ProSmile Family Dental Care Listed by Crpx0 Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
SourceLeak-site claim data adapted from RansomLook.io, used under CC BY 4.0.
ProSmile Family Dental Care has been listed by the Crpx0 ransomware group on 12 August 2026, indicating that personal data of an undisclosed number of people may have been exposed. Individuals who have received services from the practice are advised to check whether their information is involved and to follow any official guidance on protective steps.
On August 12, 2026, the ransomware and extortion group Crpx0 listed ProSmile Family Dental Care on its leak site. According to that listing, the group claims to have stolen internal data from the organization. Public detail is limited: the number of people who might be affected is unknown, and the listing does not describe specific data types. ProSmile Family Dental Care has not publicly confirmed the incident as of writing. A leak-site entry is an accusation and a pressure tactic, not independent verification that a breach occurred or that any particular files left the organization.
For patients, staff, and partners, the practical question is what such a claim implies and what to do if personal or clinical information were later shown to be involved. The sections below separate what the listing actually says from background on the actor, the dental sector, and conditional steps people can take.
Inside the listing
The available record states that ProSmile Family Dental Care was listed on the Crpx0 ransomware leak site and that the group claims to have stolen internal data. The reported date for that listing is August 12, 2026. Beyond that headline claim, the public summary does not disclose how access was supposedly obtained, whether encryption or other disruption was involved, how much data is alleged, or any timeline of intrusion. People affected are recorded as unknown. Data types named as exposed are not disclosed.
Ransomware crews often publish victim names on dedicated sites to coerce payment by threatening to release material. A name on such a site establishes that the group chose to make that claim; it does not by itself prove theft, the completeness of any haul, or that files will be published. No confirmation from the company, a regulator, or a neutral breach index is included in the facts provided for this write-up. Readers should treat scale, method, and contents as unconfirmed unless and until a primary source says otherwise.
Who is Crpx0?
Crpx0 is presented in open reporting as a ransomware and data-extortion actor that uses leak-site listings to name organizations and assert that internal data was taken. Groups in this category commonly combine alleged data theft with public shaming: they post a victim’s name, sometimes sample files or countdown language, and demand payment under threat of wider release. Tactics associated with this style of crime often include initial access through common enterprise weaknesses, movement inside networks, and packaging of stolen material for leverage—though none of those steps are described in the ProSmile Family Dental Care listing itself.
For this incident, the only claim tied to the victim in the given facts is the leak-site listing and the assertion that internal data was stolen. No further quotes, file counts, ransom figures, or technical indicators specific to ProSmile Family Dental Care are provided. Prior activity by the same brand name, where documented elsewhere in public security reporting, is general context about how such crews operate; it does not prove what happened in this case. Listings can be exaggerated, recycled, or false, which is why attribution here stays at the level of “the group claims.”
ProSmile Family Dental Care and its sector
ProSmile Family Dental Care is a named dental-care provider. Organizations in family and general dentistry typically schedule care, maintain clinical charts, process insurance and billing, and hold contact and identity details for patients and sometimes for employees and vendors. In the United States and similar jurisdictions, much of that information is treated as protected health information or otherwise sensitive personal data, which is why alleged incidents in healthcare and dental settings draw attention even when details remain sparse.
A listing aimed at a dental practice matters because the sector concentrates records that can be reused for identity misuse, insurance fraud, or targeted phishing that looks legitimate because it references real appointments or providers. That consequence follows from the kind of data such practices ordinarily handle, not from any verified inventory in this case. The leak-site claim does not establish operational failures at ProSmile Family Dental Care; it only shows that Crpx0 chose to name the organization. What a listing does establish is public pressure and uncertainty; what it does not establish is confirmed exfiltration, confirmed patient impact, or a full picture of systems involved.
What was likely exposed
The facts state that data types named as exposed are not disclosed. It is therefore not possible to say from the public record which systems or record categories, if any, were involved. Asserting a specific haul would repeat the attacker’s marketing as if it were an inventory.
If files from a dental practice were taken, firms in this sector typically hold some mix of the following—again as a sector pattern, not as a confirmed list for this listing:
- Patient demographics and contact details (names, addresses, phone numbers, email addresses)
- Dates of birth, insurance member identifiers, and billing or payment-related records
- Clinical notes, treatment histories, radiographs or imaging references, and appointment data
- Employee or contractor information used for scheduling, payroll, or administration
- Internal business documents, vendor contracts, or correspondence that might appear in office file shares
Exact contents for the Crpx0 claim about ProSmile Family Dental Care remain unconfirmed. Anyone evaluating personal risk should wait for official notices from the practice or from regulators before assuming their own chart or identity data is involved.
Why it matters
If internal dental data were allegedly stolen and later misused, affected individuals could face phishing that cites real provider names, attempts to open credit or medical accounts, or fraud against insurance benefits. Clinical and identity details together are more useful to criminals than a password dump alone, because they support social engineering that sounds plausible. The organization, if the claim were substantiated, could face notification duties, investigative cost, and reputational strain—outcomes that depend on facts not yet established in public sources tied to this listing.
Even an unconfirmed listing creates noise: patients may worry without knowing whether they are in scope, and staff may see a rise in suspicious messages pretending to help with a “breach.” The conditional framing matters. The group claims theft; the company has not publicly confirmed the incident as of writing; people affected and data categories are unknown or not disclosed. Real-world harm tracks verified exposure and criminal follow-on use, not the mere appearance of a name on an extortion site.
What to do now
Treat the situation as a claim until you receive direct notice. If you are a patient or employee of ProSmile Family Dental Care, watch for official communication from the practice through channels you already trust—not unsolicited links in email or text. If your information were involved, sensible first steps include verifying appointment and billing messages before clicking, placing fraud alerts or credit freezes if identity data might be at issue, and reviewing insurance explanations of benefits for unfamiliar claims. Do not assume your records are “out”; act if you are notified or if you see concrete signs of misuse.
You can also run a free exposure scan of your email address to check whether that address has already appeared in known breach datasets unrelated or related to other incidents. Keep expectations realistic: such scans do not prove or disprove this specific Crpx0 listing, but they can show whether your email is circulating in compiled leak material and prompt tighter password hygiene and multi-factor authentication on important accounts. Stay calm, rely on primary notices when they exist, and treat attacker leak sites as advocacy for a ransom demand rather than as a complete or verified report.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Bright Star Partners Insurance Listed by Crpx0 Ransomware GroupDignity Phoenix Listed by Crpx0 Ransomware GroupFLP Law Group LLP Listed by Crpx0 Ransomware GroupMRO Aerospace Listed by Crpx0 Ransomware GroupLatest breaches
Publicly posted by crpx0 — unverified claim, pending independent verification. Leak-site claim data adapted from RansomLook.io, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.