dr-elizabeth-bjornson Listed by qilin Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
On February 19, 2025, the dr-elizabeth-bjornson organisation was listed by the Qilin ransomware group, which claims to have exfiltrated internal files. Individuals who may have had dealings with the organisation should review any notifications they receive and consider protective steps such as monitoring accounts and changing passwords.
People who have visited or been treated by the dental practice known as dr-elizabeth-bjornson may now face questions about whether their personal or clinical information has been taken. On February 19, 2025, the practice was listed by the Qilin ransomware group, which claims that internal files were exfiltrated in a ransomware attack. The number of people affected remains unknown, and public detail on the precise scope is limited, yet any exposure of dental-practice records can create lasting practical risks for patients and staff.
This listing is a claim by the group rather than an independently confirmed disclosure. Still, the reported nature of the incident—internal files taken during a ransomware event—means those connected to the practice have reason to understand what is known, what is not, and what steps they can take.
Inside the incident
According to the available record, dr-elizabeth-bjornson was listed by the Qilin ransomware group on February 19, 2025. The group claims that internal files were exfiltrated as part of a ransomware attack. No confirmed figure for the number of people affected has been published, and further details such as the exact method of intrusion, the volume of data taken, or any ransom demand remain undisclosed in the public facts.
What is stated is limited to the listing itself and the description of internal files having been removed. There is no public confirmation that the practice has verified the claim, nor any official statement detailing containment, notification, or recovery steps. In the absence of those details, the incident stands as an unverified claim of data theft tied to ransomware activity.
Inside qilin
Qilin is a ransomware group that has operated for several years under a ransomware-as-a-service model. It is known for double-extortion tactics: encrypting systems while also stealing data and threatening to publish it on a leak site if payment is not made. The group typically targets organizations across multiple sectors, posts victim names and sometimes sample files on its dark-web portal, and has been linked to numerous incidents reported by security researchers and law-enforcement agencies.
Public reporting describes Qilin affiliates as using common initial-access methods such as phishing, exploitation of remote-access tools, or compromised credentials, followed by lateral movement and data staging before encryption. The group’s leak-site listings are claims intended to pressure victims; they do not by themselves prove the full extent of any compromise. In this case, the listing of dr-elizabeth-bjornson is presented solely as the group’s assertion that internal files were taken.
About dr-elizabeth-bjornson
Dr-elizabeth-bjornson is identified in the available material as a dental practice. Public-facing language associated with the organization describes services aimed at affordable dental health, ranging from routine comprehensive exams to more invasive procedures, and notes acceptance of major credit cards, personal checks, cash, and payment options. Dental practices of this kind routinely handle patient contact details, medical and dental histories, treatment records, insurance information, and billing data.
A breach involving such an organization is consequential because the data it holds is both personal and sensitive. Patients entrust practices with information that can be used for identity-related fraud, insurance misuse, or targeted social engineering. Even limited internal files can contain enough detail to create ongoing risk for individuals and operational disruption for the practice itself.
What was likely exposed
The facts state only that internal files were exfiltrated in a ransomware attack. No specific data types beyond that description—such as patient names, clinical notes, financial records, or employee information—have been named or confirmed. Exact contents therefore remain unconfirmed.
Organizations of this kind typically maintain appointment systems, electronic health records, billing systems, and administrative files. Those systems can hold names, addresses, dates of birth, contact numbers, insurance identifiers, treatment histories, payment card or bank details, and staff records. Because the public record does not itemize what was taken, it is not possible to state which of these categories, if any, were actually involved. Readers should treat any assumption about specific data elements as speculative until official confirmation appears.
Why it matters
For individuals, the practical risks include identity theft, fraudulent insurance claims, phishing attempts that reference real treatment details, and long-term monitoring of credit or medical accounts. Even if clinical notes are not involved, contact and billing information alone can enable convincing scams. For the practice, a ransomware incident can interrupt patient care, damage trust, trigger regulatory notification duties, and create recovery costs that extend well beyond any initial technical remediation.
Because the number of affected people is unknown and the precise data set is undisclosed, the full scale of impact cannot yet be measured. That uncertainty itself is a reason for caution: people who have been patients or employees cannot simply assume they were untouched.
Were you affected?
If you have been a patient, family member, or staff member connected to dr-elizabeth-bjornson, treat the listing as a signal to act carefully. Monitor bank and credit-card statements for unfamiliar charges, place fraud alerts with major credit bureaus if you are concerned, and be wary of unexpected calls or emails that reference dental visits or payment details. Change passwords on any accounts that may have reused credentials associated with the practice, and enable multi-factor authentication where available.
You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach data sets. Official notifications, if they come, will provide the most reliable guidance; until then, these basic steps reduce the chance that any exposed information is used against you.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Georgia Dermatology & Skin Cancer Center Listed by qilin Ransomware GroupShore Gardens Rehabilitation & Nursing Center Listed by qilin Ransomware GroupLugiano Medical Listed by qilin Ransomware GroupOxford Rehabilitation Center Listed by qilin Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the dr-elizabeth-bjornson Listed by qilin Ransomware Group →
Publicly posted by qilin — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.