Cybersecurity

Veradigm Discloses Patient Data Breach After Gentlemen Gang Claims Attack

U.S. company Veradigm announced that a breach at one of its vendors enabled the copying of personal data and Social Security numbers belonging to a number of patients through a limited API. The Gentlemen gang claims to have stolen 3.5 million records, but the company has not confirmed this figure, and the investigation is ongoing.

2026-09-09
4 min read
14 views
فريق تحرير certi.news
Veradigm Discloses Patient Data Breach After Gentlemen Gang Claims Attack

Veradigm, a healthcare technology company, disclosed a data breach resulting from the compromise of one of its external vendors’ environments. The company said in a filing with the U.S. Securities and Exchange Commission that an attacker obtained credentials from the vendor’s environment, then used them to access an API dedicated to customer services and copy patient data.

The data that Veradigm acknowledged was exposed includes personal details and Social Security numbers belonging to some patients, while the company said clinical and medical information was not affected. It also explained that the compromised credentials provided access only to that limited interface and did not allow access to its broader network, servers, databases, or other systems.

What happened?

Veradigm discovered the incident and began response procedures. It also notified law enforcement agencies and launched an investigation to determine the scope of the impact. The company confirmed that the incident did not cause operational disruptions and said it affected a small number of customers, according to the information currently available to it. It reported that affected customers and individuals are being notified, with credit-monitoring services provided where applicable.

The company did not identify the party behind the attack in its disclosure. However, the ransomware group The Gentlemen claimed responsibility for the breach on September 5 and listed Veradigm on its data-leak site. The group claims to possess 3.5 million patient records containing full names, addresses, Social Security numbers, email addresses, phone numbers, personal identification data, or information about guarantors. It threatened to publish the data by September 11 if the company did not enter ransom negotiations.

The larger claim has not yet been resolved

Veradigm’s disclosure does not substantiate the number announced by the gang; it only indicates that personal data belonging to some patients was exposed and that the investigation is ongoing. Therefore, the gap between the company’s description of the incident as limited and the group’s claim that it stole millions of records remains a crucial issue requiring additional evidence or investigative findings.

The Gentlemen group emerged around the middle of 2025 and uses a double-extortion model that combines data theft with systems encryption. According to the source material, the group announced more than 800 victims in 86 countries and across multiple sectors, including healthcare, technology, manufacturing, transportation, and financial services. Check Point also linked, in April 2026, a botnet operating with SystemBC malware and comprising more than 1,500 hosts to one of the group’s partners, while ESET said in June 2026 that the group uses a tool for disabling endpoint detection and response solutions known as GentleKiller.

Why does this news matter?

The incident demonstrates that compromising an external vendor account can enable access to sensitive data even when the attack does not extend to the company’s internal network or core systems. Restricting access to an API also does not eliminate the impact of an incident if the interface can return patient-identifying data. For customers and individuals, the nature and actual number of affected records remain the most important open questions.

Veradigm says it does not currently expect a material impact on its business, operations, or financial position. However, this assessment is temporary, as it depends on the current investigation results and may change if the scope of the affected data expands or The Gentlemen’s claims are confirmed. Monitoring official notifications and investigation results remains essential before accepting the group’s figures or considering the medical data fully protected.

News source
BleepingComputer
Open original source ↗
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news