INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Veradigm Warns of Patient Data Breach After Ransomware Attack

| 2026-09-09 15:31 CRITICAL LOW RANSOMWARE & EXTORTION DATA BREACH
Executive Summary
AI-generated
On September 9, 2026, a cybersecurity incident at one of Veradigm's third-party vendors exposed patients' personal data, including Social Security numbers for some individuals. The attacker obtained credentials from the vendor's environment and used them to copy patient data, which includes full names, home addresses, SSNs, email addresses, phone numbers, and personally identifiable information. This attack is attributed to The Gentlemen ransomware gang, a double-extortion group that combines data theft with encryption on various systems. Thousands of hospitals, clinics, and biopharmaceutical firms across the United States use Veradigm's solutions, which were affected by this incident.
Technical Mitigations AI-generated
• Use a secure API key rotation policy to limit access to customer services interfaces. • Implement endpoint detection and response (EDR) solutions, such as GentleKiller, to detect and respond to attacks by The Gentlemen ransomware gang. • Regularly monitor for SystemBC proxy malware botnet activity and implement measures to block or hunt for it.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
SystemBCSystemBC
Target & Sectors
NORTH_AMERICA NORTH_AMERICA healthhealth technologytechnology
Incident Timeline
‎mid-2025
The Gentlemen ransomware gang claimed a patient data breach, prompting Veradigm to warn of the incident.
tactic Extortion
infrastructure Windows
infrastructure Linux
organisation NAS
organisation BSD
‎April 2026
Threat actors affiliated with The Gentlemen ransomware gang used a SystemBC proxy malware botnet to compromise over 1,500 hosts.
tactic Ransomware
tactic Botnet
malware SystemBC
infrastructure 1,500 hosts
‎June 2026
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
organisation ESET
organisation EDR
organisation GentleKiller
organisation The Blue Report 2026
‎September 5
The Gentlemen ransomware group claimed a patient data breach at Veradigm on September 5.
tactic Data Leak
tactic Ransomware
‎2026/09/09
A ransomware gang claimed to be holding 3.5 million patient records, including full names, home addresses, SSNs, and personally identifiable information, after breaching a Veradigm API reserved for customer services through compromised vendor credentials.
organisation Veradigm
organisation Allscripts Healthcare Solutions
victims 800 victims
organisation the U.S. Securities and Exchange Commission
organisation SEC
organisation Social Security
organisation Company
data_breach 3.5 patient records
‎Friday, September 11
A ransomware gang threatened to leak stolen patient data by Friday, September 11, unless Veradigm pays for a ransom payment negotiation.
tactic Ransomware
Tactical Metrics
Metrics
victims
800
Victims
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎Linux
Affected Product
Metrics
infrastructure
1,500
Hosts
Metrics
data_breach
3,500,000
Patient Records
Intelligence Sources