(WSPA) – It has been nearly one month since a major cyberattack hit the network of AnMed in Anderson. Now, the medical center confirms that the hackers stole private patient information. Just how much and who is impacted is still under investigation.
7NEWS Here to Help looked into the cyber gang claiming responsibility, why AnMed’s announcement took so long, and how patients and employees can protect themselves.
CYBERATTACK TIMELINE
There was a time when IT experts say even hackers considered hospital systems off limits to cyber extortion with the risk to human life. That day has passed.
And for AnMed, Sunday, July 26 is one the medical center will not soon forget.
The initial official statement described it as a “system disruption.” And in the days that followed the malware forced a shutdown of many AnMed Medical Group offices.
That same week, Brenda Fricks dropped her husband off at the ER where he had been many times of late. But this time, they couldn’t access his files.
“I took him down there and he stayed down there for about 10 hours at the emergency room,” Fricks explained. “Stayed in the waiting room. Did not get to see a doctor or nothing and then finally he just called me and told me to go ahead and get him.”
ANMED WARNS PATIENTS
27 days later, AnMed CEO William Kenley released a video addressing the breach.
“The investigation has now confirmed that cyber criminals did obtain some information from AnMed,” he said in the video. “Outside cyber security specialists are working with our team to help determine what that information is and who will be affected. The review is detailed and ongoing but as soon as we have more information about we will share those details with you.”
7NEWS INVESTIGATES
While AnMed said the attackers were “motivated by financial gain,” the medical center has yet to officially confirm the attack was a form of extortion called ransomware.
Still, several sources at the hospital not authorized to go on camera tell 7NEWS, from day one, an alarming message was appearing on virtually every computer screen in the system saying AnMed had “72 hours” to pay up.
IT expert David Hyde-Volpe, co-founder of the cybersecurity firm Vizius Group, said it has the trappings of extortion.
AnMed confirms data was taken in July cyberattack
While he is not associated with AnMed’s response to the breach, he said all signs point to ransomware.
“They will have known that very early on cause those attackers would have delivered a ransomware note,” said Hyde-Volpe.
WHY THE DELAY?
We asked him why, then, AnMed would wait to inform the public.
“Well there’s at least two veins of reason,” Hyde-Volpe explained. “One is just from a straight management public relations perspective being clear, having all the facts before you come out and say something is a common strategy. The other part of it, that people may not know as much, the way the whole ransom extortion thing works is it’s all about pressure.”
Hackers appear to post ransom message to AnMed Facebook page
That means the alleged gang behind the attack could potentially benefit from the public putting pressure on AnMed to pay. Which may explain what happened 2 weeks after the initial hack.
7NEWS obtained a screenshot of AnMed’s Facebook page the morning of August 11. The cybercrime syndicate known as “The Gentlemen,” claimed responsibility.
The post said they stole six terabytes of confidential data including “HIV+ patients, suicide registries, and sexual assault & rape victims.”
WHO ARE “THE GENTLEMEN”?
Hyde-Volpe said “The Gentlemen” are a known large sophisticated crime syndicate that makes millions from extortion.
“And they, we believe, operate out of Russia, and Russia is one of the states known to allow a lot of leeway to these to operate in the clear, so to speak, so they can put job postings out and hire people openly,” Hyde-Volpe said.
SERVICES STILL IMPACTED
In the video, AnMed’s CEO said “our team has worked hard to keep our services open.”
Still, Fricks said she was at the doctor this week and they were still operating on paper.
“It’s just been a mess. I mean, you try to call the doctors office you can’t get a hold of them, it’s just beep beep beep, then I’ve been having to go to the office to check on stuff,” said Fricks.
HOW TO PROTECT YOURSELF
If you are a current or former AnMed patient or employee you’d be wise to take some proactive steps.
-
Freeze your credit at all three major credit bureaus. Learn how at each agency.
-
Watch your financial accounts and medical records closely.
-
Monitor AnMed’s official site for any updates about the breach, as well as any correspondence from AnMed directly (though never click on any links and always verify).
In a written statement Friday, AnMed said, in part, “The individuals responsible may attempt to publish information, contact patients or employees, or make additional public claims. Anyone who receives a suspicious communication should not respond, click links, open attachments, provide personal information or make a payment.”
Fricks said she wants hospitals to be more transparent sooner, so that patients can protect themselves.
Copyright 2026 Nexstar Media, Inc. All rights reserved. This material may not be published, broadcast, rewritten, or redistributed.For the latest news, weather, sports, and streaming video, head to WSPA 7NEWS.