LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › ANP Health Listed by The Gentlemen Ransomware Group

HIGH severityUnverified claimHow we verify

ANP Health Listed by The Gentlemen Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·September 21, 2026
ANP Health Listed by The Gentlemen Ransomware Group

Reported September 21, 2026.

HIGH
Severity
September 21, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

ANP Health was listed by The Gentlemen ransomware group on September 21, 2026; the group claims it holds data belonging to an undisclosed number of individuals. Anyone who has interacted with ANP Health should check the status of their information and consider protective steps.

Severity & verification
HIGH severityUnverified claim
Account credentials exposed.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

A ransomware group known as The Gentlemen has listed ANP Health on its leak site, according to a report dated September 21, 2026. The listing names the Florida-based firm and its website, anphealthsolutions.com, but does not establish that a breach occurred, that files left the company, or that any individual’s information is in criminal hands. ANP Health has not publicly confirmed the claim as of writing.

For nurses, applicants, and families who may have shared identity, immigration, or employment details with a recruitment agency of this kind, the practical stake is straightforward: if personal records were copied, they could be misused for fraud, identity theft, or pressure related to immigration status. Public detail is limited, so the sensible response is caution and monitoring rather than assuming the worst.

What the listing says

The Gentlemen has listed ANP Health on its leak site. The available summary identifies the organization as ANP Health Services Inc., associated with anphealthsolutions.com, and describes it as a Florida-based recruitment agency focused on placing foreign-trained nurses into U.S. hospitals, with particular attention to candidates from Latin America, especially Venezuela. The listing does not disclose how many people might be affected, which systems were involved, what method was used, or what files—if any—the group claims to hold.

Timing beyond the September 21, 2026 report date, ransom demands, sample files, and a detailed inventory of data are undisclosed in the material provided. A leak-site entry is an extortion-related claim. It is not a regulator notice, a company admission, or an independent forensic finding. Until ANP Health or an official body confirms otherwise, the listing should be read as an unverified accusation.

The group behind it: The Gentlemen

The Gentlemen is a ransomware and extortion crew that, in public reporting on the wider threat landscape, has been associated with double-extortion style pressure: encrypting systems where they can and threatening to publish stolen data on a dedicated leak site if payment is not made. Groups in this category typically advertise victims to increase leverage, sometimes recycling older material or exaggerating access. Their posts are marketing for a criminal business, not audited disclosures.

For this specific listing, only what appears in the reported summary can be attributed to the group’s claim about ANP Health. No additional statements by The Gentlemen about file counts, exfiltration proof, or internal access at this company are included in the facts at hand. Readers should treat the appearance of a company name on such a site as a signal to watch for official updates, not as proof that a full data dump already exists in the wild.

Who is ANP Health?

ANP Health Services Inc. is described in the listing-related summary as a Florida-based recruitment agency that places foreign-trained nurses into U.S. hospitals. Publicly described aspects of its model include credential validation, NCLEX exam preparation, English training, direct-hire placement with a large network of partner hospitals, and visa sponsorship pathways such as EB-3 green cards for nurses and their families. The firm is said to have been founded in 2019 by Nelson Hurtado, a Venezuelan immigrant and registered nurse, and to have worked with candidates from many countries, with a strong focus on Latin America.

Organizations in this sector sit at the intersection of healthcare staffing and immigration support. They routinely handle sensitive personal and professional information because hospitals, licensing bodies, and immigration processes require it. A claimed incident involving such a firm matters because the same records that enable lawful placement and sponsorship are also attractive to fraudsters if they ever leave authorized control. That consequence follows from the nature of the work, not from any confirmed event at ANP Health.

What data was at risk

The facts state that data types named as exposed are not disclosed. The Gentlemen’s listing, as summarized, does not provide a verified inventory of stolen fields or documents. It is therefore inaccurate to assert that any particular category of ANP Health data was taken.

If files from a nurse-recruitment and visa-support agency were ever obtained by unauthorized parties, firms in this sector typically hold information such as full names, contact details, dates of birth, passport and immigration documents, educational and licensing credentials, exam and training records, employment history, hospital placement details, and family information tied to sponsorship. Financial or payment data related to program fees can also appear in similar businesses. None of that list is confirmed as involved here; it is a conditional picture of what is commonly processed in the industry, offered only so readers can judge personal risk if official confirmation later emerges.

The real-world impact

For individuals, the conditional risks are concrete. Identity details can support new-account fraud or tax-related scams. Immigration and credential documents can be used in social-engineering attempts that impersonate employers, lawyers, or government offices. Contact data can feed phishing aimed at nurses still in process or already placed. Family members named on sponsorship paperwork can face secondary exposure. None of these outcomes is established for ANP Health clients solely because of a leak-site listing; they are the usual harms people prepare for when healthcare-adjacent or immigration-related records may have been involved elsewhere.

For the organization, a public extortion listing can create operational distraction, partner concern, and reputational pressure even when the underlying claim is unproven or incomplete. Hospitals, candidates, and regulators may seek clarity. That dynamic is how leak sites are designed to work. It does not, by itself, prove negligence, describe internal security, or state that production systems were compromised.

What a leak-site listing does establish is narrow: a named crew has chosen to associate this company with its brand of pressure. What it does not establish is scope, accuracy, freshness of any alleged data, or whether the company has validated an intrusion. Those gaps are why calm verification beats panic.

What to do now

Until ANP Health or a competent authority confirms what, if anything, occurred, treat personal risk as possible rather than proven. Practical steps remain useful whether or not this listing turns out to be substantive:

Public detail on this listing remains limited. The Gentlemen has named ANP Health; the company has not publicly confirmed an incident as of writing; people affected and data types are unknown or undisclosed. Conditional vigilance—not assumed catastrophe—is the proportionate response.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

SourceLeak-site claim data adapted from RansomLook.io, used under CC BY 4.0.

CompanyANP Health security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See ANP Health’s full breach history →

More recent breaches

Progeny Listed by The Gentlemen Ransomware GroupSeptember 21, 2026Crystal Glass Listed by The Gentlemen Ransomware GroupSeptember 21, 2026Grupolider Listed by The Gentlemen Ransomware GroupSeptember 21, 2026Magnetos y Refacciones Listed by The Gentlemen Ransomware GroupSeptember 21, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the ANP Health Listed by The Gentlemen Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by thegentlemen — unverified claim, pending independent verification. Leak-site claim data adapted from RansomLook.io, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram