A ransomware group calling itself ‘thegentlemen’ has posted a claim on its leak site stating that it obtained data from Veradigm, with the claim dated September 4, 2026. This listing was identified by security researchers at ransomware.live, a platform that tracks the public leak sites operated by ransomware groups. At this time, the claim is unverified — Veradigm has not confirmed any incident, and no regulator or independent investigator has corroborated the group’s statement. BreachLetter is reporting on the existence of this claim, not on a confirmed data breach.
What we know — and don’t
- The group ‘thegentlemen’ listed Veradigm on its extortion site with a claimed date of September 4, 2026.
- Veradigm operates in the healthcare sector, providing technology and services used by healthcare organizations.
- The specific types of data the group claims to have obtained have not been disclosed publicly and have not been confirmed.
- Veradigm has not issued a public confirmation or statement regarding this claim as of this writing.
- No regulatory filing or official breach notification tied to this claim has been identified at this time.
What should you do if you have an account with this company?
- Change your password for any account associated with Veradigm, and avoid reusing that password elsewhere.
- Enable two-factor authentication (2FA) wherever it is offered, particularly for accounts tied to healthcare or financial services.
- Be alert to phishing emails, texts, or phone calls that reference Veradigm, healthcare services, or claim to require urgent account verification.
- Review account and insurance statements periodically for unfamiliar activity, especially if the account involves sensitive personal or medical information.
- Consider using a service like a service like Aura or LifeLock to monitor for signs of identity misuse, since claims like this one can sometimes precede attempts at identity theft even before any breach is confirmed.
- Keep records of any suspicious communications in case they become relevant if this claim is later confirmed.
BreachLetter will update this article if Veradigm confirms the incident, issues a public statement, or if the matter is reported to regulators or data protection authorities.