Veradigm Breach Linked To Gentlemen Ransomware's Growing Arsenal

Veradigm, a Chicago-based healthcare technology company formerly known as Allscripts, has disclosed a data breach affecting a limited number of its customers. The company disclosed the incident in a filing with the U.S. Securities and Exchange Commission on September 8, 2026. Attackers compromised a third-party vendor's credentials and used them to access a customer-service API. Veradigm stated that the breach did not disrupt daily operations across its electronic health record and practice management platforms.

Veradigm Breach Linked To Gentlemen Ransomware's Growing Arsenal

Veradigm supplies thousands of hospitals, clinics, and biopharmaceutical firms across the United States with e-prescribing, patient engagement, and revenue cycle software. The company's electronic health records systems support a wide range of medical practices, making it a significant target for cybercriminals seeking patient data.

According to the SEC filing, the stolen vendor credentials granted access only to a narrow interface reserved for customer services. The attacker then used that limited access to copy certain patient records without touching the company's broader network. Personal details and Social Security numbers for some patients were exposed, though clinical and medical information remained untouched.

Veradigm emphasized that the compromised credentials never reached its internal servers, databases, or other core systems. The company explained in its filing that,

the vendor's compromised credentials provided access only through that limited interface and did not provide access to any other part of the Company's environment, including the Company's broader network, servers, databases, or other systems.

After discovering the intrusion, Veradigm activated its incident-response procedures and alerted law enforcement authorities to the breach. Affected individuals and customers are now being notified, and credit-monitoring services are being offered where applicable.
Veradigm has not publicly named the attacker responsible for the breach, but a ransomware group has already claimed credit. The Gentlemen ransomware operation listed Veradigm on its dark web leak site on September 5, 2026, days before the SEC filing was made public.

The group claims to be holding roughly 3.5 million patient records, including names, addresses, and Social Security numbers. It has threatened to publish the stolen data on September 11 unless Veradigm opens ransom negotiations. The group's leak site listing includes personally identifiable information about guarantors, along with phone numbers and email addresses. This tactic, commonly known as double extortion, pressures victims by combining the threat of encryption with the promise of public exposure of data.

The Gentlemen ransomware operation first surfaced in mid-2025 and now runs as a double-extortion, ransomware-as-a-service business. Affiliates steal data before encrypting victim systems, then threaten public exposure to pressure organizations into paying. The group's malware can encrypt Windows, Linux, network-attached storage, BSD, and VMware ESXi environments across a wide range of industries.

Its data leak site currently lists more than 800 victims spanning 86 countries, suggesting broadly opportunistic targeting rather than a narrow focus. Analysts note that the group appears to select victims primarily based on available access rather than industry preference or strategic planning. This opportunistic approach has allowed the operation to expand rapidly despite its relatively recent emergence within the ransomware landscape.

The Gentleman refines its Toolset

Recent research indicates the group has grown considerably more sophisticated since its emergence, expanding well beyond simple file encryption. In April 2026, Check Point researchers investigated an affiliate attack and uncovered a SystemBC proxy malware botnet comprising more than 1,570 infected hosts. The researchers said the infection profile "strongly suggesting a focus on corporate and organizational environments rather than opportunistic consumer targeting." Most infected systems traced back to organizations in the United States, the United Kingdom, Germany, Australia, and Romania.

Check Point's investigation also detailed how a Gentlemen affiliate operated from a compromised domain controller with Domain Admin privileges. The attacker tested stolen credentials, conducted reconnaissance, and then deployed Cobalt Strike payloads across remote systems via RPC calls. Mimikatz supported credential harvesting, while Group Policy objects triggered near-simultaneous ransomware execution across every domain-joined machine. Before encrypting files, the malware terminated database, backup, and virtualization processes and deleted shadow copies to block recovery.

By June 2026, researchers at ESET had uncovered an even more advanced layer of the group's toolkit. The Gentlemen operation actively develops and maintains a custom endpoint detection and response killer known as GentleKiller. This tool exists in at least eight variants, each impersonating legitimate security products such as Kaspersky, Valorant, and WatchDog. Every variant abuses the "bring your own vulnerable driver" technique to gain kernel-level privileges and disable installed defenses.

ESET reported that GentleKiller targets more than 400 processes associated with approximately 48 security vendors and products. Beyond its custom tool, The Gentlemen operation has assembled a broader arsenal of defense-evasion utilities for its affiliates. The group's expanding toolkit now includes several notable components:

  • GentleKiller, a custom EDR killer with at least eight variants that impersonate trusted security brands
  • HexKiller, a tool previously associated with the Warlock ransomware operation
  • ThrottleBlood, previously linked to the MesudaLocker and DragonForce ransomware groups
  • HavocKiller, another EDR-disabling utility, was observed in separate ransomware campaigns
  • OxideHarvest, a Rust-based credential-stealing tool believed to be sourced from an external developer

ESET suggested that Gentlemen affiliates may deploy these additional tools for redundancy or to complicate investigators' attribution efforts. The researchers also noted that GentleKiller's binaries rely on commercial packing tools and carry stolen, invalid digital signatures. This layered evasion strategy has helped the ransomware operation compromise organizations across the manufacturing, technology, transportation, and financial services sectors.

Security researchers have observed a consistent operational pattern across the group's documented intrusions and victim data over the past year:

  • The group publicly claims around 320 confirmed victims, with most attacks concentrated within the current year
  • Attackers reportedly prioritize targets based on the configuration of exposed FortiGate VPN endpoints
  • Prior victims include Romania's Oltenia Energy Complex and technology consultancy The Adaptavist Group

The Veradigm incident illustrates how vendor-side security gaps continue to expose sensitive healthcare data even when core systems remain protected. Organizations that share data or system access with third-party vendors face growing risk from credential theft targeting those external partners. This dynamic has become increasingly common across the healthcare sector, where interconnected vendor relationships often create overlooked attack surfaces.

Healthcare providers and technology vendors alike should enforce strict access controls, multifactor authentication, and continuous monitoring on all vendor-facing interfaces. Regular audits of third-party API permissions can also help organizations detect unauthorized access before large-scale data theft occurs. As The Gentlemen ransomware group continues to refine its toolkit, defenders must treat EDR-killing malware and stolen credentials as immediate warning signs of a larger breach.

Veradigm's investigation into the scope and impact of the breach remains ongoing as of this writing. The company maintains that, based on the information currently available, the incident is unlikely to materially affect its overall business or financial condition. Whether The Gentlemen group follows through on its threat to leak the stolen patient data remains to be seen. Organizations across the healthcare sector should closely monitor developments, given the group's demonstrated pattern of following through on extortion threats against non-paying victims.

Share:

facebook
X (Twitter)
linkedin
copy link
Karolis Liucveikis

Karolis Liucveikis

Experienced software engineer, passionate about behavioral analysis of malicious apps

Author and general operator of PCrisk's News and Removal Guides section. Co-researcher working alongside Tomas to discover the latest threats and global trends in the cyber security world. Karolis has experience of over 8 years working in this branch. He attended Kaunas University of Technology and graduated with a degree in Software Development in 2017. Extremely passionate about technical aspects and behavior of various malicious applications.

▼ Show Discussion

PCrisk security portal is brought by a company RCS LT.

Joined forces of security researchers help educate computer users about the latest online security threats. More information about the company RCS LT.

Our malware removal guides are free. However, if you want to support us you can send us a donation.

Donate