AnMed unauthorized Facebook posts appeared as the nonprofit hospital system continued to recover from a cybersecurity disruption involving malware that it identified on July 26. AnMed said it removed the posts, disabled access through the platform and was working with the provider to secure its accounts.
The confirmed account issue adds another problem to an incident that had already disrupted operations across AnMed’s network of four hospitals and other clinics in Georgia and South Carolina. The Record reported that, as of the referenced Monday, 10 AnMed facilities remained closed to appointments.
What has AnMed confirmed about the unauthorized Facebook posts?
AnMed said it found unauthorized posts on its social-media accounts and removed the content. A spokesperson said the organization had disabled access through the platform while it worked with the provider to secure the accounts, and that cybersecurity specialists were investigating as part of the response to the July 26 incident.
Reporting by The Record said AnMed’s Facebook page was removed from Facebook after the messages appeared. The material available does not establish how the posts were placed on the page or independently confirm a takeover of the account.
Data-theft claims remain unverified
The messages were attributed to people claiming to represent the ransomware group The Gentlemen. They asserted that they had taken 6 terabytes of data, including sensitive health-related records. The Record reported that the posters supplied no evidence for that assertion.
AnMed said it had not verified the claims in the posts and had not confirmed the scope of any potential effect on patient information. That leaves several central questions unanswered: whether data was taken, whether patient records were affected, and whether the people behind the posts were involved in the malware disruption.
When AnMed first disclosed the incident, it said it was restoring systems after a cybersecurity disruption involving malware. It later began publishing daily updates on which offices were open or closed, according to The Record. The 10-facility figure refers to locations closed to appointments, not a system-wide shutdown of AnMed hospitals or services.
What is known about The Gentlemen?
The Record described The Gentlemen as a ransomware-as-a-service operation that emerged in the second half of 2025. Security firms cited in its reporting have analyzed the group’s alleged tactics and victim claims, but that background is not confirmation that the group carried out AnMed’s underlying cyber incident or the unauthorized social-media activity.
For patients, the current status is narrower than the ransom-post claims: AnMed has confirmed unauthorized posts and continuing recovery work, while it investigates the incident and works to secure its social-media accounts.
This story draws on original reporting from The Record.