AnMed says claims in ransom messages posted on Facebook by suspected hackers have not been verified
AnMed, the major health system based in Anderson, says it has made significant progress in restoring its systems and communications following the cyberattack identified on July 26.
AnMed said Tuesday evening that care teams now have full read/write access to patients’ electronic health records, allowing them to view and electronically update medical records.
Beginning at 7 a.m. Wednesday, patients can once again call their doctors’ offices and other departments directly during regular service hours with questions regarding their care.
The investigation remains ongoing.
The update comes after nearly 100 ransom messages were posted by suspected hackers on its Facebook page Tuesday morning.
These ransom messages claimed that six terabytes of critical information, including patient records, had been leaked. AnMed responded Tuesday afternoon by stating the claims contained in the posts have not been verified.
AnMed said that its cybersecurity specialists are investigating Tuesday morning’s incident as part of the organization’s ongoing response to the cyberattack in July.
Keep up with what’s happening around our area by downloading theWYFF News 4 appon the App Store or Google Play.
AnMed stated, “If the investigation determines personal information was affected, AnMed will provide appropriate notifications and additional information as it becomes available.”
The organization also said that the unauthorized content was removed and access through the platform was disabled. AnMed’s cybersecurity specialists are working with the provider to secure the accounts and investigate the incident.
What Happened on Facebook?
The first post, labeled as AI generated content and littered with grammatical errors, was posted about 9:40 a.m. Tuesday. It was taken down shortly after that.
(Video below shows what the page looked like before it was taken down)
The first message said: “Gentlemen, your confidential data has been exfiltrated. We have full access to your corporate network and have extracted all critical information — 6 terabytes.Patient records containing DOB, SSN, addresses, medical histories, prescriptions,laboratory results, and detailed medical files1Mental and behavioral health records, suicide attempts and ideation databases,pediatric and psychiatric reportsHIV-related data, reproductive and abortion records, prenatal and NIPT testingGenetic and molecular pathology data (DNA information)Biometric data, identification documents, forensic and autopsy recordsSexual assault, harassment, and rape victim recordsbase of the patients with DOB, SSN, home addresses and some medical info.- HIV-positive pregnant women’s list- Data base of the cancer diagnosis – Confidential papers about the abortions and reproductive health- Fingerprint reports and scans- Mental health data bases – Drug and alcohol tests and reports- Hundreds of prenatal and NIPT (Non-Invasive Prenatal Testing)- prescriptions’s data – personal ID cards, passports, SSNs and DL- detailed medical records- data base of the mental and behavoral health patients — Data base of all registered suicide atempts with details – Genetic markers and notes – Full data base of the mental and behavoral health patients – Data base of the forecnic reports – HIV-positive data base (medication and treatment details) – Abortions data base- Sexual harassment incidents registered in details – Testimonies of rape victims and the gallery from the Police departement- sexual assault pictures and charts , including intimate details and foto- autopsy’s reports and pictures, including criminal case relatedWe guarantee complete data deletion and confidentiality in the event of cooperation and payment within the deadline. To verify that we possess your data, you may request samples of specific files — we will provide them immediately.”
Then, just after 10 a.m., a shorter message was posted nearly 100 times.Within the next hour, the AnMed Facebook page was made unavailable.
Phil Yanov, a Cybersecurity expert with Tech After 5, said it could take weeks or months for the attack to settle and assess the aftermath.
“Why are hospitals vulnerable? Well, hospitals are big, they’re complicated. And there’s lots of third-party vendors. When we think about what their security profile is and what the threat surface is, it’s very large,” Yanov said. “The data in a hospital is more valuable than maybe getting it from somewhere. If someone comes after you and they get your credit card, what are you going to do? You’re going to go change your credit card number and it goes away. You can’t change your Social Security number. You can’t change your medical history. You can’t change all of these other things.”
Yanov said “The Gentlemen” is an online criminal group who are hired for ransomware-as-a-service jobs. We asked why we would see this two weeks after the initial attack was reported:
“This is pressure on AnMed. This is pressure to pay. Right? Why would I put this message up? I want all of your customers, all of your patients to know I’ve got data,” Yanov said.
Brian Cain is a patient who say this message and immediately felt panic in his chest.
“I didn’t know if it was real or not,” Cain said.
AnMed Cyberattack
The cyberattack was first reported on July 26.
At that time, AnMed provided the following message to patients:
“We are currently experiencing a cybersecurity disruption involving malware that is impacting our network. We are working diligently to return our systems to full functionality as quickly as possible with the assistance of third-party cybersecurity specialists as well as state and federal authorities.
In the following days, AnMed did set up a website and phoneline for patientswith questions.
For Cain, this has become more than a minor inconvenience. He is waiting on urgent testing, and his wife is permanently disabled. Not only this, but his family has trusted AnMed for generations.
“Myself, my wife, my kids, each and every one of us were born within those walls. We’ve entrusted them with our care for many years, many decades,” Cain said. “No one knew that this is coming. There’s evil in this world that exist. And unfortunately, they picked the most horrible target and of all places: Anderson, South Carolina.”
AnMed launching patient phone line as cyberattack recovery continues:
WYFF 4 continues to look for answers after hospital cyberattack:
AnMed continues to suffer from cyberattack
WYFF 4 continues to look for answers after cyberattack at AnMed Medical Center
Patients flow into surrounding Upstate hospital systems
Cain knows patients who have started relying on surrounding hospitals in the Upstate for critical care.
“I don’t feel safe. In a medical emergency I can’t go five minutes up the road, I have to go an hour up the road. We’re left in limbo. And so is our healthcare,” Cain said.
Prisma, which is sorting through its own connectivity issues, is one of them.
Staff said they worked overnight without access to connective equipment or devices and relied on pen and paper to log medications and vitals. Some patients are able to see their MyChart and others cannot.
A spokesperson for Prisma tells WYFF News 4 they are operating under downtime procedures and there is no indication their issue is related to cybersecurity.
What can you do?
Patients have reported seeing requests to pay bills or verify information in the MyChart app.
Yanov recommends avoiding any suspicious links or messages from numbers or emails appearing as AnMed. He adds this can be used to install software or hack into your devices.
You are being asked to avoid doing so while the app remains down. Instead, check with an AnMed representative to ensure you are not being targeted by a scam. If you do see any suspicious activity, report it immediately.
Healthcare workers are asking for patience and understanding as they work around the issue to deliver critical care.
