regions
- united states of america
- Detection rules
- 9
- Indicators of compromise
- 30
Malware and tooling in AnMed Health Ransomware/Malware Disruption Closes 79-83
Malware and tooling: 3am, ALPHV/BlackCat, AgendaCrypt, DragonForce, LockBit 3.0 - S1202, RansomHub - S1212, gunra, kazu, nightspire, Cobalt Strike, Mimikatz, Rclone - S1040
How AnMed Health Ransomware/Malware Disruption Closes 79-83 works
AnMed, a nonprofit health system operating four hospitals and 60+ physician practices across upstate South Carolina and northeast Georgia, suffered a network-wide malware disruption beginning Sunday, July 26, 2026 that knocked out phone lines, internet connectivity, and the MyChart patient portal. Reporting from Healthcare IT News indicates hospital staff observed an on-screen extortion message on AnMed computers threatening to leak stolen patient data unless a ransom was paid within 72 hours, and AnMed closed 79-83 of its 106 facilities (imaging, OBGYN, primary care, and medical group offices) while urgent care, labs, and ERs stayed open. No threat actor has publicly claimed responsibility and no CVE, malware family, or technical IOC has been disclosed as of this writing.
On Sunday, July 26, 2026, AnMed Health confirmed it was 'experiencing a cybersecurity disruption involving malware that is impacting our network,' with phone lines, internet connectivity, electronic patient records/paperwork systems, and the MyChart patient portal all affected across its hospital locations. The FBI's Columbia, SC field office, the South Carolina Law Enforcement Division (SLED), and the Anderson Police Department were engaged, alongside unnamed third-party cybersecurity specialists retained by AnMed. Emergency rooms remained open throughout, with some patients diverted to Prisma Health and other Greenville-area hospitals to maintain continuity of care.
By Monday, July 27, 2026, AnMed announced the temporary closure of the large majority of its facility footprint — reported as 79 of 106 facilities by HIPAA Journal and classaction.org, and as 83 facilities by TechTarget/HealthTech Security — covering all AnMed Medical Group offices, AnMed Imaging Services, OBGYN, and primary care clinics. Urgent Care, Kids Care, Integrated Therapy, and Laboratory Services remained operational, and a groundbreaking ceremony for AnMed's planned Education and Technology Center was postponed. Elective procedures were postponed pending a safety review, with affected patients to be contacted directly. classaction.org's breach-notification tracker lists the impacted data categories as still 'TBD' as of this writing, confirming AnMed has not yet disclosed which patient data elements (if any) were exposed.
Healthcare IT News reported that hospital staff told a patient that hackers had posted a message directly on AnMed's computers threatening to leak patient information stolen in the incident unless AnMed paid an extortion demand within 72 hours — a pattern consistent with double-extortion ransomware, where an on-screen ransom note follows encryption/disruption of endpoint systems and is paired with a claim of prior data exfiltration to pressure payment. As of the most recent reporting (re-checked July 27, 2026), no ransomware group has publicly claimed the attack on a dark-web leak site, AnMed has not confirmed whether patient data was actually exfiltrated, and no malware family, CVE, initial-access vector, or network-level indicator of compromise (IP, domain, hash) has been disclosed by AnMed, law enforcement, or any outlet covering the story. Data-breach law firms (classaction.org) have already begun soliciting current/former AnMed patients and employees for a potential class action over undisclosed data exposure.
This incident lands amid a documented surge in healthcare-sector ransomware activity in 2026: Flare/Help Net Security researcher Assaf Morag tracked 14 ransomware groups actively targeting EMEA healthcare and its supply chain in the same window (week of July 24, 2026), naming at least 8 by name — Qilin, LockBit 3.0, RansomHub, DragonForce, Gunra, NightSpire, 3AM, and the newer Kazu group (which pivoted from government/public-sector targets to Latin American healthcare) — and citing precedent-scale breaches at American Hospital Dubai (40 TB / 450 million patient records claimed), Spire Healthcare (1.8 TB claimed), and the ALPHV/BlackCat attack on Change Healthcare (February 2024; $22 million ransom paid; ~$2.87 billion in total estimated damages). Healthcare-practice ransomware attacks were reported up 36% year-over-year in late 2025, with double-extortion tactics now standard in 96% of healthcare ransomware cases. None of these named groups or precedent incidents are confirmed as responsible for or related to the AnMed intrusion — they are cited here strictly as sector threat-landscape context, not attribution, since no source ties any specific actor to this incident.
SECTOR THREAT-LANDSCAPE TTP REFERENCE (not AnMed-specific): because AnMed's own statements use the word 'malware' without confirming ransomware, encryption, or exfiltration, and because no technical artifact from the intrusion itself has been published, the MITRE ATT&CK entries in this record are split into two groups. The first group (Collection, Exfiltration, Impact — Data from Local System, Data from Information Repositories, Exfiltration Over Web Service, Data Encrypted for Impact, Service Stop, Internal Defacement, Financial Theft) is inferred directly from AnMed-specific reporting (the on-screen ransom note, the claimed data theft, the network-wide service outage) and represents the actual, evidence-grounded scope of this record. The second, larger group of MITRE entries is drawn verbatim from the joint CISA/FBI/HHS #StopRansomware advisory AA24-242A on RansomHub — one of the 14 groups Flare/Help Net Security confirmed is actively hitting the healthcare sector in the same period — and is included as a sourced, authoritative sector-hunting reference for defenders (what a contemporaneous, healthcare-targeting RansomHub-affiliate intrusion typically looks like end-to-end), NOT as a claim about how the AnMed intrusion specifically unfolded. SOC analysts should treat the first group as confirmed-for-this-incident and the second group as hunting/detection-engineering context only.
MITRE ATT&CK techniques used in TL-2026-1727
Credential Access
T1003 OS Credential Dumping; T1110.003 Password Spraying
Collection
T1005 Data from Local System; T1213 Data from Information Repositories
Discovery
T1018 Remote System Discovery; T1046 Network Service Discovery
Defense Evasion
T1036 Masquerading; T1070 Indicator Removal
Execution
T1047 Windows Management Instrumentation; T1059.001 PowerShell
Exfiltration
T1048 Exfiltration Over Alternative Protocol; T1537 Transfer Data to Cloud Account; T1567 Exfiltration Over Web Service
Privilege Escalation
Persistence
Initial Access
T1190 Exploit Public-Facing Application; T1566 Phishing
Lateral Movement
T1210 Exploitation of Remote Services
Command and Control
Impact
T1486 Data Encrypted for Impact; T1489 Service Stop; T1490 Inhibit System Recovery; T1491.001 Internal Defacement; T1657 Financial Theft
defense-impairment
Affected products and versions in AnMed Health Ransomware/Malware Disruption Closes 79-83
- AnMed Health Corporation — AnMed enterprise network (phone systems, internet connectivity, MyChart patient portal, electronic patient records/paperwork systems)
Vulnerable versions: N/A — organization-wide network disruption; no specific software product/version publicly disclosed
Remediation for AnMed Health Ransomware/Malware Disruption Closes 79-83
Immediate actions
- Isolate and segment affected network zones (phone/VoIP, general enterprise IT, clinical/EHR) to contain further spread while restoring connectivity
- Activate downtime/continuity procedures (paper charting, verbal orders, manual patient intake) per existing Hospital Incident Command System plans
- Preserve forensic evidence (memory captures, logs, the on-screen ransom note) before remediation actions overwrite artifacts; coordinate collection with FBI, SLED, and Anderson PD
- Do not pay the extortion demand without law-enforcement consultation; independently validate any claim of stolen patient data before responding to the 72-hour deadline
- Notify and coordinate patient diversion with regional partners (e.g., Prisma Health) for imaging, OBGYN, and primary-care continuity
- Hunt for the sector-context RansomHub TTPs/tools documented in CISA AA24-242A (Mimikatz, Cobalt Strike, Sliver, PsExec, rclone, vssadmin abuse) as a precautionary detection-engineering baseline, given confirmed contemporaneous healthcare-sector targeting by that and similar groups
Workarounds
- Keep urgent care, ER, laboratory, and integrated-therapy services on isolated/unaffected infrastructure to sustain critical patient access
- Postpone elective procedures and imaging/OBGYN/primary-care visits with direct patient outreach until systems are validated as clean
Longer-term hardening
- Segment clinical/EHR and patient-portal (MyChart) infrastructure from general enterprise IT and telephony networks
- Maintain offline, immutable backups of EHR, imaging, and patient-portal data with regularly tested restore procedures, hardened against Inhibit System Recovery (T1490)-style backup/VSS destruction
- Adopt HHS HC3 / CISA StopRansomware healthcare-sector hardening guidance: phishing-resistant MFA, EDR on all endpoints, and privileged-access management
- Run tabletop exercises simulating multi-week phone/internet/EHR outage across the full facility footprint, not just a single hospital
- Patch and monitor internet-facing VPN/remote-access appliances and collaboration software (Citrix NetScaler, Fortinet FortiOS/FortiProxy, Confluence, F5 BIG-IP) — the class of edge infrastructure named healthcare-targeting ransomware affiliates most commonly exploit for initial access sector-wide
Timeline of AnMed Health Ransomware/Malware Disruption Closes 79-83
- Flare (via Help Net Security) publishes research identifying 14 ransomware groups — including RansomHub, Qilin, LockBit 3.0, DragonForce, Gunra, NightSpire, 3AM, and Kazu — actively targeting EMEA healthcare organizations and supply chains in the same period as the AnMed incident; no group named in this report is attributed to the AnMed intrusion.
- AnMed begins diverting patients to Prisma Health and other Greenville-area hospitals to maintain continuity of care during the outage.
- FBI's Columbia, SC field office made aware of the cyber incident affecting AnMed; South Carolina Law Enforcement Division (SLED) and the Anderson Police Department also engaged.
- Phone lines, internet connectivity, MyChart patient portal, and electronic patient records/paperwork systems reported down across all AnMed hospital locations; emergency rooms remain open and accepting patients.
- AnMed Health publishes initial notice confirming 'a cybersecurity disruption involving malware' impacting its network.
- AnMed states it is unable to provide a timeline for full system restoration and is working with third-party cybersecurity specialists plus state and federal authorities; updates promised via its website.
- Data-breach law firms (via classaction.org) begin soliciting current/former AnMed patients and employees for a potential class action over undisclosed data exposure; impacted data categories listed as 'TBD'.
- As of GovInfoSecurity's reporting, no ransomware group has publicly claimed responsibility for the attack on a dark-web leak site.
- Healthcare IT News reports hospital staff observed an on-screen message on AnMed computers threatening to leak stolen patient information unless a ransom is paid within 72 hours.
- Elective procedures postponed pending safety review; affected patients to be contacted directly. Groundbreaking ceremony for AnMed's Education and Technology Center also postponed.
- AnMed temporarily closes the large majority of its facility footprint (reported as 79 of 106 by HIPAA Journal/classaction.org, 83 by TechTarget) — all Medical Group offices, Imaging, OBGYN, and primary care clinics; Urgent Care, Kids Care, Integrated Therapy, and Laboratory Services remain open.
Sources cited for AnMed Health Ransomware/Malware Disruption Closes 79-83
- Health system in South Carolina, Georgia closes offices after malware affects networks
- AnMed given 72 hours to respond to demands in ransomware incident
- AnMed Closes Almost 80 Facilities While it Grapples with Cyberattack
- Cyberattack forces temporary closure of 83 AnMed facilities
- AnMed: Phone, internet outage impacting all hospital locations; ERs remain open
- AnMed Closes Care Facilities As it Deals with Malware Attack
- AnMed Cyberattack Reported; Lawyers Investigating Potential Impact
- Ransomware gangs go after EMEA healthcare's supply chain
- AnMed closes offices, imaging after cybersecurity disruption
- #StopRansomware: RansomHub Ransomware (CISA/FBI/MS-ISAC/HHS Joint Advisory AA24-242A)
- RansomHub Ransomware Analysis, Simulation, and Mitigation — CISA Alert AA24-242A
Detection coverage for TL-2026-1727
As of 2026-07-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1727 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.