Minnesota Orthodontics Listed by bianlian Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Minnesota Orthodontics was listed by the bianlian ransomware group on March 7, 2025, after internal files were exfiltrated in a ransomware attack. The number of people affected has not been disclosed; anyone who received services from the practice should verify whether their information was compromised and take appropriate protective steps.
Patients and staff connected to Minnesota Orthodontics may now face questions about whether their personal or clinical details have left the organisation’s systems. On 7 March 2025 the ransomware group known as bianlian listed the practice on its leak site, claiming it had exfiltrated internal files. The number of people affected remains unknown, and public detail on exactly what was taken is limited, yet the listing alone is enough to put ordinary people on notice that their information could be at risk.
For anyone who has received orthodontic care at one of the practice’s Twin Cities locations, the practical stakes are straightforward: medical and administrative records can be used for identity fraud, targeted phishing, or further social-engineering attacks. Until more is confirmed, vigilance is the only reliable response.
Breaking down the breach
Public reporting states that Minnesota Orthodontics was listed by the bianlian ransomware group on 7 March 2025. The group claims that internal files were exfiltrated during a ransomware attack. No confirmed figure for the number of individuals affected has been released, nor has any detailed inventory of the files been made public. The method of initial access, the duration of the intrusion, and whether systems were encrypted in addition to data theft all remain undisclosed. The sole concrete assertion available is the group’s own claim that internal files left the organisation’s control.
Who is bianlian?
Bianlian is a ransomware operation that has been active since at least 2022. Like many modern groups, it typically employs double-extortion tactics: encrypting systems while also stealing data and threatening to publish it if a ransom is not paid. The group maintains a dark-web leak site where it posts victim names and, in some cases, sample files. It has previously targeted healthcare providers, professional services firms and mid-sized organisations across North America and Europe. Public technical analyses describe bianlian as using custom ransomware binaries, living-off-the-land techniques for lateral movement, and data-exfiltration tools that copy large volumes of files before encryption. In the present case the group claims Minnesota Orthodontics is among its victims; that claim has not been independently verified in the available record.
Minnesota Orthodontics and its sector
Minnesota Orthodontics describes itself as North America’s leading Invisalign provider, with more than thirty years of experience and thirteen locations across the Twin Cities. The practice offers clear-aligner treatment for adults, teens and children as well as traditional braces. Orthodontic clinics of this type routinely collect and store patient names, dates of birth, addresses, insurance details, treatment plans, digital scans, photographs and payment information. Because orthodontic care often spans months or years, records can accumulate substantial personal and clinical history. A breach at such a provider therefore carries consequences both for individual privacy and for the continuity of care, as staff must also manage the operational disruption that ransomware incidents commonly produce.
The information in question
The only data type named in public reporting is “internal files” said to have been exfiltrated. No further breakdown—whether those files contained patient charts, financial records, employee data or administrative documents—has been disclosed. Organisations of this kind typically hold protected health information, contact details, insurance identifiers and billing records. Until Minnesota Orthodontics or an investigating authority releases a confirmed inventory, the precise contents remain unconfirmed. Readers should therefore treat any assumption about specific data elements as speculative.
What's at stake
For individuals, the principal risks are identity theft, fraudulent insurance claims, and highly targeted phishing that references real treatment details. Medical information can also be used to craft convincing social-engineering messages that pressure people into revealing further credentials or payment data. For the organisation, the stakes include regulatory notification duties under health-privacy rules, potential civil claims, reputational damage, and the cost of forensic investigation and system restoration. Because the number of people affected is still unknown, the full scale of these risks cannot yet be quantified.
What to do if you're exposed
If you have been a patient or employee of Minnesota Orthodontics, treat the listing as a prompt for basic protective steps rather than confirmed compromise. Concrete actions include:
- Monitor bank, credit-card and insurance statements for unfamiliar charges or claims.
- Place a free fraud alert or credit freeze with the major credit bureaus if you notice suspicious activity.
- Be sceptical of unsolicited emails or calls that reference orthodontic treatment or request personal information.
- Change passwords for any online patient portals or email accounts that may have been reused.
- Request a copy of your medical records from the practice so you know what information exists about you.
You can also run a free exposure scan of your email address to check whether that address has already appeared in other known breach data sets. Doing so provides an additional data point while official notifications, if any, are still pending. Remain calm, document any unusual contacts, and wait for verified guidance from the organisation or regulators before taking more drastic measures.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Meridian Senior Listed by bianlian Ransomware GroupSonrisas Dental Health Listed by bianlian Ransomware GroupGoshen Medical Center Listed by bianlian Ransomware GroupAlabama Ophthalmology Associates Listed by bianlian Ransomware GroupLatest breaches
Publicly posted by bianlian — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.