Threat reportRansomwareTL-2026-1727

AnMed Health Ransomware/Malware Disruption Closes 79-83 South Carolina/Georgia Facilities, Extortion Note Demands Payment Within 72 Hours

highACTIVE

AnMed Health Ransomware/Malware Disruption Closes 79-83 (TL-2026-1727) is a high-severity ransomware operation, first published 2026-07-27. It has no confirmed attribution, affects AnMed Health Corporation AnMed enterprise network (phone systems, maps to 25 MITRE ATT&CK techniques (T1003, T1005, T1018), and is covered by 9 detection rules and 30 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
25MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
30Indicators of compromise

Key facts for TL-2026-1727

Threat ID
TL-2026-1727
Severity
HIGH
Status
ACTIVE
Category
RANSOMWARE
First published
Last reviewed
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
health
Target regions
united states of america
Detection rules
9
Indicators of compromise
30

Malware and tooling in AnMed Health Ransomware/Malware Disruption Closes 79-83

Malware and tooling: 3am, ALPHV/BlackCat, AgendaCrypt, DragonForce, LockBit 3.0 - S1202, RansomHub - S1212, gunra, kazu, nightspire, Cobalt Strike, Mimikatz, Rclone - S1040

How AnMed Health Ransomware/Malware Disruption Closes 79-83 works

AnMed, a nonprofit health system operating four hospitals and 60+ physician practices across upstate South Carolina and northeast Georgia, suffered a network-wide malware disruption beginning Sunday, July 26, 2026 that knocked out phone lines, internet connectivity, and the MyChart patient portal. Reporting from Healthcare IT News indicates hospital staff observed an on-screen extortion message on AnMed computers threatening to leak stolen patient data unless a ransom was paid within 72 hours, and AnMed closed 79-83 of its 106 facilities (imaging, OBGYN, primary care, and medical group offices) while urgent care, labs, and ERs stayed open. No threat actor has publicly claimed responsibility and no CVE, malware family, or technical IOC has been disclosed as of this writing.

On Sunday, July 26, 2026, AnMed Health confirmed it was 'experiencing a cybersecurity disruption involving malware that is impacting our network,' with phone lines, internet connectivity, electronic patient records/paperwork systems, and the MyChart patient portal all affected across its hospital locations. The FBI's Columbia, SC field office, the South Carolina Law Enforcement Division (SLED), and the Anderson Police Department were engaged, alongside unnamed third-party cybersecurity specialists retained by AnMed. Emergency rooms remained open throughout, with some patients diverted to Prisma Health and other Greenville-area hospitals to maintain continuity of care.

By Monday, July 27, 2026, AnMed announced the temporary closure of the large majority of its facility footprint — reported as 79 of 106 facilities by HIPAA Journal and classaction.org, and as 83 facilities by TechTarget/HealthTech Security — covering all AnMed Medical Group offices, AnMed Imaging Services, OBGYN, and primary care clinics. Urgent Care, Kids Care, Integrated Therapy, and Laboratory Services remained operational, and a groundbreaking ceremony for AnMed's planned Education and Technology Center was postponed. Elective procedures were postponed pending a safety review, with affected patients to be contacted directly. classaction.org's breach-notification tracker lists the impacted data categories as still 'TBD' as of this writing, confirming AnMed has not yet disclosed which patient data elements (if any) were exposed.

Healthcare IT News reported that hospital staff told a patient that hackers had posted a message directly on AnMed's computers threatening to leak patient information stolen in the incident unless AnMed paid an extortion demand within 72 hours — a pattern consistent with double-extortion ransomware, where an on-screen ransom note follows encryption/disruption of endpoint systems and is paired with a claim of prior data exfiltration to pressure payment. As of the most recent reporting (re-checked July 27, 2026), no ransomware group has publicly claimed the attack on a dark-web leak site, AnMed has not confirmed whether patient data was actually exfiltrated, and no malware family, CVE, initial-access vector, or network-level indicator of compromise (IP, domain, hash) has been disclosed by AnMed, law enforcement, or any outlet covering the story. Data-breach law firms (classaction.org) have already begun soliciting current/former AnMed patients and employees for a potential class action over undisclosed data exposure.

This incident lands amid a documented surge in healthcare-sector ransomware activity in 2026: Flare/Help Net Security researcher Assaf Morag tracked 14 ransomware groups actively targeting EMEA healthcare and its supply chain in the same window (week of July 24, 2026), naming at least 8 by name — Qilin, LockBit 3.0, RansomHub, DragonForce, Gunra, NightSpire, 3AM, and the newer Kazu group (which pivoted from government/public-sector targets to Latin American healthcare) — and citing precedent-scale breaches at American Hospital Dubai (40 TB / 450 million patient records claimed), Spire Healthcare (1.8 TB claimed), and the ALPHV/BlackCat attack on Change Healthcare (February 2024; $22 million ransom paid; ~$2.87 billion in total estimated damages). Healthcare-practice ransomware attacks were reported up 36% year-over-year in late 2025, with double-extortion tactics now standard in 96% of healthcare ransomware cases. None of these named groups or precedent incidents are confirmed as responsible for or related to the AnMed intrusion — they are cited here strictly as sector threat-landscape context, not attribution, since no source ties any specific actor to this incident.

SECTOR THREAT-LANDSCAPE TTP REFERENCE (not AnMed-specific): because AnMed's own statements use the word 'malware' without confirming ransomware, encryption, or exfiltration, and because no technical artifact from the intrusion itself has been published, the MITRE ATT&CK entries in this record are split into two groups. The first group (Collection, Exfiltration, Impact — Data from Local System, Data from Information Repositories, Exfiltration Over Web Service, Data Encrypted for Impact, Service Stop, Internal Defacement, Financial Theft) is inferred directly from AnMed-specific reporting (the on-screen ransom note, the claimed data theft, the network-wide service outage) and represents the actual, evidence-grounded scope of this record. The second, larger group of MITRE entries is drawn verbatim from the joint CISA/FBI/HHS #StopRansomware advisory AA24-242A on RansomHub — one of the 14 groups Flare/Help Net Security confirmed is actively hitting the healthcare sector in the same period — and is included as a sourced, authoritative sector-hunting reference for defenders (what a contemporaneous, healthcare-targeting RansomHub-affiliate intrusion typically looks like end-to-end), NOT as a claim about how the AnMed intrusion specifically unfolded. SOC analysts should treat the first group as confirmed-for-this-incident and the second group as hunting/detection-engineering context only.

MITRE ATT&CK techniques used in TL-2026-1727

Credential Access

T1003 OS Credential Dumping; T1110.003 Password Spraying

Collection

T1005 Data from Local System; T1213 Data from Information Repositories

Discovery

T1018 Remote System Discovery; T1046 Network Service Discovery

Defense Evasion

T1036 Masquerading; T1070 Indicator Removal

Execution

T1047 Windows Management Instrumentation; T1059.001 PowerShell

Exfiltration

T1048 Exfiltration Over Alternative Protocol; T1537 Transfer Data to Cloud Account; T1567 Exfiltration Over Web Service

Privilege Escalation

T1098 Account Manipulation

Persistence

T1136 Create Account

Initial Access

T1190 Exploit Public-Facing Application; T1566 Phishing

Lateral Movement

T1210 Exploitation of Remote Services

Command and Control

T1219 Remote Access Tools

Impact

T1486 Data Encrypted for Impact; T1489 Service Stop; T1490 Inhibit System Recovery; T1491.001 Internal Defacement; T1657 Financial Theft

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in AnMed Health Ransomware/Malware Disruption Closes 79-83

  • AnMed Health Corporation — AnMed enterprise network (phone systems, internet connectivity, MyChart patient portal, electronic patient records/paperwork systems)
    Vulnerable versions: N/A — organization-wide network disruption; no specific software product/version publicly disclosed

Remediation for AnMed Health Ransomware/Malware Disruption Closes 79-83

Immediate actions

  • Isolate and segment affected network zones (phone/VoIP, general enterprise IT, clinical/EHR) to contain further spread while restoring connectivity
  • Activate downtime/continuity procedures (paper charting, verbal orders, manual patient intake) per existing Hospital Incident Command System plans
  • Preserve forensic evidence (memory captures, logs, the on-screen ransom note) before remediation actions overwrite artifacts; coordinate collection with FBI, SLED, and Anderson PD
  • Do not pay the extortion demand without law-enforcement consultation; independently validate any claim of stolen patient data before responding to the 72-hour deadline
  • Notify and coordinate patient diversion with regional partners (e.g., Prisma Health) for imaging, OBGYN, and primary-care continuity
  • Hunt for the sector-context RansomHub TTPs/tools documented in CISA AA24-242A (Mimikatz, Cobalt Strike, Sliver, PsExec, rclone, vssadmin abuse) as a precautionary detection-engineering baseline, given confirmed contemporaneous healthcare-sector targeting by that and similar groups

Workarounds

  • Keep urgent care, ER, laboratory, and integrated-therapy services on isolated/unaffected infrastructure to sustain critical patient access
  • Postpone elective procedures and imaging/OBGYN/primary-care visits with direct patient outreach until systems are validated as clean

Longer-term hardening

  • Segment clinical/EHR and patient-portal (MyChart) infrastructure from general enterprise IT and telephony networks
  • Maintain offline, immutable backups of EHR, imaging, and patient-portal data with regularly tested restore procedures, hardened against Inhibit System Recovery (T1490)-style backup/VSS destruction
  • Adopt HHS HC3 / CISA StopRansomware healthcare-sector hardening guidance: phishing-resistant MFA, EDR on all endpoints, and privileged-access management
  • Run tabletop exercises simulating multi-week phone/internet/EHR outage across the full facility footprint, not just a single hospital
  • Patch and monitor internet-facing VPN/remote-access appliances and collaboration software (Citrix NetScaler, Fortinet FortiOS/FortiProxy, Confluence, F5 BIG-IP) — the class of edge infrastructure named healthcare-targeting ransomware affiliates most commonly exploit for initial access sector-wide

Timeline of AnMed Health Ransomware/Malware Disruption Closes 79-83

  • Flare (via Help Net Security) publishes research identifying 14 ransomware groups — including RansomHub, Qilin, LockBit 3.0, DragonForce, Gunra, NightSpire, 3AM, and Kazu — actively targeting EMEA healthcare organizations and supply chains in the same period as the AnMed incident; no group named in this report is attributed to the AnMed intrusion.
  • AnMed begins diverting patients to Prisma Health and other Greenville-area hospitals to maintain continuity of care during the outage.
  • FBI's Columbia, SC field office made aware of the cyber incident affecting AnMed; South Carolina Law Enforcement Division (SLED) and the Anderson Police Department also engaged.
  • Phone lines, internet connectivity, MyChart patient portal, and electronic patient records/paperwork systems reported down across all AnMed hospital locations; emergency rooms remain open and accepting patients.
  • AnMed Health publishes initial notice confirming 'a cybersecurity disruption involving malware' impacting its network.
  • AnMed states it is unable to provide a timeline for full system restoration and is working with third-party cybersecurity specialists plus state and federal authorities; updates promised via its website.
  • Data-breach law firms (via classaction.org) begin soliciting current/former AnMed patients and employees for a potential class action over undisclosed data exposure; impacted data categories listed as 'TBD'.
  • As of GovInfoSecurity's reporting, no ransomware group has publicly claimed responsibility for the attack on a dark-web leak site.
  • Healthcare IT News reports hospital staff observed an on-screen message on AnMed computers threatening to leak stolen patient information unless a ransom is paid within 72 hours.
  • Elective procedures postponed pending safety review; affected patients to be contacted directly. Groundbreaking ceremony for AnMed's Education and Technology Center also postponed.
  • AnMed temporarily closes the large majority of its facility footprint (reported as 79 of 106 by HIPAA Journal/classaction.org, 83 by TechTarget) — all Medical Group offices, Imaging, OBGYN, and primary care clinics; Urgent Care, Kids Care, Integrated Therapy, and Laboratory Services remain open.

Sources cited for AnMed Health Ransomware/Malware Disruption Closes 79-83

Detection coverage for TL-2026-1727

As of 2026-07-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1727 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
30 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats