LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › MCNA Dental 1 million patients records Listed by everest Ransomware Group

HIGH severityUnverified claimHow we verify

MCNA Dental 1 million patients records Listed by everest Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·September 16, 2024
MCNA Dental 1 million patients records Listed by everest Ransomware Group

Reported September 16, 2024.

HIGH
Severity
September 16, 2024
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

On September 16, 2024, the MCNA Dental data breach was publicly disclosed, with internal files exfiltrated in a ransomware attack by the Everest group. Anyone who received services from the organization should verify their personal information and follow recommended protective steps.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

For patients and families who rely on dental coverage or care coordination, a claim that personal medical records have been taken can mean real uncertainty about privacy, identity risk, and future contact from scammers. Public reporting on this incident is limited, and the number of people affected has not been confirmed, yet the appearance of a dental-related organisation on a ransomware leak site is enough to warrant careful attention from anyone who has been a patient or plan member.

What is known so far comes largely from a listing attributed to the Everest ransomware group, dated September 16, 2024. The group claims it has exfiltrated internal files and more than one million personal electronic medical records, and it has published sample rows that appear to contain names, addresses, dates of birth, phone numbers, and plan-related fields. Whether those claims are accurate, complete, or still under negotiation remains unverified in the public record.

What happened

According to the available facts, the organisation identified as MCNA Dental 1 million patients records was listed by the Everest ransomware group on September 16, 2024. The listing states that internal files were exfiltrated in a ransomware attack and that the company had a short window—described as the last 24 hours—to make contact using instructions left by the attackers. In the event of silence, the group said all data would be published. The same listing asserts that the material includes more than one million personal electronic medical records together with various internal company documents, and it supplies an illustrative excerpt that appears to show patient-identifying and eligibility fields.

No independent confirmation of the intrusion method, the exact volume of data, the full set of systems involved, or the final disposition of any ransom demand has been provided in the facts. The number of people affected is recorded as unknown. Public detail beyond the group’s own claims is therefore limited.

Inside everest

Everest is a ransomware operation known for double-extortion tactics: encrypting systems while also stealing data and threatening to publish it if payment is not made. Groups of this type typically post victims on dedicated leak sites, set short deadlines for contact, and release sample files to pressure organisations. Everest has appeared in multiple public reports of such campaigns against companies across sectors; its listings are claims made by the actors themselves and are not automatically verified by independent investigators.

In this case, the facts show only that Everest listed the organisation and asserted possession of internal files and a large volume of personal EMRs. No additional statements attributed specifically to Everest about this victim—beyond the deadline language, the publication threat, and the sample data—are supplied. Readers should treat the leak-site content as an unverified claim until corroborated by the organisation, regulators, or forensic reporting.

Who is MCNA Dental 1 million patients records?

The organisation is presented in the facts under the name MCNA Dental 1 million patients records and is associated with the domain mcna.net. Public knowledge of the broader MCNA Dental entity indicates it operates in the dental benefits and care-management space, typically serving plan members, providers, and state or commercial dental programs. Organisations of this kind routinely maintain electronic records that support eligibility, claims, treatment history, and member contact details.

A breach claim involving such an entity is consequential because dental and medical administrative systems often hold sensitive personal and health-related information for large populations, including children and families enrolled in public or private plans. Even when the precise scope remains unconfirmed, the potential reach of any exposed membership or clinical data raises legitimate concern for identity and privacy risks.

The information in question

The facts state that the data types named as exposed are internal files exfiltrated in a ransomware attack. The Everest listing further claims “more than 1 million personal EMR’s + different internal company documents” and includes an example string containing fields that appear to include names, street addresses, city and state, dates of birth, telephone numbers, identifiers, plan names, eligibility dates, and monetary amounts. These elements are presented by the group as illustrative of the stolen material.

Because the facts list people affected as unknown and do not independently verify the contents, the exact composition and volume of any compromised data remain unconfirmed. Organisations in dental benefits administration typically hold member demographics, contact information, insurance identifiers, treatment or eligibility records, and internal operational documents. Whether any particular individual’s full record was among the files claimed by Everest cannot be established from the public facts alone.

The real-world impact

If personal electronic medical or membership records were in fact taken, affected individuals could face elevated risk of identity theft, targeted phishing, or social-engineering attempts that reference real names, addresses, dates of birth, or plan details. Health-related data can also be used to craft more convincing fraud or to pressure people with sensitive medical information. For the organisation, a ransomware incident of this type can disrupt operations, trigger regulatory notification duties, and require costly investigation and remediation—though no dollar figures or confirmed operational outages are stated in the facts.

Because the number of people affected is unknown and the group’s claims have not been independently verified here, the practical impact for any given person remains uncertain. The prudent approach is to treat the listing as a credible warning signal rather than as proof that every listed sample belongs to a confirmed victim set.

What to do if you're exposed

If you have been a patient, member, or employee connected with MCNA Dental, monitor financial and insurance statements for unexpected activity and be cautious of unsolicited calls or messages that reference personal or plan details. Consider placing fraud alerts with credit bureaus and reviewing any free or paid credit reports for new accounts you did not open. Keep records of any official notices you later receive from the organisation or from regulators, as those will contain the most reliable guidance on what data, if any, was involved.

As a practical first check, you can run a free exposure scan of your email address to see whether it has already appeared in known breach data sets. That step does not confirm or rule out involvement in this specific incident, but it can help you prioritise further monitoring and password hygiene across accounts that use the same address.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyMCNA Dental security record
80/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

3 reported incidents on record.

See MCNA Dental’s full breach history →
RelatedMore incidents at MCNA Dental

More recent breaches

Total Patient Care LLC;A Sensitive Touch Home Health;Alphastar Home Health Care;Heart of T Listed by everest Ransomware GroupDecember 17, 2024Artistic Family Dental;Value Dental Center;Sparkling Smiles Family Dentistry Listed by everest Ransomware GroupDecember 17, 2024A Sensitive Touch Home Health;Alphastar Home Health Care;Heart of Texas Home Healthcare Se Listed by everest Ransomware GroupNovember 15, 20242K Dental Listed by everest Ransomware GroupJune 13, 2024

Latest breaches

Read GalaxyWarden’s full analysis of the MCNA Dental 1 million patients records Listed by everest Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by everest — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram