Desk live·
ForensicPost
Ransomware/Third party/File 26-0908

Veradigm Confirmed a Patient Data Theft via a Vendor’s API Credential After a 3.5M Claim

The Gentlemen listed the health-IT company on 5 September. Its Form 8-K three days later said an unauthorised party had taken credentials from a vendor’s environment to a Veradigm interface and downloaded patient data, Social Security numbers included, for a small number of customers. The vendor is not named.

Constructed geometry · not a chart of case data
JurisdictionUSAChicagothe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetVeradigm customer patients
ActorThe Gentlemen (claimed)
S. Rosler8 min readConfidence: medium3 sources reviewed

Veradigm, the Chicago health-IT company formerly called Allscripts, filed a Form 8-K on 8 September 2026 confirming that an unauthorised party had obtained credentials from a vendor’s environment to a Veradigm application programming interface the vendor used, and had used them to download personal data of patients associated with a small number of its customers. The data included, in some instances, Social Security numbers. No clinical data was involved, the filing said, and no other part of the company’s environment was accessed.

The Gentlemen extortion operation had listed Veradigm on its leak site on 5 September, claiming about 3.5 million patient records and threatening publication. The filing names no group and gives no count. The vendor is not named either.

A Credential To An Interface

The mechanism is precise and the corpus has filed it before. A vendor holds a credential to a customer’s API because its product needs the data. The vendor is breached, the credential is used from outside, and the customer’s API serves the request as it would any other. The file at 26-0611 recorded the same path into Salesforce environments; 26-0917 records it in a storefront ecosystem the following week. The API did what it was built to do. The control that failed was in the vendor’s environment, and the vendor is the one party nobody has named.

Small Number Of Customers, 3.5 Million Claimed

A health-IT company’s customers are practices and hospitals, and a small number of them can hold millions of patients. The two figures are not in conflict. What the file cannot do is verify the claim, which is the attackers’ and which they made three days before the company confirmed anything. The verification rule at 26-0425 applies: a listing is a claim, and this one arrived first.

The Patient’s Position

The people in the data are patients of a practice that bought software from Veradigm, which shared an interface with a vendor that was breached. Three organisations stand between the patient and the failure, and the notification, where it comes, will come from one of them with a name the patient may not recognise. The corpus filed the same position at 25-0801, and this file adds nothing to it except another instance.

How we reported this

Compiled from Veradigm’s Form 8-K and contemporaneous reporting of the leak-site listing, listed below. The 3.5 million figure is the attackers’ claim; the company has published no count. The vendor was not identified by any source. Graded medium. Corrections: corrections@forensicpost.com.

Sources
  1. Veradigm Inc., Form 8-K, 8 September 2026U.S. Securities and Exchange Commission
  2. Veradigm discloses patient data breach after Gentlemen gang claims attackBleepingComputer
  3. Veradigm Discloses Third Party Data Breach as Hackers Threaten to Publish DataHIPAA Journal
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary