1-800-Dentist Hit by Qilin Ransomware, Health Data of Millions Threatened: Ransomware Claim — What’s Alleged & What To Do
1-800-Dentist confirmed a ransomware attack by Qilin on June 30, 2026, exposing personal and health data of millions of patients. Individuals should check whether their records were affected and take protective steps if necessary.
Millions of people who contacted 1-800-Dentist for dental referrals may face exposure of personal and health records after the Qilin ransomware group claimed responsibility for a breach. The group posted sample files and threatened further disclosure unless the company responds, though 1-800-Dentist has not stated the incident as of the June 30, 2026 report.
The scale described involves millions of individuals, with the service handling roughly two million callers each year and maintaining relationships with thousands of dental practices across the United States.
Breaking down the breach
The incident centers on an unconfirmed claim by the Qilin group that it accessed systems belonging to 1-800-Dentist. According to the group, sample files were obtained and additional data would be released if demands were not met. No independent verification of the access method, timeline of the intrusion, or total volume of records has been released by the organization or by investigators. The exact date range of any unauthorized activity remains undisclosed.
Who is qilin?
Qilin operates as a ransomware group that publicly lists claimed victims on its leak site. Such groups commonly employ double-extortion tactics, first encrypting systems and then threatening to publish stolen files. Public records show prior activity by the group against organizations in multiple sectors, though each listing represents an assertion by the actors rather than a confirmed event until corroborated by the victim or law enforcement.
About 1-800-Dentist
1-800-Dentist functions as a referral service that connects callers with dental providers. Organizations of this type routinely collect contact details, appointment information, and basic health histories to facilitate matches between patients and practices. A breach at such a service is consequential because the data often includes identifiers that link individuals to specific medical providers and treatment records.
The information in question
The Qilin group claims the exposed material includes personal data, health data, medical and dental history, insurance information, payment details, and medical images. 1-800-Dentist has not released its own description of the records involved. Organizations in this sector typically hold names, addresses, dates of birth, insurance identifiers, treatment notes, and billing records, but the precise contents of any exfiltrated files remain unconfirmed.
Why it matters
Health-related records can be used for identity theft, insurance fraud, or targeted scams. When medical histories or images are involved, affected individuals may encounter long-term privacy concerns and the need to monitor statements and accounts for unauthorized activity. For the organization, the episode highlights the operational and regulatory pressures that follow any large-scale claim of access to patient-linked data.
Were you affected?
Individuals who have used 1-800-Dentist should watch for official statements from the company and follow any guidance it issues on monitoring or protective steps. Practical measures include reviewing insurance explanations of benefits, placing fraud alerts if warranted, and changing passwords on associated accounts. Readers can also run a free exposure scan of their email address against known breach datasets to check for appearances in previously published records.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Goodwill Manasota Listed by Qilin RansomwareCentral Florida Cosmetic & Family Dentistry Listed by qilin Ransomware GroupKeller Williams Real Estate - Exton Listed by qilin Ransomware GroupArmstrong George Cohen Will Ophthalmology Listed by qilin Ransomware GroupLatest breaches
Publicly posted by qilin — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.