INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Veradigm Warns of Patient Data Breach After Ransomware Attack
| 2026-09-09 15:31 CRITICAL LOW RANSOMWARE & EXTORTION DATA BREACH
Executive Summary
AI-generated
On September 9, 2026, a cybersecurity incident at one of Veradigm's third-party vendors exposed patients' personal data, including Social Security numbers for some individuals. The attacker obtained credentials from the vendor's environment and used them to copy patient data, which includes full names, home addresses, SSNs, email addresses, phone numbers, and personally identifiable information. This attack is attributed to The Gentlemen ransomware gang, a double-extortion group that combines data theft with encryption on various systems. Thousands of hospitals, clinics, and biopharmaceutical firms across the United States use Veradigm's solutions, which were affected by this incident.
Technical Mitigations AI-generated
• Use a secure API key rotation policy to limit access to customer services interfaces.
• Implement endpoint detection and response (EDR) solutions, such as GentleKiller, to detect and respond to attacks by The Gentlemen ransomware gang.
• Regularly monitor for SystemBC proxy malware botnet activity and implement measures to block or hunt for it.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
SystemBCSystemBC
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
healthhealth
technologytechnology
Incident Timeline
mid-2025
The Gentlemen ransomware gang claimed a patient data breach, prompting Veradigm to warn of the incident.
Click on any entity below to view its context and source!
tactic
Extortion
The Gentlemen extortion page
Source: BleepingComputer.com
The Gentlemen threat actor emerged around mid-2025 and operates as a double-extortion group, combining data theft with data encryption on Windows, Linux, NAS, BSD, and ESXi systems.
infrastructure
Windows
The Gentlemen extortion page
Source: BleepingComputer.com
The Gentlemen threat actor emerged around mid-2025 and operates as a double-extortion group, combining data theft with data encryption on Windows, Linux, NAS, BSD, and ESXi systems.
infrastructure
Linux
The Gentlemen extortion page
Source: BleepingComputer.com
The Gentlemen threat actor emerged around mid-2025 and operates as a double-extortion group, combining data theft with data encryption on Windows, Linux, NAS, BSD, and ESXi systems.
organisation
NAS
The Gentlemen extortion page
Source: BleepingComputer.com
The Gentlemen threat actor emerged around mid-2025 and operates as a double-extortion group, combining data theft with data encryption on Windows, Linux, NAS, BSD, and ESXi systems.
organisation
BSD
The Gentlemen extortion page
Source: BleepingComputer.com
The Gentlemen threat actor emerged around mid-2025 and operates as a double-extortion group, combining data theft with data encryption on Windows, Linux, NAS, BSD, and ESXi systems.
April 2026
Threat actors affiliated with The Gentlemen ransomware gang used a SystemBC proxy malware botnet to compromise over 1,500 hosts.
Click on any entity below to view its context and source!
tactic
Ransomware
In April 2026,
Check Point reported
that it discovered a SystemBC proxy malware botnet with more than 1,500 hosts and linked it to an affiliate of The Gentlemen ransomware gang.
tactic
Botnet
In April 2026,
Check Point reported
that it discovered a SystemBC proxy malware botnet with more than 1,500 hosts and linked it to an affiliate of The Gentlemen ransomware gang.
malware
SystemBC
In April 2026,
Check Point reported
that it discovered a SystemBC proxy malware botnet with more than 1,500 hosts and linked it to an affiliate of The Gentlemen ransomware gang.
infrastructure
1,500 hosts
In April 2026,
Check Point reported
that it discovered a SystemBC proxy malware botnet with more than 1,500 hosts and linked it to an affiliate of The Gentlemen ransomware gang.
June 2026
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
Click on any entity below to view its context and source!
organisation
ESET
In June 2026,
ESET said
that The Gentlemen was employing a new endpoint detection and response (EDR) killer called GentleKiller.
organisation
EDR
In June 2026,
ESET said
that The Gentlemen was employing a new endpoint detection and response (EDR) killer called GentleKiller.
organisation
GentleKiller
In June 2026,
ESET said
that The Gentlemen was employing a new endpoint detection and response (EDR) killer called GentleKiller.
organisation
The Blue Report 2026
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
September 5
The Gentlemen ransomware group claimed a patient data breach at Veradigm on September 5.
Click on any entity below to view its context and source!
tactic
Data Leak
The Gentlemen ransomware claims the attack
Although Veradigm's disclosure did not identify the attacker, The Gentlemen ransomware group has claimed the intrusion on September 5 and listed the company on its data leak site.
tactic
Ransomware
The Gentlemen ransomware claims the attack
Although Veradigm's disclosure did not identify the attacker, The Gentlemen ransomware group has claimed the intrusion on September 5 and listed the company on its data leak site.
2026/09/09
A ransomware gang claimed to be holding 3.5 million patient records, including full names, home addresses, SSNs, and personally identifiable information, after breaching a Veradigm API reserved for customer services through compromised vendor credentials.
Click on any entity below to view its context and source!
organisation
Veradigm
Healthcare technology company Veradigm disclosed a data breach after a cybersecurity incident at one of its third-party vendors exposed patients' personal data.
organisation
Allscripts Healthcare Solutions
The company says the incident did not cause operational disruptions but affected a small number of customers.
Formerly known as Allscripts Healthcare Solutions, Veradigm is a Chicago-based healthcare technology company that supplies medical practices with electronic health records, e-prescribing, patient-engagement, practice-management, and revenue-cycle software.
victims
800 victims
On its data leak site, the gang listed more than 800 victims from 86 countries and various sectors, including manufacturing, technology, healthcare, transportation, and financial services, indicating opportunistic attacks that rely only on access availability.
organisation
the U.S. Securities and Exchange Commission
The company says in a filing with the U.S. Securities and Exchange Commission (SEC) that an attacker obtained credentials from a vendor’s environment for a Veradigm API reserved for customer services.
organisation
SEC
The company says in a filing with the U.S. Securities and Exchange Commission (SEC) that an attacker obtained credentials from a vendor’s environment for a Veradigm API reserved for customer services.
organisation
Social Security
Veradigm's disclosure notes that the stolen data includes personal details and Social Security numbers (SSNs) for some of the patients.
organisation
Company
“The vendor’s compromised credentials provided access only through that limited interface and did not provide access to any other part of the Company’s environment, including the Company’s broader network, servers, databases, or other systems,” the company says in the
SEC filing
.
data_breach
3.5 patient records
The threat actor alleges to be holding 3.5 million patient records that include full names, home addresses, SSNs, email addresses, phone numbers, and personally identifiable information or guarantors.
Friday, September 11
A ransomware gang threatened to leak stolen patient data by Friday, September 11, unless Veradigm pays for a ransom payment negotiation.
Click on any entity below to view its context and source!
tactic
Ransomware
The ransomware actor threatens to leak the stolen data by Friday, September 11, if the company doesn't engage in a ransom payment negotiation.
Tactical Metrics
Metrics
victims
800
Victims
Click for context!
On its data leak site, the gang listed more than 800 victims from 86 countries and various sectors, including manufacturing, technology, healthcare, transportation, and financial services, indicating opportunistic attacks that rely only on access availability.
Metrics
infrastructure
Windows
Affected Product
The Gentlemen extortion page
Source: BleepingComputer.com
The Gentlemen threat actor emerged around mid-2025 and operates as a double-extortion group, combining data theft with data encryption on Windows, Linux, NAS, BSD, and ESXi systems.
Metrics
infrastructure
Linux
Affected Product
The Gentlemen extortion page
Source: BleepingComputer.com
The Gentlemen threat actor emerged around mid-2025 and operates as a double-extortion group, combining data theft with data encryption on Windows, Linux, NAS, BSD, and ESXi systems.
Metrics
infrastructure
1,500
Hosts
In April 2026,
Check Point reported
that it discovered a SystemBC proxy malware botnet with more than 1,500 hosts and linked it to an affiliate of The Gentlemen ransomware gang.
Metrics
data_breach
3,500,000
Patient Records
The threat actor alleges to be holding 3.5 million patient records that include full names, home addresses, SSNs, email addresses, phone numbers, and personally identifiable information or guarantors.
Intelligence Sources
BleepingComputer
2026-09-09
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-06T11:54
Comprehensive Tactical Telemetry
Highly Correlated Entities
12x
organisation
Identified Entity
Veradigm
entity
5x
industry
Targeted Sector
Healthcare
sector
5x
tactic
Cyber Operation Type
Data Breach
tactic
5x
timeline
Temporal Reference
September 5
date
2x
infrastructure
Affected Product
Windows
software
Contextual Telemetry
Context Block
8 METRICS
target region
Target Country
United States
country
victims
Victims
800
victims
general metric
Countries
86
countries
malware
Malware Payload
SystemBC
tool
infrastructure
Hosts
1,500
hosts
general metric
Blue Report
2,026
blue report
general metric
Simulations
338,000,000
simulations
data breach
Patient Records
3,500,000
patient records
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.