LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Minnesota Orthodontics Listed by bianlian Ransomware Group

HIGH severityUnverified claimHow we verify

Minnesota Orthodontics Listed by bianlian Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·March 7, 2025
Minnesota Orthodontics Listed by bianlian Ransomware Group

Reported March 7, 2025.

HIGH
Severity
March 7, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Minnesota Orthodontics was listed by the bianlian ransomware group on March 7, 2025, after internal files were exfiltrated in a ransomware attack. The number of people affected has not been disclosed; anyone who received services from the practice should verify whether their information was compromised and take appropriate protective steps.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Patients and staff connected to Minnesota Orthodontics may now face questions about whether their personal or clinical details have left the organisation’s systems. On 7 March 2025 the ransomware group known as bianlian listed the practice on its leak site, claiming it had exfiltrated internal files. The number of people affected remains unknown, and public detail on exactly what was taken is limited, yet the listing alone is enough to put ordinary people on notice that their information could be at risk.

For anyone who has received orthodontic care at one of the practice’s Twin Cities locations, the practical stakes are straightforward: medical and administrative records can be used for identity fraud, targeted phishing, or further social-engineering attacks. Until more is confirmed, vigilance is the only reliable response.

Breaking down the breach

Public reporting states that Minnesota Orthodontics was listed by the bianlian ransomware group on 7 March 2025. The group claims that internal files were exfiltrated during a ransomware attack. No confirmed figure for the number of individuals affected has been released, nor has any detailed inventory of the files been made public. The method of initial access, the duration of the intrusion, and whether systems were encrypted in addition to data theft all remain undisclosed. The sole concrete assertion available is the group’s own claim that internal files left the organisation’s control.

Who is bianlian?

Bianlian is a ransomware operation that has been active since at least 2022. Like many modern groups, it typically employs double-extortion tactics: encrypting systems while also stealing data and threatening to publish it if a ransom is not paid. The group maintains a dark-web leak site where it posts victim names and, in some cases, sample files. It has previously targeted healthcare providers, professional services firms and mid-sized organisations across North America and Europe. Public technical analyses describe bianlian as using custom ransomware binaries, living-off-the-land techniques for lateral movement, and data-exfiltration tools that copy large volumes of files before encryption. In the present case the group claims Minnesota Orthodontics is among its victims; that claim has not been independently verified in the available record.

Minnesota Orthodontics and its sector

Minnesota Orthodontics describes itself as North America’s leading Invisalign provider, with more than thirty years of experience and thirteen locations across the Twin Cities. The practice offers clear-aligner treatment for adults, teens and children as well as traditional braces. Orthodontic clinics of this type routinely collect and store patient names, dates of birth, addresses, insurance details, treatment plans, digital scans, photographs and payment information. Because orthodontic care often spans months or years, records can accumulate substantial personal and clinical history. A breach at such a provider therefore carries consequences both for individual privacy and for the continuity of care, as staff must also manage the operational disruption that ransomware incidents commonly produce.

The information in question

The only data type named in public reporting is “internal files” said to have been exfiltrated. No further breakdown—whether those files contained patient charts, financial records, employee data or administrative documents—has been disclosed. Organisations of this kind typically hold protected health information, contact details, insurance identifiers and billing records. Until Minnesota Orthodontics or an investigating authority releases a confirmed inventory, the precise contents remain unconfirmed. Readers should therefore treat any assumption about specific data elements as speculative.

What's at stake

For individuals, the principal risks are identity theft, fraudulent insurance claims, and highly targeted phishing that references real treatment details. Medical information can also be used to craft convincing social-engineering messages that pressure people into revealing further credentials or payment data. For the organisation, the stakes include regulatory notification duties under health-privacy rules, potential civil claims, reputational damage, and the cost of forensic investigation and system restoration. Because the number of people affected is still unknown, the full scale of these risks cannot yet be quantified.

What to do if you're exposed

If you have been a patient or employee of Minnesota Orthodontics, treat the listing as a prompt for basic protective steps rather than confirmed compromise. Concrete actions include:

You can also run a free exposure scan of your email address to check whether that address has already appeared in other known breach data sets. Doing so provides an additional data point while official notifications, if any, are still pending. Remain calm, document any unusual contacts, and wait for verified guidance from the organisation or regulators before taking more drastic measures.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyMinnesota Orthodontics security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See Minnesota Orthodontics’s full breach history →

More recent breaches

Meridian Senior Listed by bianlian Ransomware GroupMarch 31, 2025Sonrisas Dental Health Listed by bianlian Ransomware GroupMarch 31, 2025Goshen Medical Center Listed by bianlian Ransomware GroupFebruary 15, 2025Alabama Ophthalmology Associates Listed by bianlian Ransomware GroupJanuary 22, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the Minnesota Orthodontics Listed by bianlian Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by bianlian — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram