mcna.net Listed by lockbit3 Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The mcna.net Listed by lockbit3 Ransomware Group (reported March 27, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
When a company that manages dental benefits for Medicaid and children's health programs appears on a ransomware group's leak site, the practical concern is straightforward: internal files may have left the organisation's control, and people whose records sit inside those systems have little immediate way to know whether their information was among them. Public reporting places the listing of mcna.net by the LockBit3 group on March 27, 2023. The number of people affected remains unknown, and the precise contents of what was taken have not been fully detailed beyond a description of internal files exfiltrated in a ransomware attack.
For patients, state agencies, and managed-care partners who rely on MCNA Dental, that uncertainty is the core problem. Ransomware incidents that include data theft create lasting exposure risks even when systems are restored, because copies of files can circulate long after the initial intrusion. What follows is a plain account of what has been reported, what is known about the actors and the organisation, and what individuals can reasonably do next.
Breaking down the breach
According to public breach records, mcna.net was listed by the LockBit3 ransomware group on March 27, 2023. The organisation involved is identified as MCNA Dental, also referred to as MCNA Insurance Company and Managed Care of North America, Inc. The available summary describes the company as a leading dental benefits manager that provides services to state agencies and managed care organisations for Medicaid and children's health insurance programs.
The records state that internal files were exfiltrated in a ransomware attack. Beyond that description, public detail is limited. The number of people affected is listed as unknown. No confirmed figure for the volume of data, no itemised inventory of file types beyond the general label of internal files, and no independent confirmation of the full scope of the intrusion have been supplied in the facts available here. The listing itself is a claim published by the threat actor on its leak infrastructure; it should be treated as an unverified assertion unless and until the organisation or regulators confirm the details.
Timing of the underlying intrusion, the initial access method, and whether a ransom was demanded or paid are not disclosed in the material at hand. What is established is the reported date of the listing and the characterisation of the incident as a ransomware attack involving exfiltration of internal files.
Who is lockbit3?
LockBit3 is a well-documented ransomware operation that has appeared repeatedly in public reporting since the earlier LockBit variants. Groups operating under the LockBit name have typically followed a double-extortion model: encrypting systems to disrupt operations while also copying data and threatening to publish it if payment is not made. Affiliates often gain initial access through stolen credentials, exposed remote services, or phishing, then move laterally before deploying ransomware and staging data for exfiltration.
The group has maintained leak sites where it names victims and, in many cases, posts samples or larger archives of stolen data. LockBit and its successors have been among the more prolific ransomware brands in law-enforcement and industry reporting, with victims spanning healthcare, manufacturing, government contractors, and professional services. That history does not, by itself, prove every claim the group makes about a specific victim. In this case, the facts establish only that LockBit3 listed mcna.net; they do not independently verify the volume or sensitivity of any files the group may claim to hold.
Who is mcna.net?
MCNA Dental, operating through MCNA Insurance Company and Managed Care of North America, Inc., is described in the available summary as a dental benefits manager serving state agencies and managed care organisations. Its work centres on Medicaid and children's health insurance dental programs. Organisations in this role typically sit between public programs, dental providers, and enrolled members. They process eligibility, claims, provider networks, and related administrative data.
Because the company handles benefits for publicly funded health programs, a breach involving its internal systems is consequential. Such organisations routinely process names, dates of birth, member identifiers, addresses, treatment and claims information, and provider details. They may also hold contracts, internal correspondence, and operational documents tied to state partners. Even when the exact file list from an incident is unconfirmed, the sector's normal data holdings explain why listings of this kind draw attention from regulators, partners, and the people enrolled in the programs.
The information in question
The facts name the exposed material as internal files exfiltrated in a ransomware attack. No further breakdown of data types—such as specific categories of personal health information, financial records, or employee data—is provided in the available record. The number of affected individuals is unknown.
Organisations that administer Medicaid and children's dental benefits typically hold member demographic data, insurance identifiers, claims and treatment-related information, provider credentials and payment details, and internal business documents. It is reasonable to expect that internal file stores at a company of this type could contain some mix of those categories. It is not established, from the facts given here, exactly which of those categories were present in the material LockBit3 claims to have taken. Readers should treat any more specific description as unconfirmed unless the company or official notices state otherwise.
The real-world impact
For individuals, the main risks after a ransomware incident that includes data theft are long-term rather than immediate. If personal or health-related information was among the internal files, affected people may face elevated risk of targeted phishing, identity misuse, or attempts to commit fraud using details that appear legitimate because they come from a real benefits administrator. Health and insurance data can be especially useful to criminals crafting convincing scams. Because the scale of exposure is unknown, people who have been MCNA members or providers cannot yet rule themselves in or out solely from public reporting.
For the organisation, consequences can include operational disruption during and after the attack, contractual and regulatory obligations to notify partners and individuals, forensic and recovery costs, and reputational damage with state agencies and managed care clients. Ransomware groups that publish or auction data can keep pressure on a victim for weeks or months. None of that requires assuming negligence; it is the ordinary fallout pattern when internal files are claimed to have been stolen and systems encrypted.
State agencies and other partners may also need to reassess how member data is shared and monitored. When a benefits manager is listed, the impact can extend beyond a single company's network to the wider set of programs that depend on it.
Were you affected?
If you are or were a member, parent or guardian of a child enrolled through a program MCNA administers, or a dental provider in its network, treat the incident as a reason for heightened caution rather than proof that your specific records were taken. Monitor insurance explanations of benefits and credit reports for unfamiliar activity. Be wary of unexpected calls, texts, or emails that reference your dental coverage, Medicaid, or children's health benefits and press you for personal information or payments. Prefer contact channels you already know and trust.
Official notification, if required and if your data was involved, would typically come from the organisation or through established regulatory channels. Until clearer inventories are published, public detail remains limited. As a practical step, you can run a free exposure scan of your email address to check whether your information has already surfaced in known breach data sets, and you can place fraud alerts or credit freezes if you believe sensitive identifiers may have been exposed. Keep records of any suspicious contact and report clear fraud to the relevant consumer-protection and law-enforcement bodies in your jurisdiction.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
coastalplainsctr.org Listed by lockbit3 Ransomware Groupolea.com Listed by lockbit3 Ransomware Grouppcli.com Listed by lockbit3 Ransomware Groupbemes.com Listed by lockbit3 Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the mcna.net Listed by lockbit3 Ransomware Group →
Publicly posted by lockbit — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.