AnMed Investigating Ransomware Group’s Data Theft Claims
AnMed has not disclosed the name of the group behind the attack, but a threat group called The Gentlemen claimed responsibility. The Gentlemen is a ransomware-as-a-service group that is thought to include affiliates and operators from other prominent ransomware groups. The group has claimed several healthcare victims in recent months, and the pace of the attacks is accelerating. According to the Industrial Ransomware Analysis from the operational technology cybersecurity company Dragos, The Gentlemen was the third most active ransomware group in Q2 2026, claiming 125 attacks in the quarter alone, up from 83 attacks in Q1 – the largest gain out of all established ransomware groups. While the group ranked third, there were only 15 attacks separating the top three ransomware groups, with no single ransomware group dominating. In addition to adding AnMed to its dark web data leak site, the group posted a message on AnMed’s Facebook page on August 11, 2026, ramping up pressure on AnMed to negotiate a ransom payment. “Gentlemen, your confidential data has been exfiltrated. 6TB:...
Strict Rules Set for Change Healthcare Dataset in Multidistrict Litigation
The volume and sensitive nature of the data stolen from Change Healthcare in its 2024 ransomware attack have led to strict rules being established for data handling by attorneys involved in a consolidated lawsuit against United Health Group (UHG), Change Healthcare, Optum, and other UHG subsidiaries. The rules will help to ensure that the dataset is protected at all times. The ransomware attack resulted in the theft of approximately 6 terabytes of data, including files containing the electronic protected health information of an estimated 192,700,000 individuals, including names, contact information, Social Security numbers, driver’s license numbers, insurance information, and medical information. UHG paid the BlackCat ransomware group a $22 million ransom to delete the data; however, the operators pocketed the cash and didn’t pay the affiliate, who had retained a copy. The affiliate joined another ransom group, RansomHub, which attempted to extort UHG a second time. This was the largest-ever healthcare data breach by some distance, and triggered dozens of lawsuits, including class...
Critical Vulnerabilities Identified in Popular Consumer Fertility Device
Vulnerabilities have been identified in two consumer health and wellness devices – The Mira Hormone Monitor, a popular fertility tracking device, and the Pulsetto Vagus Nerve Stimulator. Vulnerabilities in the former could result in sensitive data exposure and data manipulation. The latter has a vulnerability that poses a safety risk to users. Mira Hormone Monitor & Mira Android App Multiple vulnerabilities have been identified in the Mira Hormone Monitor and its associated Android app that could expose sensitive health data, cause a denial-of-service condition, and allow an unauthorized individual to take control of user accounts and manipulate data, potentially resulting in failed fertility treatments, missed fertility windows, or unwanted pregnancies. The vulnerabilities were identified by a team of researchers at Northeastern University SPQR Lab. The research was partly funded by the Department of Health and Human Services’ Advanced Research Projects Agency for Health (ARPA-H) through a grant issued under the Universal Patching and Remediation for Autonomous Defense...
Data Breaches Announced by Five Small Healthcare Organizations
Five small healthcare organizations have recently announced that they have experienced security incidents exposing patient data: Family Medical Associates of Raleigh; Arkansas Oral & Maxillofacial Surgeons; Alpine Agency of the Midlands; Princeton Family Eye Care; and James C. Standring, DDS. Family Medical Associates of Raleigh, North Carolina Family Medical Associates of Raleigh, a multi-provider family medical practice in Raleigh, North Carolina, identified a potential cybersecurity incident on May 7, 2026, and activated its incident response protocol. Steps were immediately taken to investigate, contain, and remediate the incident; law enforcement was notified, and third-party cybersecurity professionals were engaged. The investigation and data review are ongoing; however, it has been confirmed that certain systems were intermittently accessed by an unauthorized third party between April 18, 2026, and April 20, 2026, who potentially downloaded internal data, including files containing patients’ protected health information. The data review has not yet been completed, but...
Healthcare Orgs Warned About Gunra Ransomware Attacks
CISA, the FBI, and international partners have issued a joint cybersecurity advisory about the Gunra ransomware-as-a-service (RaaS) operation, which is targeting government and critical infrastructure entities, including healthcare organizations, and organizations in other sectors. The group has conducted attacks in the Americas, Europe, Middle East, Africa, and Asia-Pacific, with attacks accelerating in 2026. Gunra ransomware was first identified as a financially motivated threat group in April 2025; however, in 2026, it transitioned into a RaaS group. The group is attempting to recruit experienced affiliates from other groups by offering an 80% cut of any generated ransoms, as well as initial access brokers who can deliver enterprise-scale footholds. The group primarily targets Windows systems and uses advanced encryption methods. In late 2025, the group also developed a Linux variant of its encryptor to allow cross-platform targeting. The encryptor is based on leaked Conti ransomware source code. The group engages in double extortion attacks, stealing sensitive data before...



