~/f4n6 $ grep -r "Ransomware: thegentlemen named Veradigm (US)" ./investigations/ --include="*.md"

Ransomware: thegentlemen named Veradigm (US)

Jeff Davies 05 Sep 2026 4 min read


1. Executive summary

On 5 September 2026, ransomware group "thegentlemen" listed US healthcare technology firm Veradigm (veradigm.com) on its leak site, claiming the theft of 3.5+ million personal patient records containing PII — full name, address, Social Security number, email, phone number and guarantor PII. Veradigm operates one of the largest multi-EHR data networks in US healthcare (450,000+ connected providers, 200M+ patient records), so the claimed dataset is plausibly high-value clinical and financial data. Attribution to "thegentlemen" is unconfirmed — the group has no MITRE ATT&CK profile in our verified reference data, and the claim rests entirely on the group's own leak-site posting. No encryption event, initial access vector, malware family or exploitation of any CVE is evidenced in the source material; this is a data-theft/extortion listing, not a confirmed ransomware deployment. EMEA financial services clients are not direct victims, but should treat this as a third-party/supply-chain data exposure event: Veradigm's payer and life-sciences analytics segments mean healthcare and insurance counterparties may hold shared data flows.

2. Regulatory framing

No specific DORA/NIS2 article is directly engaged by this item. The victim is a US healthcare entity; the source material contains no evidence of EMEA financial-services impact, no confirmed incident at a client, and no ICT third-party relationship that can be asserted from the available facts. Clients with a documented contractual relationship with Veradigm or its data-network partners should assess that relationship under their own ICT third-party risk framework (DORA Art. 28: ICT third-party risk — general principles) — but that assessment is client-specific and cannot be presumed here.

3. Technical analysis & attack chain

No confirmed attack chain can be reconstructed from the source material. The only primary artefact is the thegentlemen leak-site listing itself, which asserts a breach and a claimed dataset but provides no technical detail on how access was obtained.

What the source establishes

  1. Listing event. thegentlemen posted Veradigm to its victim leak site on/around 5 September 2026, claiming 3.5+ million personal patient records with PII: full name, address, Social Security number, email, phone number, and guarantor PII.
  2. Victim profile. Veradigm Inc. (OTC: MDRX), formerly Allscripts, headquartered in Chicago, ~2,300–2,600 employees. Revenue segments: Provider (EHR, practice management, revenue cycle — $473M in 2024), Payer (quality/risk-adjustment analytics — $67.3M), Life Sciences (real-world data and AI-driven evidence — $54M). Network scale: 450,000+ connected providers, 200M+ patient records.
  3. Exposure context (single-sourced, from the leak-site page's Hudson Rock-sponsored sidebar): the listing page reports 6 compromised users, 0 compromised employees, 3 third-party employee credentials, and an external attack surface count of 4 for the victim's domain. These are automated enrichment figures attached to the listing, not evidence of the actual intrusion path. Treat as low-confidence context only.

What the source does NOT establish — and we will not speculate on

  • No initial access vector, exploited CVE, or vulnerability mechanism is described.
  • No malware, payload, persistence, C2, or lateral movement detail exists.
  • No encryption or system-impact claim is made — the listing describes data theft and PII exposure. We do not characterise this as a confirmed ransomware deployment; "ransomware group" here means the extortion-site actor category, and the observed activity is data-theft/extortion.
  • No sample data, file trees, or archive listings are available in the source.

Confidence caveat: Every substantive claim in this section is single-sourced — it derives from the thegentlemen leak-site listing as indexed by ransomware.live. Ransomware.live explicitly does not access or verify the underlying stolen data; the record count and PII composition are the actor's own claims. Verify before enforcement or notification action.

4. Mitigation & containment

There are no technical containment actions against the threat itself available from this source — no CVE to patch, no malware to block. Actions are exposure- and relationship-driven:

P1 — within 24h

  • Determine whether your organisation has a data relationship with Veradigm, its EHR network, or its Payer/Life Sciences analytics products. If yes, identify what client, patient, or counterparty data flows into or is shared with that estate.
  • Check your third-party register and contracts for Veradigm/Allscripts entities (the 2023 rename means older contracts may be under the Allscripts name).

P2 — within 72h

  • For confirmed relationships: request an incident statement from the vendor covering scope, data types, and whether your data is implicated. Do not rely on the actor's claimed record count.
  • If shared data may include EEA/UK data subjects, engage your data-protection lead for GDPR assessment — this is a client-specific determination outside this advisory's scope.

P3 — within 7 days

  • Review whether any of your own credentials or accounts relate to the "compromised users / third-party employee credentials" counts on the listing page (single-sourced enrichment data — treat as a prompt to check, not as evidence).
  • If no relationship exists, close the item with a no-impact determination on record.

5. Indicators of compromise

No indicators of compromise available in the source material. The listing provides no hashes, domains, IPs, URLs, filenames, or infrastructure beyond the victim's own legitimate domain (veradigm.com), which is not an IOC.

6. Detection

Insufficient indicators to author detection rules.

7. Sources

  • Ransomware.live — Victim: Veradigm – thegentlemen — https://www.ransomware.live/id/VmVyYWRpZ21AdGhlZ2VudGxlbWVu — 2026-09-05
  • Hudson Rock enrichment data (compromised user/credential counts) as displayed on the above listing page — https://www.ransomware.live/id/VmVyYWRpZ21AdGhlZ2VudGxlbWVu — accessed 2026-09-06

8. Adverse Trace position

This is a leak-site extortion listing with no corroborated technical detail: no CVE, no malware, no attack chain, and an actor ("thegentlemen") with no MITRE ATT&CK profile in our verified reference data — attribution and the claimed 3.5M-record breach are both unconfirmed and single-sourced to the actor's own posting. Severity for EMEA financial services clients is low-to-moderate and entirely contingent on third-party exposure: the risk is data-theft fallout through Veradigm's payer and life-sciences data relationships, not a directly exploitable vulnerability or a threat to client infrastructure. We are monitoring for independent confirmation of the breach, a Veradigm disclosure, sample-data release, or any technical reporting that establishes initial access; we will reissue with an attack chain and IOCs if either emerges. Clients should action the P1 third-party relationship check now and treat everything else as watch-and-hold.


Read the original source →

Published via PulseTrace — Adverse Trace threat intelligence.

Post this to LinkedIn
Formatting is converted automatically — headings, bullets, a link back & hashtags. Paste straight in.
J
Jeff Davies