Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-09-10 ยท updated: 2026-09-10 ยท tags: [incident, healthcare, breach, ransomware, vendor-credentials] ยท confidence: reported ยท affected_sectors: [healthcare, technology] ยท au_impact: false

Healthcare technology provider Veradigm (formerly Allscripts) disclosed in an SEC filing that an attacker obtained credentials from a third-party vendor's environment for a Veradigm customer-services API and used them to copy patient data, including personal details and Social Security numbers for some patients; clinical or medical information was not accessed and access was limited to that interface. Separately, The Gentlemen ransomware group claimed the intrusion, listing Veradigm on its leak site on 5 September and alleging it holds 3.5 million patient records, threatening to leak them if no ransom is negotiated by 11 September. Veradigm said the incident did not materially affect operations and is notifying affected customers with credit monitoring, while law enforcement was notified.

Attribute Detail
Date Disclosed 2026-09-08/09; claimed 2026-09-05
Type Third-party vendor credential compromise โ†’ data exfiltration
Breach Confirmed breach (victim SEC disclosure); scale per gang 3.5M records
Source BleepingComputer โ€” Tier 2/4

Source