Fox Broermann Pediatric Dentistry of Tulsa Listed by pear Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Fox Broermann Pediatric Dentistry of Tulsa has been listed by the pear ransomware group, with internal files reported as exfiltrated in an attack. The incident came to light on May 01, 2026; the number of people affected is undisclosed. Anyone who may have received services from the organization should review their accounts and consider credit monitoring.
What happened
The incident centers on a ransomware operation that resulted in the exfiltration of internal files from Fox Broermann Pediatric Dentistry of Tulsa. The pear group added the organization to its leak site on the reported date of May 1, 2026. No further details on the timing of the intrusion, the method of access, or the volume of data have been made public.
Who is pear?
Pear is a ransomware group that maintains a public leak site to post names of organizations it claims to have targeted. Such groups typically gain access through common vectors such as compromised credentials or unpatched systems, encrypt files to disrupt operations, and then threaten to release stolen material if a ransom is not paid. The listing of Fox Broermann Pediatric Dentistry of Tulsa constitutes the group's claim regarding this case; independent confirmation of the data's authenticity or extent has not been reported.
Who is Fox Broermann Pediatric Dentistry of Tulsa?
Fox Broermann Pediatric Dentistry of Tulsa operates as a specialized dental practice serving children in the Tulsa area. Organizations of this type routinely collect and store patient records that include personal identifiers, medical histories, insurance information, and treatment details. A breach involving such an entity is consequential because the data held can support identity-related fraud or targeted scams when it leaves the organization's control.
The information in question
The only detail released is that internal files were allegedly exfiltrated. The exact categories of information contained in those files have not been disclosed. Pediatric dental practices commonly maintain records that include names, dates of birth, addresses, Social Security numbers, insurance data, and clinical notes, yet it is not confirmed whether any of these elements appear in the material referenced by the listing.
The real-world impact
Individuals whose information may have been included face the standard risks associated with exposure of personal and medical records, such as potential misuse for fraud or unwanted solicitations. The organization itself may encounter operational disruption, regulatory scrutiny, and costs related to investigation and notification. Because the scale of exposure is unknown, the full extent of these effects cannot be quantified at present.
What to do if you're exposed
Anyone concerned about possible involvement should monitor their financial accounts and credit reports for unusual activity. Contacting the dental practice directly can provide the most current information available from the source. Readers can also run a free exposure scan of their email address against known breach data to check for prior appearances in public listings.
- Review credit reports from the three major bureaus at no cost.
- Place a fraud alert or credit freeze if suspicious activity appears.
- Change passwords for any accounts linked to the practice and enable multi-factor authentication.
- Retain records of any communications from the organization about the incident.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
South Plains Rural Health Services, Inc. Listed by pear Ransomware GroupLangenberg, Strubberg, Arand & King, LLC Listed by pear Ransomware GroupColorado Pulmonary Intensivists Listed by pear Ransomware GroupArkansas Oral & Maxillofacial Surgeons Listed by pear Ransomware GroupLatest breaches
Publicly posted by pear — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.