# AnMed Health Ransomware/Malware Disruption Closes 79-83 South Carolina/Georgia Facilities, Extortion Note Demands Payment Within 72 Hours

> AnMed, a nonprofit health system operating four hospitals and 60+ physician practices across upstate South Carolina and northeast Georgia, suffered a network-wide malware disruption beginning Sunday, July 26, 2026 that knocked out phone lines, internet connectivity, and the MyChart patient portal. Reporting from Healthcare IT News indicates hospital staff observed an on-screen extortion message on AnMed computers threatening to leak stolen patient data unless a ransom was paid within 72 hours, and AnMed closed 79-83 of its 106 facilities (imaging, OBGYN, primary care, and medical group offices) while urgent care, labs, and ERs stayed open. No threat actor has publicly claimed responsibility and no CVE, malware family, or technical IOC has been disclosed as of this writing.

- **Published:** 2026-07-27T00:00:00Z
- **Last reviewed:** 2026-07-27T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1727
- **ID:** TL-2026-1727
- **Severity:** HIGH
- **Category:** RANSOMWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 30 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On Sunday, July 26, 2026, AnMed Health confirmed it was 'experiencing a cybersecurity disruption involving malware that is impacting our network,' with phone lines, internet connectivity, electronic patient records/paperwork systems, and the MyChart patient portal all affected across its hospital locations. The FBI's Columbia, SC field office, the South Carolina Law Enforcement Division (SLED), and the Anderson Police Department were engaged, alongside unnamed third-party cybersecurity specialists retained by AnMed. Emergency rooms remained open throughout, with some patients diverted to Prisma Health and other Greenville-area hospitals to maintain continuity of care.

By Monday, July 27, 2026, AnMed announced the temporary closure of the large majority of its facility footprint — reported as 79 of 106 facilities by HIPAA Journal and classaction.org, and as 83 facilities by TechTarget/HealthTech Security — covering all AnMed Medical Group offices, AnMed Imaging Services, OBGYN, and primary care clinics. Urgent Care, Kids Care, Integrated Therapy, and Laboratory Services remained operational, and a groundbreaking ceremony for AnMed's planned Education and Technology Center was postponed. Elective procedures were postponed pending a safety review, with affected patients to be contacted directly. classaction.org's breach-notification tracker lists the impacted data categories as still 'TBD' as of this writing, confirming AnMed has not yet disclosed which patient data elements (if any) were exposed.

Healthcare IT News reported that hospital staff told a patient that hackers had posted a message directly on AnMed's computers threatening to leak patient information stolen in the incident unless AnMed paid an extortion demand within 72 hours — a pattern consistent with double-extortion ransomware, where an on-screen ransom note follows encryption/disruption of endpoint systems and is paired with a claim of prior data exfiltration to pressure payment. As of the most recent reporting (re-checked July 27, 2026), no ransomware group has publicly claimed the attack on a dark-web leak site, AnMed has not confirmed whether patient data was actually exfiltrated, and no malware family, CVE, initial-access vector, or network-level indicator of compromise (IP, domain, hash) has been disclosed by AnMed, law enforcement, or any outlet covering the story. Data-breach law firms (classaction.org) have already begun soliciting current/former AnMed patients and employees for a potential class action over undisclosed data exposure.

This incident lands amid a documented surge in healthcare-sector ransomware activity in 2026: Flare/Help Net Security researcher Assaf Morag tracked 14 ransomware groups actively targeting EMEA healthcare and its supply chain in the same window (week of July 24, 2026), naming at least 8 by name — Qilin, LockBit 3.0, RansomHub, DragonForce, Gunra, NightSpire, 3AM, and the newer Kazu group (which pivoted from government/public-sector targets to Latin American healthcare) — and citing precedent-scale breaches at American Hospital Dubai (40 TB / 450 million patient records claimed), Spire Healthcare (1.8 TB claimed), and the ALPHV/BlackCat attack on Change Healthcare (February 2024; $22 million ransom paid; ~$2.87 billion in total estimated damages). Healthcare-practice ransomware attacks were reported up 36% year-over-year in late 2025, with double-extortion tactics now standard in 96% of healthcare ransomware cases. None of these named groups or precedent incidents are confirmed as responsible for or related to the AnMed intrusion — they are cited here strictly as sector threat-landscape context, not attribution, since no source ties any specific actor to this incident.

SECTOR THREAT-LANDSCAPE TTP REFERENCE (not AnMed-specific): because AnMed's own statements use the word 'malware' without confirming ransomware, encryption, or exfiltration, and because no technical artifact from the intrusion itself has been published, the MITRE ATT&CK entries in this record are split into two groups. The first group (Collection, Exfiltration, Impact — Data from Local System, Data from Information Repositories, Exfiltration Over Web Service, Data Encrypted for Impact, Service Stop, Internal Defacement, Financial Theft) is inferred directly from AnMed-specific reporting (the on-screen ransom note, the claimed data theft, the network-wide service outage) and represents the actual, evidence-grounded scope of this record. The second, larger group of MITRE entries is drawn verbatim from the joint CISA/FBI/HHS #StopRansomware advisory AA24-242A on RansomHub — one of the 14 groups Flare/Help Net Security confirmed is actively hitting the healthcare sector in the same period — and is included as a sourced, authoritative sector-hunting reference for defenders (what a contemporaneous, healthcare-targeting RansomHub-affiliate intrusion typically looks like end-to-end), NOT as a claim about how the AnMed intrusion specifically unfolded. SOC analysts should treat the first group as confirmed-for-this-incident and the second group as hunting/detection-engineering context only.

## MITRE ATT&CK

- T1005 Data from Local System
- T1213 Data from Information Repositories
- T1567 Exfiltration Over Web Service
- T1486 Data Encrypted for Impact
- T1489 Service Stop
- T1491.001 Internal Defacement
- T1657 Financial Theft
- T1190 Exploit Public-Facing Application
- T1566 Phishing
- T1047 Windows Management Instrumentation
- T1059.001 PowerShell
- T1136 Create Account
- T1098 Account Manipulation
- T1036 Masquerading
- T1070 Indicator Removal
- T1685 Disable or Modify Tools
- T1003 OS Credential Dumping
- T1110.003 Password Spraying
- T1018 Remote System Discovery
- T1046 Network Service Discovery
- T1210 Exploitation of Remote Services
- T1219 Remote Access Tools
- T1048 Exfiltration Over Alternative Protocol
- T1537 Transfer Data to Cloud Account
- T1490 Inhibit System Recovery

## Sources

- [Health system in South Carolina, Georgia closes offices after malware affects networks](https://therecord.media/health-system-south-carolina-georgia-disruptions-malware)
- [AnMed given 72 hours to respond to demands in ransomware incident](https://www.healthcareitnews.com/news/anmed-given-72-hours-respond-demands-ransomware-incident)
- [AnMed Closes Almost 80 Facilities While it Grapples with Cyberattack](https://www.hipaajournal.com/anmed-closes-almost-80-facilities-while-it-grapples-with-cyberattack/)
- [Cyberattack forces temporary closure of 83 AnMed facilities](https://www.techtarget.com/healthtechsecurity/news/366646219/Cyberattack-forces-temporary-closure-of-83-AnMed-facilities)
- [AnMed: Phone, internet outage impacting all hospital locations; ERs remain open](https://www.foxcarolina.com/2026/07/26/anmed-phone-internet-outage-impacting-all-hospital-locations-ers-remain-open/)
- [AnMed Closes Care Facilities As it Deals with Malware Attack](https://www.govinfosecurity.com/malware-attack-forces-anmed-to-close-care-facilities-a-32336)
- [AnMed Cyberattack Reported; Lawyers Investigating Potential Impact](https://www.classaction.org/data-breach-lawsuits/anmed-july-2026)
- [Ransomware gangs go after EMEA healthcare's supply chain](https://www.helpnetsecurity.com/2026/07/24/emea-healthcare-ransomware-activity/)
- [AnMed closes offices, imaging after cybersecurity disruption](https://www.beckershospitalreview.com/healthcare-information-technology/cybersecurity/anmed-closes-offices-imaging-after-cybersecurity-disruption/)
- [#StopRansomware: RansomHub Ransomware (CISA/FBI/MS-ISAC/HHS Joint Advisory AA24-242A)](https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-242a)
- [RansomHub Ransomware Analysis, Simulation, and Mitigation — CISA Alert AA24-242A](https://www.picussecurity.com/resource/blog/ransomhub-ransomware-cisa-alert-aa24-242a)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1727
