LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surface
Recent BreachesData breach tracker

Recent Breaches › ProSmile Family Dental Care Listed by CRPxO Ransomware Group

HIGH severityUnverified claimHow we verify

ProSmile Family Dental Care Listed by CRPxO Ransomware Group: What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·July 27, 2026
ProSmile Family Dental Care Listed by CRPxO Ransomware Group

Reported July 27, 2026.

HIGH
Severity
1
Data types exposed
July 27, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

ProSmile Family Dental Care was listed by the CRPxO ransomware group on July 27, 2026, after internal files were exfiltrated in a ransomware attack. Anyone who received care or shared personal information with the practice should check for updates and consider protective steps such as monitoring accounts and changing passwords.

Severity & verification
HIGH severityUnverified claim
Contact / identity PII exposed.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Was your email in the ProSmile Family Dental Care Listed by CRPxO Ransomware Group breach?
See every leak tied to your email — not just this one. 15-second check, no card, no account.

Healthcare providers remain among the most frequently targeted organisations in the current cyber-threat landscape, where ransomware groups routinely seek both disruption and leverage through stolen data. Dental practices, like other clinical settings, hold concentrated stores of personal and medical information that can be valuable to criminals and distressing to patients if exposed. Against that backdrop, ProSmile Family Dental Care has been named in a listing associated with the ransomware group CRPxO.

Public reporting dated July 27, 2026 states that the group claims to have exfiltrated internal files in a ransomware attack and lists a data volume of 9.6 GB. The number of people affected is unknown, and independent confirmation of the full scope remains limited. For patients, staff, and partners, the listing is a signal to pay attention and take measured steps rather than a complete public accounting of what occurred.

Inside the incident

According to the available record, ProSmile Family Dental Care was listed by the CRPxO ransomware group in connection with a ransomware attack in which internal files were said to have been exfiltrated. The reported summary places the organisation in the healthcare and dental sector and cites a leaked data volume of 9.6 GB. The listing was reported on July 27, 2026.

Beyond those points, public detail is limited. The number of people affected is unknown. The precise method of initial access, the timeline of the intrusion, whether systems were encrypted, and whether any ransom demand was made or paid have not been disclosed in the facts available here. What is stated is that internal files were exfiltrated as part of a ransomware attack and that CRPxO has associated the organisation with a 9.6 GB data leak on its listing. That claim should be treated as an assertion by the group until corroborated by the organisation or independent investigation.

The group behind it: CRPxO

CRPxO is presented in public reporting as a ransomware group that engages in double-extortion style activity: encrypting or disrupting systems while also claiming to steal data and threatening to publish it if demands are not met. Like other actors in this category, such groups typically advertise victims on leak sites to increase pressure and to demonstrate that they hold material. Listings are marketing and coercion tools as much as technical disclosures; they do not by themselves prove every detail of an intrusion.

Well-documented patterns among ransomware operators include phishing, exploitation of remote-access services, and abuse of stolen credentials, followed by lateral movement, data staging, and exfiltration before or alongside encryption. Specific claims that CRPxO has made about ProSmile Family Dental Care beyond the listing itself—such as exact file inventories or internal commentary—are not provided in the facts and are not invented here. The group’s association of this victim with a 9.6 GB leak of internal files is therefore reported as its claim.

About ProSmile Family Dental Care

ProSmile Family Dental Care is identified as a dental care provider operating in the healthcare sector. Organisations of this type deliver clinical dental services and, in the ordinary course of care, maintain records needed for treatment, billing, insurance, and regulatory compliance. That typically includes patient identities, contact details, appointment and treatment histories, insurance information, and sometimes payment-related data, along with internal administrative and operational files.

A breach affecting a dental practice matters because the relationship between patient and provider depends on confidentiality. Even when the full contents of a leak are unconfirmed, the mere possibility that clinical or administrative material left the organisation’s control raises practical concerns for individuals whose information may have been among the files and for the practice’s ability to maintain trust and continuity of care.

The information in question

The facts name the exposed material as internal files exfiltrated in a ransomware attack, with a reported leak size of 9.6 GB. They do not itemise specific data categories such as names, Social Security numbers, clinical charts, or financial records. Exact contents are therefore unconfirmed in the public record summarised here.

Dental and healthcare organisations commonly hold patient demographics, health histories relevant to dental treatment, insurance and billing data, staff records, and internal business documents. It is reasonable for affected people to assume that material of that general kind could be in scope when “internal files” are claimed, but it would be inaccurate to state that any particular field or document type was definitively exposed without further disclosure. Until the organisation or investigators provide a clearer inventory, the prudent stance is that sensitive internal material may have been taken, at a claimed volume of 9.6 GB, while the precise mix remains unknown.

What's at stake

For individuals, the main risks are misuse of personal or health-related information if it was among the exfiltrated files—such as targeted phishing that references real appointments or insurers, identity fraud if identifiers were included, or unwanted exposure of private medical details. Because the count of affected people is unknown and the file list is not public, no one outside the investigation can yet say who is or is not included; uncertainty itself is part of the burden.

For the organisation, stakes include operational disruption from a ransomware event, regulatory and contractual obligations common in healthcare, potential notification duties, and reputational harm. None of that establishes negligence as a proven fact; it describes the ordinary consequences that follow when a healthcare provider is named in a ransomware data-leak claim. Recovery and communication will depend on what internal forensics ultimately show.

What to do if you're exposed

If you are a patient, employee, or partner of ProSmile Family Dental Care, treat the listing as a reason to heighten caution rather than as proof that your own file was taken. Watch for unexpected messages that reference dental care, insurance, or personal details; verify any request for information through official channels you already trust; and consider placing fraud alerts or credit freezes if you believe identifiers may have been involved. Keep records of any suspicious contact.

Where the practice issues official guidance or notification, follow those instructions. You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach datasets, which can help you prioritise password changes and monitoring. Public detail on this incident remains limited; measured vigilance is the appropriate response until more is confirmed.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyProSmile Family Dental Care security record
64/100
DoxxScan™ · Moderate doxx risk
B- 76Above-average record

1 reported incident on record.

See ProSmile Family Dental Care’s full breach history →

More recent breaches

eCare Platform Listed by CRPxO Ransomware GroupJuly 27, 2026American Hospice & Home Health Services (Ahhh Care) Listed by CRPxO Ransomware GroupJuly 27, 2026Leah Walker Orthodontics Listed by CRPxO Ransomware GroupJuly 27, 2026Elko Dental Specialists Listed by CRPxO Ransomware GroupJuly 27, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the ProSmile Family Dental Care Listed by CRPxO Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by crpxo — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram