Garn Mason Orthodontics was hacked. All insurance and personal data of customers was stole Listed by knight Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The Garn Mason Orthodontics was hacked. All insurance and personal data of customers was stole Listed by knight Ransomware Group (reported September 29, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
Ransomware groups continue to target healthcare and specialty medical practices, treating patient and insurance records as high-value leverage in double-extortion schemes. In this environment, even smaller orthodontic offices have appeared on leak sites, underscoring that no segment of the sector is automatically insulated.
On 29 September 2023 it was reported that Garn Mason Orthodontics had been listed by the knight ransomware group. The group claims the practice was hacked and that all insurance and personal data of customers was stolen, with internal files exfiltrated. The number of people affected remains unknown, and independent confirmation of the full scope is limited.
Inside the incident
Public reporting on 29 September 2023 stated that Garn Mason Orthodontics was hacked and that insurance and personal data of customers had been stolen. The same reports note that internal files were allegedly exfiltrated in a ransomware attack and that the incident was listed by the knight ransomware group. No further operational details—such as the initial access method, the precise date of intrusion, the volume of data taken, or any ransom demand—have been disclosed in the available record. The number of individuals affected is listed as unknown. Beyond the group’s claim on its leak site and the summary description of stolen insurance and personal customer data, concrete technical findings remain unconfirmed.
Inside knight
Knight is a ransomware operation that became visible in public reporting during 2023. Like many contemporaneous groups, it has been observed using double-extortion tactics: encrypting systems while also exfiltrating data and threatening to publish it on a dedicated leak site if payment is not made. The group typically lists victim organizations on that site, often with brief descriptions of the claimed haul, as a form of pressure. Public analyses of knight’s activity describe relatively rapid listing of victims across multiple sectors, including healthcare-adjacent practices. No verified statements from knight beyond the listing itself are part of the record for this specific incident; the claim that Garn Mason Orthodontics suffered theft of all insurance and personal customer data originates from that listing and the accompanying summary reports.
Garn Mason Orthodontics and its sector
Garn Mason Orthodontics is an orthodontic practice. Organizations of this type routinely manage scheduling, treatment records, insurance billing, and demographic information for patients and their families. The orthodontic and broader dental sector holds data that is both clinically sensitive and financially useful to criminals—insurance identifiers, contact details, and treatment histories. A breach at such a practice is consequential because the data can be reused for identity fraud, insurance scams, or targeted social engineering, and because patients often have long-term relationships with a single office, increasing the concentration of personal information in one place. Public detail on the internal size or exact patient volume of Garn Mason Orthodontics is not provided in the incident record.
The information in question
The available facts state that internal files were exfiltrated in a ransomware attack and that reports describe all insurance and personal data of customers as stolen. Exact file inventories, record counts, or a confirmed list of data fields have not been disclosed. Orthodontic practices typically maintain names, addresses, dates of birth, insurance policy numbers, treatment notes, and billing records. Whether any or all of those categories were present in the exfiltrated material remains unconfirmed beyond the high-level claim. Readers should treat specific content assertions as unverified until corroborated by the organization or regulators.
The real-world impact
For individuals, exposure of insurance and personal data can enable fraudulent claims, account takeover attempts, or phishing that references real treatment details. Credit monitoring and careful scrutiny of explanation-of-benefits statements become practical precautions. For the practice, a ransomware incident can disrupt scheduling and clinical operations, create notification and regulatory obligations, and erode patient trust even when the full technical picture is still incomplete. Because the number of people affected is unknown and the precise data set is unconfirmed, the scale of downstream harm cannot yet be quantified from public sources alone.
Were you affected?
If you have been a patient or guarantor at Garn Mason Orthodontics, consider the following immediate steps:
- Monitor insurance statements and credit reports for unfamiliar activity.
- Be alert to unsolicited calls or messages that reference orthodontic treatment or insurance details.
- Request an official incident notification or status update directly from the practice if you have not already received one.
- Change passwords on any online patient portals you used and enable multi-factor authentication where available.
You can also run a free exposure scan of your email address to check whether it has appeared in known breach data sets. That check will not confirm or deny involvement in this specific incident, but it can surface other exposures that warrant attention. Public detail on this event remains limited; rely on official communications from the practice and, where applicable, state or federal regulators for authoritative updates.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
National Health Mission. Department of Heath & Family Welfare, Govt. of U.P Listed by knight Ransomware GroupNational Health Mission. Department of Health & Family Welfare, Govt. of U.P Listed by knight Ransomware GroupCrace Medical Centre Listed by knight Ransomware GroupAkir Metal San Tic Ltd ti was hacked. All confidential information was stolen Listed by knight Ransomware GroupLatest breaches
Publicly posted by knight — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.