ANP Health Listed by The Gentlemen Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
ANP Health was listed by The Gentlemen ransomware group on September 21, 2026; the group claims it holds data belonging to an undisclosed number of individuals. Anyone who has interacted with ANP Health should check the status of their information and consider protective steps.
A ransomware group known as The Gentlemen has listed ANP Health on its leak site, according to a report dated September 21, 2026. The listing names the Florida-based firm and its website, anphealthsolutions.com, but does not establish that a breach occurred, that files left the company, or that any individual’s information is in criminal hands. ANP Health has not publicly confirmed the claim as of writing.
For nurses, applicants, and families who may have shared identity, immigration, or employment details with a recruitment agency of this kind, the practical stake is straightforward: if personal records were copied, they could be misused for fraud, identity theft, or pressure related to immigration status. Public detail is limited, so the sensible response is caution and monitoring rather than assuming the worst.
What the listing says
The Gentlemen has listed ANP Health on its leak site. The available summary identifies the organization as ANP Health Services Inc., associated with anphealthsolutions.com, and describes it as a Florida-based recruitment agency focused on placing foreign-trained nurses into U.S. hospitals, with particular attention to candidates from Latin America, especially Venezuela. The listing does not disclose how many people might be affected, which systems were involved, what method was used, or what files—if any—the group claims to hold.
Timing beyond the September 21, 2026 report date, ransom demands, sample files, and a detailed inventory of data are undisclosed in the material provided. A leak-site entry is an extortion-related claim. It is not a regulator notice, a company admission, or an independent forensic finding. Until ANP Health or an official body confirms otherwise, the listing should be read as an unverified accusation.
The group behind it: The Gentlemen
The Gentlemen is a ransomware and extortion crew that, in public reporting on the wider threat landscape, has been associated with double-extortion style pressure: encrypting systems where they can and threatening to publish stolen data on a dedicated leak site if payment is not made. Groups in this category typically advertise victims to increase leverage, sometimes recycling older material or exaggerating access. Their posts are marketing for a criminal business, not audited disclosures.
For this specific listing, only what appears in the reported summary can be attributed to the group’s claim about ANP Health. No additional statements by The Gentlemen about file counts, exfiltration proof, or internal access at this company are included in the facts at hand. Readers should treat the appearance of a company name on such a site as a signal to watch for official updates, not as proof that a full data dump already exists in the wild.
Who is ANP Health?
ANP Health Services Inc. is described in the listing-related summary as a Florida-based recruitment agency that places foreign-trained nurses into U.S. hospitals. Publicly described aspects of its model include credential validation, NCLEX exam preparation, English training, direct-hire placement with a large network of partner hospitals, and visa sponsorship pathways such as EB-3 green cards for nurses and their families. The firm is said to have been founded in 2019 by Nelson Hurtado, a Venezuelan immigrant and registered nurse, and to have worked with candidates from many countries, with a strong focus on Latin America.
Organizations in this sector sit at the intersection of healthcare staffing and immigration support. They routinely handle sensitive personal and professional information because hospitals, licensing bodies, and immigration processes require it. A claimed incident involving such a firm matters because the same records that enable lawful placement and sponsorship are also attractive to fraudsters if they ever leave authorized control. That consequence follows from the nature of the work, not from any confirmed event at ANP Health.
What data was at risk
The facts state that data types named as exposed are not disclosed. The Gentlemen’s listing, as summarized, does not provide a verified inventory of stolen fields or documents. It is therefore inaccurate to assert that any particular category of ANP Health data was taken.
If files from a nurse-recruitment and visa-support agency were ever obtained by unauthorized parties, firms in this sector typically hold information such as full names, contact details, dates of birth, passport and immigration documents, educational and licensing credentials, exam and training records, employment history, hospital placement details, and family information tied to sponsorship. Financial or payment data related to program fees can also appear in similar businesses. None of that list is confirmed as involved here; it is a conditional picture of what is commonly processed in the industry, offered only so readers can judge personal risk if official confirmation later emerges.
The real-world impact
For individuals, the conditional risks are concrete. Identity details can support new-account fraud or tax-related scams. Immigration and credential documents can be used in social-engineering attempts that impersonate employers, lawyers, or government offices. Contact data can feed phishing aimed at nurses still in process or already placed. Family members named on sponsorship paperwork can face secondary exposure. None of these outcomes is established for ANP Health clients solely because of a leak-site listing; they are the usual harms people prepare for when healthcare-adjacent or immigration-related records may have been involved elsewhere.
For the organization, a public extortion listing can create operational distraction, partner concern, and reputational pressure even when the underlying claim is unproven or incomplete. Hospitals, candidates, and regulators may seek clarity. That dynamic is how leak sites are designed to work. It does not, by itself, prove negligence, describe internal security, or state that production systems were compromised.
What a leak-site listing does establish is narrow: a named crew has chosen to associate this company with its brand of pressure. What it does not establish is scope, accuracy, freshness of any alleged data, or whether the company has validated an intrusion. Those gaps are why calm verification beats panic.
What to do now
Until ANP Health or a competent authority confirms what, if anything, occurred, treat personal risk as possible rather than proven. Practical steps remain useful whether or not this listing turns out to be substantive:
- If you are a current or former candidate, employee, or family member on a sponsorship file, watch for unexpected emails, calls, or messages that reference your application, visa, NCLEX status, or hospital placement; verify any request through channels you already trust.
- Place fraud alerts or credit freezes with major consumer credit bureaus if you shared Social Security numbers, ITINs, or extensive identity documents in the past, and review credit reports for new accounts you did not open.
- Change passwords on email and portal accounts used for recruitment or licensing, and turn on multi-factor authentication where available.
- Keep copies of your own credential and immigration paperwork secure; do not resend full document sets in response to unsolicited “urgent” requests.
- Follow only official company or regulator notices for confirmation; ignore ransom-site screenshots circulated without context.
- Run a free exposure scan of your email address to see whether it has already appeared in other known breach datasets, which can help you prioritize further monitoring.
Public detail on this listing remains limited. The Gentlemen has named ANP Health; the company has not publicly confirmed an incident as of writing; people affected and data types are unknown or undisclosed. Conditional vigilance—not assumed catastrophe—is the proportionate response.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
SourceLeak-site claim data adapted from RansomLook.io, used under CC BY 4.0.
More recent breaches
Progeny Listed by The Gentlemen Ransomware GroupCrystal Glass Listed by The Gentlemen Ransomware GroupGrupolider Listed by The Gentlemen Ransomware GroupMagnetos y Refacciones Listed by The Gentlemen Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the ANP Health Listed by The Gentlemen Ransomware Group →
Publicly posted by thegentlemen — unverified claim, pending independent verification. Leak-site claim data adapted from RansomLook.io, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.