LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Astidental di Sabbione Listed by Lamashtu Ransomware Group

HIGH severityUnverified claimHow we verify

Astidental di Sabbione Listed by Lamashtu Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·September 30, 2026
Astidental di Sabbione Listed by Lamashtu Ransomware Group

Reported September 30, 2026.

HIGH
Severity
September 30, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Astidental di Sabbione was listed on September 30, 2026 by the Lamashtu ransomware group, which claims to have stolen data belonging to an undisclosed number of individuals. Anyone who may have shared personal or account information with the organisation should review their accounts and consider protective steps such as changing passwords and enabling multi-factor authentication.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Ransomware crews continue to use public leak sites as pressure tools, posting names of organisations and threatening to release material unless demands are met. Many such posts are unverified, sometimes recycled or inflated, and they sit in a wider pattern of extortion aimed at suppliers and professional services across Europe. Against that backdrop, the group known as Lamashtu has listed Astidental di Sabbione on its leak site, according to a report dated 30 September 2026. The company has not publicly confirmed the claim as of writing. For patients, clinics, and partners who deal with Italian dental supply channels, the listing is a signal to watch—not proof that any particular file has left the organisation.

Public detail is limited. The number of people who might be affected is unknown, and the listing does not set out a verified inventory of records. What follows treats the post as a claim by the group, explains what is and is not established, and outlines conditional steps readers can take if they believe their information could be involved.

What the listing says

According to the report, Lamashtu has listed Astidental di Sabbione on its leak site. The headline associated with the entry frames the matter as a listing by that ransomware group. The reported date is 30 September 2026. Beyond the name of the organisation and the fact of the listing, the available summary does not describe how any intrusion allegedly occurred, whether encryption was used, what volume of material is supposedly held, or a deadline for publication. People affected are recorded as unknown. Data types named as exposed are not disclosed.

The listing material also characterises the business, via associated public description, as connected with a long-standing Italian distribution role in dental equipment, instruments, and laboratory supplies, including services such as dental office turnkey design and digital workflow support. That characterisation comes with the claim package and should not be read as an independent confirmation that systems were compromised. As of writing, Astidental di Sabbione has not issued a public confirmation of the incident. Nothing in the open record establishes that files were copied, that a leak has occurred, or that any specific dataset is in third-party hands.

The group behind it: Lamashtu

Lamashtu is known in public reporting as a ransomware and extortion actor that follows a familiar double-pressure model: allege access to an organisation’s systems, demand payment, and use a leak site to name victims and threaten release of material if the group is not paid. Like other crews in this category, it relies on the reputational and regulatory cost of a public listing as much as on any technical payload. Tactics commonly associated with such groups in open sources include initial access through commodity methods, movement inside networks where possible, and staged claims on dedicated sites rather than quiet negotiation alone.

Notable prior activity attributed to Lamashtu in the wider threat landscape fits the same extortion pattern seen across multiple sectors; those patterns are general and do not prove what happened in any single case. For this listing, the only victim-specific assertion that can be repeated from the given facts is that the group has named Astidental di Sabbione. The group claims the organisation belongs on its site; that claim is unverified. No statement from Lamashtu about exact file counts, exfiltration methods, or content categories for this victim is included in the facts provided, and none should be invented.

Who is Astidental di Sabbione?

Astidental di Sabbione appears in the listing context as an Italian operator tied to dental distribution and related professional services. Public-facing description associated with the report presents a distributor role with decades of experience in dental equipment, instruments, and dental laboratory supplies, alongside broader services such as turnkey design for dental offices and support for digital workflows. Organisations in this sector sit between manufacturers, laboratories, and clinical practices. They typically handle commercial contracts, shipping and inventory data, and correspondence with clinics and labs rather than acting as a primary hospital or insurer of record.

A listing aimed at such a firm matters because dental supply chains touch many small and mid-sized practices. Even when a claim is unconfirmed, partners may worry about invoices, delivery details, account contacts, or project files that could, if ever exposed, aid fraud or nuisance contact. The consequence is not that a breach has been proven; it is that clinics and suppliers in Italy’s dental ecosystem have a reason to monitor official notices and to treat unsolicited messages that reference dental procurement with extra caution until clarity emerges.

The information in question

The facts state that data types named as exposed are not disclosed. It is therefore not possible to say which fields, if any, were taken. Asserting a specific inventory would repeat attacker marketing as if it were an audit. If files were ever taken from a distributor in this sector, firms of this kind typically hold business contact details for clinics and laboratories, order and shipping records, warranty or service information, design or configuration materials for office projects, and internal administrative documents. They may also hold credentials or access information for supplier portals, and in some cases limited personal data of staff or of individual practitioners named on accounts.

None of that list is confirmed as involved here. Patient clinical charts are less central to a pure distributor than to a dental practice itself, but indirect identifiers—names of dentists, practice addresses, phone numbers, email addresses, and commercial history—can still be useful to scammers if they surface. Because the listing does not name categories, readers should treat every category as hypothetical. The honest position is that public detail is limited and the exact contents remain unconfirmed.

Why it matters

For individuals and practices, the real-world risk is conditional. If business or contact data related to dental supply relationships were ever published, likely harms would include targeted phishing that impersonates a familiar supplier, fraudulent invoices, or social engineering that cites a real order or project. Identity-related misuse is less automatic than with a full consumer credit file, but email addresses and phone numbers still support credential-stuffing attempts and spam. For the organisation, an unverified listing can still drive customer questions, contractual notice duties where contracts require them, and time spent on investigation—costs that arise from the claim itself even before any data is shown to be public.

At sector level, dental distribution is operationally sensitive: delays or distrust in equipment and laboratory supply chains affect clinics that cannot easily pause care. Extortion listings exploit that sensitivity. What a leak-site name does establish is narrow: a group has chosen to apply public pressure. What it does not establish is the success of an intrusion, the scope of any data involved, or any conclusion about internal controls. Those points remain open until the company, a regulator, or another independent channel confirms otherwise.

What to do now

Treat the situation as a claim under watch, not as notice that your own records are already public. Practical steps stay conditional and measured:

You can also run a free exposure scan of your email to check whether your information has already surfaced in known breach datasets unrelated to this listing. That check does not prove or disprove the Lamashtu claim about Astidental di Sabbione; it only shows whether your address appears in collections that are already indexed. Remain sceptical of anyone who demands payment, crypto, or remote access while citing this listing. Until the company confirms otherwise, the responsible reading is that Lamashtu has published a name—and that alone is not the same as a verified breach.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

SourceLeak-site claim data adapted from RansomLook.io, used under CC BY 4.0.

CompanyAstidental di Sabbione security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See Astidental di Sabbione’s full breach history →

More recent breaches

Fiducial Listed by Lamashtu Ransomware GroupSeptember 30, 2026Becker Logistik Listed by Lamashtu Ransomware GroupSeptember 30, 2026Gerlon Listed by Lamashtu Ransomware GroupSeptember 30, 2026Projahn Listed by Lamashtu Ransomware GroupSeptember 30, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Astidental di Sabbione Listed by Lamashtu Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by lamashtu — unverified claim, pending independent verification. Leak-site claim data adapted from RansomLook.io, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram