Maryann Kriger Listed by INC Ransom Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Maryann Kriger was listed by the INC Ransom ransomware group on 21 September 2026. Readers should check any notifications from the organisation or credit-monitoring services and change passwords or enable two-factor authentication if they have an account.
INC Ransom has listed Maryann Kriger, associated with Bonita Orthodontics, on its leak site, according to a report dated September 21, 2026. The listing is an unverified claim by the group. Public detail is limited: the number of people who might be affected is unknown, and the types of data the group says it holds have not been disclosed in the available record. As of writing, the practice has not publicly confirmed that an incident occurred.
Claims of this kind matter because dental and orthodontic practices often hold sensitive personal and clinical information, including records that can involve minors. Until any organisation confirms what happened—or independent reporting establishes it—the listing should be read as an accusation, not as a verified inventory of stolen files.
Inside the listing
The public record describes the headline as Maryann Kriger listed by the INC Ransom ransomware group, with a reported date of September 21, 2026. The organisation named is Maryann Kriger, in connection with Bonita Orthodontics, where Dr. Maryann Kriger is described in practice-facing language as providing orthodontic care, including as a board-certified orthodontist and Elite Invisalign provider.
According to the listing material reflected in the report, the group states that it contacted Bonita Ortho on multiple occasions and warned that a leak would expose private information of patients who are minors. The available summary cuts off without a full statement of demands, file counts, timelines, or technical method. People affected are recorded as unknown. Data types named as exposed are not disclosed. No confirmed ransom figure, sample file set, or independent verification appears in the facts provided.
Nothing in the public listing material supplied here establishes that data left the practice’s systems, that encryption or exfiltration occurred, or that any particular patient file is in third-party hands. A leak-site entry is a pressure tactic and a claim; it is not the same as a regulator notice, a company disclosure, or a claimed breach index entry.
The group behind it: INC Ransom
INC Ransom is a known ransomware and extortion actor that has appeared in public reporting over recent years. Groups in this category typically claim to encrypt systems, steal copies of data, or both, then threaten publication on a dedicated leak site if payment is not made. Listings often include victim names, countdown-style pressure, and marketing language about the sensitivity of the alleged haul.
Well-documented patterns for such crews include double-extortion messaging—pairing operational disruption claims with the threat of data release—and outreach framed as “warnings” before publication. Those patterns describe how the ecosystem works in general; they do not prove what happened in any single named case. For this listing, only what the group claims about Maryann Kriger and Bonita Orthodontics should be attributed to INC Ransom, and those claims remain unverified in the material at hand.
Readers should treat screenshots, alleged file trees, and statements about minors’ data on criminal leak sites as unverified until corroborated by the organisation, a regulator, or reputable independent investigation.
Who is Maryann Kriger?
Maryann Kriger is identified in connection with Bonita Orthodontics, a practice that presents itself as offering personalised orthodontic care with modern technology, including Invisalign-related services, and free consultations. Orthodontic practices sit in the broader healthcare and dental sector: they schedule care, bill insurers or patients, and maintain clinical charts tied to real identities.
A claimed incident involving a named orthodontic provider is consequential on its face because the patient base can include children and adolescents as well as adults, and because clinical and administrative systems often link names, contact details, treatment history, and payment information. That sector context explains why a leak-site claim draws attention; it does not establish that any specific systems were compromised or that any particular records were copied.
What data was at risk
The facts state that data types named as exposed are not disclosed, and the number of people affected is unknown. It is therefore not possible to state from this record what, if anything, was taken.
If files from an orthodontic practice were ever obtained by an unauthorised party, organisations in this sector typically hold combinations of patient identifiers, guardian or emergency contacts, appointment and treatment notes, imaging or dental records, insurance and billing data, and staff or vendor information. Claims that minors’ private information could be involved raise the stakes of any real exposure, because children’s data is especially sensitive and can support long-lived identity or social-engineering risk. Those are conditional sector norms, not a confirmed catalogue for this listing.
INC Ransom’s own description of what it holds should be read as the attacker’s assertion. Without disclosure from the practice or another authoritative source, exact contents remain unconfirmed.
Why it matters
For patients and families, the practical concern—if the claim were ever substantiated—would be misuse of personal and clinical details: targeted phishing that references real appointments or providers, attempts to open credit or medical-identity accounts, or embarrassment and privacy harm if treatment information circulated. When minors are mentioned in extortion messaging, guardians also face the separate worry of how long such data might remain in criminal circulation.
For the organisation, a public leak-site listing can damage trust, trigger legal and regulatory scrutiny under health-privacy rules depending on jurisdiction, and force costly review whether or not the underlying claim is accurate. A listing alone does not prove negligence or confirm a successful intrusion; it does create a need for careful verification, patient communication if a real incident is found, and caution among people who have been patients or staff.
What a leak-site listing does establish is that a named practice has been singled out in a criminal publication channel. What it does not establish is scale, method, or a verified data inventory.
What to do now
If you or your child have been a patient of Dr. Maryann Kriger or Bonita Orthodontics, treat the situation as conditional. Watch for unexpected bills, insurance notices, or messages that pressure you for payments or passwords while claiming to be the practice. Prefer contact channels you already trust rather than links or attachments in unsolicited email or text. Consider placing fraud alerts or credit freezes if you later learn that financial identifiers were involved, and keep records of any suspicious contact.
The practice has not publicly confirmed this incident in the information available here; official guidance from the provider or regulators, if issued, should take priority over criminal leak-site claims. As a general step, you can run a free exposure scan of your email to check whether your address has already appeared in known breach datasets, and update passwords on important accounts if you reuse credentials across services.
Remain sceptical of anyone demanding payment to “remove” your data. Extortion follow-on scams are common after high-profile listings. Verify news through primary sources, and act on confirmed notices rather than on unverified claims alone.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Second House Listed by INC Ransom Ransomware Groupsslf.local Listed by INC Ransom Ransomware Grouphttps://eclmn.com/ Listed by INC Ransom Ransomware GroupRuby Seven Studios Listed by INC Ransom Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Maryann Kriger Listed by INC Ransom Ransomware Group →
Publicly posted by incransom — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.