AnMed Health Ransomware/Malware Disruption Closes 79-83 South Carolina/Georgia Facilities, Extortion Note Demands Payment Within 72 Hours — Threadlinqs Intelligence
As of 2026-07-27, AnMed Health Ransomware/Malware Disruption Closes 79-83 South Carolina/Georgia Facilities, Extortion Note Demands Payment Within 72 Hours is a high-severity ransomware threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 30 indicators of compromise.
Threat ID: TL-2026-1727 · Severity: HIGH · Status: ACTIVE · Category: RANSOMWARE
AnMed, a nonprofit health system operating four hospitals and 60+ physician practices across upstate South Carolina and northeast Georgia, suffered a network-wide malware disruption beginning Sunday,
On Sunday, July 26, 2026, AnMed Health confirmed it was 'experiencing a cybersecurity disruption involving malware that is impacting our network,' with phone lines, internet connectivity, electronic patient records/paperwork systems, and the MyChart patient portal all affected across its hospital locations. The FBI's Columbia, SC field office, the South Carolina Law Enforcement Division (SLED), and the Anderson Police Department were engaged, alongside unnamed third-party cybersecurity specialists retained by AnMed. Emergency rooms remained open throughout, with some patients diverted to Prisma Health and other Greenville-area hospitals to maintain continuity of care.
By Monday, July 27, 2026, AnMed announced the temporary closure of the large majority of its facility footprint — reported as 79 of 106 facilities by HIPAA Journal and classaction.org, and as 83 facilities by TechTarget/HealthTech Security — covering all AnMed Medical Group offices, AnMed Imaging Services, OBGYN, and primary care clinics. Urgent Care, Kids Care, Integrated Therapy, and Laboratory Services remained operational, and a groundbreaking ceremony for AnMed's planned Education and Technology Center was postponed. Elective procedures were postponed pending a safety review, with affected patients to be contacted directly. classaction.org's breach-notification tracker lists the impacted data categories as still 'TBD' as of this writing, confirming AnMed has not yet disclosed which patient data elements (if any) were exposed.
Healthcare IT News reported that hospital staff told a patient that hackers had posted a message directly on AnMed's computers threatening to leak patient information stolen in the incident unless AnMed paid an extortion demand within 72 hours — a pattern consistent with double-extortion ransomware, where an on-screen ransom note follows encryption/disruption of endpoint systems and is paired with a claim of prior data exfiltration to pressure payment. As of the most recent reporting (re-checked July 27, 2026), no ransomware group has publicly claimed the attack on a dark-web leak site, AnMed has not confirmed whether patient data was actually exfiltrated, and no malware family, CVE, initial-access vector, or network-level indicator of compromise (IP, domain, hash) has been disclosed by AnMed, law enforcement, or any outlet covering the story. Data-breach law firms (classaction.org) have already begun soliciting current/former AnMed patients and employees for a potential class action over undisclosed data exposure.
This incident lands amid a documented surge in healthcare-sector ransomware activity in 2026: Flare/Help Net Security researcher Assaf Morag tracked 14 ransomware groups actively targeting EMEA healthcare and its supply chain in the same window (week of July 24, 2026), naming at least 8 by name — Qilin, LockBit 3.0, RansomHub, DragonForce, Gunra, NightSpire, 3AM, and the newer Kazu group (which pivoted from government/public-sector targets to Latin American healthcare) — and citing precedent-scale breaches at American Hospital Dubai (40 TB / 450 million patient records claimed), Spire Healthcare (1.8 TB claimed), and the ALPHV/BlackCat attack on Change Healthcare (February 2024; $22 million ransom paid; ~$2.87 billion in total estimated damages). Healthcare-practice ransomware attacks were reported up 36% year-over-year in late 2025, with double-extortion tactics now standard in 96% of healthcare ransomware cases. None of these named groups or precedent incidents are confirmed as responsible for or related to the AnMed intrusion — they are cited here strictly as sector threat-landscape context, not attribution, since no source ties any specific actor to this incident.
SECTOR THREAT-LANDSCAPE TTP REFERENCE (not AnMed-specific): because AnMed's own statements use the word 'malware' without confirming ransomware, encryption, or exfiltration, and because no technical artifact from the intrusion itself has been published, the
Target sectors: health
Target regions: united states of america
Detections & IOCs
As of 2026-08-17, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 30 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
RANSOMWARE, HIGH, threat intelligence, cybersecurity, T1005, T1213, T1567, T1486, T1489, T1491.001, T1657, T1190, T1566, T1047