Thank you for reading or listening to The Realist Juggernaut. Independent journalism should be accessible to everyone.
Anderson, South Carolina — August 11, 2026 — AnMed has disabled access to its social media accounts after unauthorized posts containing ransom demands appeared while the nonprofit health system continues recovering from a malware attack that disrupted its information-technology network more than two weeks ago.
The unauthorized messages appeared Tuesday on AnMed’s Facebook page and claimed to come from a ransomware operation calling itself “The Gentlemen.” The page was removed from Facebook shortly after the messages became public.
AnMed said it identified the unauthorized posts, removed the content and disabled access through the social media platform. The health system is working with the platform provider to secure the affected accounts.
The organization said the claims contained in the posts have not been verified. Its cybersecurity specialists are examining the account compromise as part of the broader investigation into the incident identified on July 26.
The attackers claimed they had removed six terabytes of data from AnMed’s systems. They alleged the information included sensitive health records involving sexual assault, mental-health care, abortions and sexual-harassment incidents.
No evidence was released publicly to establish that the attackers possess the information they described. AnMed has not confirmed that patient records were accessed or removed and has not determined the scope of any potential effect on patient information.
The appearance of ransom messages on an organization’s verified social media presence can serve several purposes during a cyberattack. It can increase public pressure, give attackers direct access to the victim’s audience and create a channel for publishing claims after access to the organization’s internal systems has been restricted.
Control of a social media account does not independently prove that the same attackers entered AnMed’s clinical network or obtained patient data. The investigation must determine whether the account was compromised through credentials taken during the original intrusion, an unrelated password breach, a connected administrative account or another access method.
AnMed first reported the cybersecurity disruption on July 26, describing it as a malware incident affecting its network. The organization began working with state and federal authorities and third-party cybersecurity specialists to determine the nature and scope of the attack and restore systems securely.
The disruption forced AnMed to modify services, close physician offices and adjust scheduled care. Ten facilities remained closed to appointments as of August 10, while the health system continued publishing operational updates for patients.
AnMed has made daily decisions concerning procedures, transfers, diversions and service availability based on the condition of its systems and the ability of individual facilities to provide care safely.
Emergency and urgent-care services remained available during the response, along with selected laboratory, therapy and prescription services. Patients with affected appointments were directed to monitor AnMed’s official updates and wait for instructions from their care teams.
AnMed reported additional restoration progress on August 11. Care teams regained full read-and-write access to patients’ electronic health records, allowing providers to view and update medical information electronically. Direct telephone access to physicians’ offices and other departments was scheduled to resume at 7:00 a.m. on August 12 during regular service hours. The investigation into data security and the information involved remained ongoing.
AnMed is an independent nonprofit health system serving Upstate South Carolina and northeast Georgia. It operates four hospitals along with specialty centers, urgent-care locations, therapy facilities and a network of physician practices.
The system is licensed for 648 beds and is anchored by AnMed Medical Center, a 495-bed acute-care hospital. Its network includes cancer, cardiovascular, maternity, behavioral-health and rehabilitation services, placing a wide range of clinical and administrative systems within the recovery effort.
Healthcare organizations depend upon connected systems for patient registration, clinical documentation, diagnostic results, medication management, appointment scheduling, billing and communication among care teams. A network shutdown can affect operations even when medical facilities remain open and clinical personnel continue treating patients.
Restoring those systems requires more than removing malware. Investigators must identify how the intrusion began, determine how far the attackers moved, inspect administrative accounts, reset compromised credentials and verify that restored devices do not contain unauthorized access mechanisms.
Backup systems must also be checked before data is returned to production. Reconnecting an unsafe backup or a device containing persistent access could allow the attackers to regain entry and disrupt recovery.
The examination of patient-information exposure is a separate part of the response. AnMed must determine whether unauthorized individuals viewed, copied or transferred protected health information before the network was contained.
The volume and sensitivity of the data described in the ransom posts make independent verification necessary. Claims published by attackers can be accurate, exaggerated, incomplete or fabricated to pressure an organization into payment.
If the investigation determines that protected health information was compromised, AnMed may be required to notify affected individuals and federal regulators based on the type and scale of the exposure. The organization would also need to determine whether identity-protection or other support services are appropriate.
The social media compromise introduces another area for investigation because unauthorized posts can create confusion about which statements are genuine. Patients and employees should rely on AnMed’s secured website, direct communications and verified telephone contacts for operational instructions.
They should also be cautious with unexpected messages claiming to concern appointments, test results, billing, prescription services or exposed records. Cybercriminals can exploit public awareness of a healthcare attack by sending fraudulent messages designed to obtain passwords, financial information or additional personal data.
AnMed has not announced whether it received a direct ransom demand, whether negotiations occurred or whether any payment has been considered. It has also not attributed the original network intrusion to a specific group.
The health system’s response now covers two connected security concerns: restoration of its clinical and administrative technology and recovery of control over its external communications. The investigation remains active as AnMed works to reopen affected facilities, secure its accounts and determine whether patient information was compromised.
🔥 NOW AVAILABLE! 🔥
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 1 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed
🔥 Kindle Edition 👉 https://a.co/d/9EoGKzh
🔥 Paperback 👉 https://a.co/d/9EoGKzh
🔥 Hardcover Edition 👉 https://a.co/d/0ITmDIB
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 2 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed just like the first one.
🔥 Kindle Edition 👉 https://a.co/d/1xlx7J2
🔥 Paperback 👉 https://a.co/d/a7vFHN6
🔥 Hardcover Edition 👉 https://a.co/d/efhu1ON
Get your copy today and experience poetry like never before. #InkAndFire #PoetryUnleashed #FuelTheFire
🚨 NOW AVAILABLE! 🚨
📖 THE INEVITABLE: THE DAWN OF A NEW ERA 📖
A powerful, eye-opening read that challenges the status quo and explores the future unfolding before us. Dive into a journey of truth, change, and the forces shaping our world.
🔥 Kindle Edition 👉 https://a.co/d/0FzX6MH
🔥 Paperback 👉 https://a.co/d/2IsxLof
🔥 Hardcover Edition 👉 https://a.co/d/bz01raP
Get your copy today and be part of the new era. #TheInevitable #TruthUnveiled #NewEra
🚀 NOW AVAILABLE! 🚀
📖 THE FORGOTTEN OUTPOST 📖
The Cold War Moon Base They Swore Never Existed
What if the moon landing was just the cover story?
Dive into the boldest investigation The Realist Juggernaut has ever published—featuring declassified files, ghost missions, whistleblower testimony, and black-budget secrets buried in lunar dust.
🔥 Kindle Edition 👉 https://a.co/d/2Mu03Iu
🛸 Paperback Coming Soon
Discover the base they never wanted you to find. TheForgottenOutpost #RealistJuggernaut #MoonBaseTruth #ColdWarSecrets #Declassified



