LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Sunstar Americas Listed by royal Ransomware Group

HIGH severityUnverified claimHow we verify

Sunstar Americas Listed by royal Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·March 30, 2023
Sunstar Americas Listed by royal Ransomware Group

Reported March 30, 2023.

HIGH
Severity
March 30, 2023
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Sunstar Americas Listed by royal Ransomware Group (reported March 30, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

For customers and others whose information may sit in Sunstar Americas systems, a ransomware group's claim that it stole internal files raises practical questions about personal data, account security, and what happens next. Public reporting places the listing on March 30, 2023; the number of people affected remains unknown, and independent confirmation of the full scope is limited.

What is known so far comes largely from the group's own leak-site claim: that Sunstar Americas, part of the broader Sunstar Corporation known for dental products, lost roughly 118GB of data said to include customers' personal information and other internal corporate material. Until more is verified, people connected to the company are left weighing ordinary precautions against incomplete public detail.

What happened

According to the reported listing, the Royal ransomware group named Sunstar Americas as a victim and asserted that it had exfiltrated internal files in a ransomware attack. The claim, dated in public reporting to March 30, 2023, states that about 118GB of data was taken, described as including customers' personal information and other internal corporate data, with the group indicating that material would later be viewable. The number of people affected is unknown. Method of initial access, exact timing of the intrusion, whether systems were encrypted, and any ransom demand or payment outcome are not detailed in the available facts. The listing itself should be treated as an unverified claim by the group rather than independently confirmed fact.

Inside royal

Royal is a ransomware operation that became widely documented in public cybersecurity reporting around 2022. Like many contemporary groups, it has been associated with double-extortion tactics: encrypting victim environments while also copying data and threatening to publish or auction it if demands are not met. Public analyses have described Royal as using common intrusion paths such as compromised credentials, phishing, or exploitation of exposed services, followed by lateral movement and bulk data staging before encryption or leak-site pressure. The group has listed numerous organizations across sectors on its leak infrastructure. Specific technical claims Royal may have made solely about Sunstar Americas beyond the volume and broad categories noted in the facts are not independently set out here; the leak-site listing remains the group's assertion.

About Sunstar Americas

Sunstar Americas is identified in the reporting as part of the Sunstar Corporation, a name long associated with dental and oral-care products. Organizations in this sector typically manage customer and patient-related records, order and distribution data, employee information, supplier contracts, and internal operational files. Even when a company is primarily known for consumer goods, its Americas operations can hold contact details, purchase or account histories, and corporate documents that are sensitive if exposed. A breach claim against such an entity matters because dental and consumer-health adjacent businesses often sit at the intersection of personal identity data and commercial records, increasing the potential impact on individuals and on business partners who rely on the integrity of those systems.

What was likely exposed

The facts name exposed material as internal files exfiltrated in a ransomware attack. The group's reported summary adds that roughly 118GB was involved and that the haul included customers' personal information and other internal corporate data. Exact file inventories, field-level data types, and confirmation of every category are not independently detailed in the public record provided. Organizations of this kind commonly hold names, contact information, account or order data, employee records, and internal business documents; whether any specific subset of those appeared in this incident remains unconfirmed beyond the group's claim. Readers should treat the 118GB figure and the personal-information assertion as part of the threat actor's listing unless and until corroborated elsewhere.

Why it matters

If customer personal information was among the taken files, affected people face familiar risks: targeted phishing that references real relationships with the company, credential stuffing if reused passwords appear, and longer-term misuse of identity details. Internal corporate data can expose business processes, partner lists, or employee information, creating secondary risk for staff and suppliers. For the organization, a public ransomware listing can disrupt operations, strain customer trust, and trigger regulatory or contractual notification duties depending on jurisdiction and the nature of the data. Because the count of affected individuals is unknown and full contents are not independently catalogued in the facts, the practical exposure for any one person cannot be stated with precision; the prudent assumption is that anyone who has been a customer, employee, or close partner should monitor for unusual contact and account activity.

If your data was in this claimed breach

Start with basics: watch financial and email accounts for unexpected messages or password-reset attempts that reference Sunstar or dental products; enable multi-factor authentication where available; and change passwords that may have been reused on related services. If you receive notices from the company, follow only official channels. Keep records of any suspicious contact. You can also run a free exposure scan of your email to check whether your information has already surfaced in known breach data, which helps prioritize further monitoring without assuming you were or were not included in this specific incident.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanySunstar Americas security record
88/100
DoxxScan™ · Low doxx risk
B 83Good record

1 reported incident on record.

See Sunstar Americas’s full breach history →

More recent breaches

Kretek International Listed by royal Ransomware GroupApril 5, 2023Steve Silver furniture Listed by royal Ransomware GroupMarch 30, 2023Vending Group Listed by royal Ransomware GroupMarch 30, 2023Ferretería EPA Listed by royal Ransomware GroupMarch 2, 2023

Latest breaches

Read GalaxyWarden’s full analysis of the Sunstar Americas Listed by royal Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by royal — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram