Sunstar Americas Listed by royal Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The Sunstar Americas Listed by royal Ransomware Group (reported March 30, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
For customers and others whose information may sit in Sunstar Americas systems, a ransomware group's claim that it stole internal files raises practical questions about personal data, account security, and what happens next. Public reporting places the listing on March 30, 2023; the number of people affected remains unknown, and independent confirmation of the full scope is limited.
What is known so far comes largely from the group's own leak-site claim: that Sunstar Americas, part of the broader Sunstar Corporation known for dental products, lost roughly 118GB of data said to include customers' personal information and other internal corporate material. Until more is verified, people connected to the company are left weighing ordinary precautions against incomplete public detail.
What happened
According to the reported listing, the Royal ransomware group named Sunstar Americas as a victim and asserted that it had exfiltrated internal files in a ransomware attack. The claim, dated in public reporting to March 30, 2023, states that about 118GB of data was taken, described as including customers' personal information and other internal corporate data, with the group indicating that material would later be viewable. The number of people affected is unknown. Method of initial access, exact timing of the intrusion, whether systems were encrypted, and any ransom demand or payment outcome are not detailed in the available facts. The listing itself should be treated as an unverified claim by the group rather than independently confirmed fact.
Inside royal
Royal is a ransomware operation that became widely documented in public cybersecurity reporting around 2022. Like many contemporary groups, it has been associated with double-extortion tactics: encrypting victim environments while also copying data and threatening to publish or auction it if demands are not met. Public analyses have described Royal as using common intrusion paths such as compromised credentials, phishing, or exploitation of exposed services, followed by lateral movement and bulk data staging before encryption or leak-site pressure. The group has listed numerous organizations across sectors on its leak infrastructure. Specific technical claims Royal may have made solely about Sunstar Americas beyond the volume and broad categories noted in the facts are not independently set out here; the leak-site listing remains the group's assertion.
About Sunstar Americas
Sunstar Americas is identified in the reporting as part of the Sunstar Corporation, a name long associated with dental and oral-care products. Organizations in this sector typically manage customer and patient-related records, order and distribution data, employee information, supplier contracts, and internal operational files. Even when a company is primarily known for consumer goods, its Americas operations can hold contact details, purchase or account histories, and corporate documents that are sensitive if exposed. A breach claim against such an entity matters because dental and consumer-health adjacent businesses often sit at the intersection of personal identity data and commercial records, increasing the potential impact on individuals and on business partners who rely on the integrity of those systems.
What was likely exposed
The facts name exposed material as internal files exfiltrated in a ransomware attack. The group's reported summary adds that roughly 118GB was involved and that the haul included customers' personal information and other internal corporate data. Exact file inventories, field-level data types, and confirmation of every category are not independently detailed in the public record provided. Organizations of this kind commonly hold names, contact information, account or order data, employee records, and internal business documents; whether any specific subset of those appeared in this incident remains unconfirmed beyond the group's claim. Readers should treat the 118GB figure and the personal-information assertion as part of the threat actor's listing unless and until corroborated elsewhere.
Why it matters
If customer personal information was among the taken files, affected people face familiar risks: targeted phishing that references real relationships with the company, credential stuffing if reused passwords appear, and longer-term misuse of identity details. Internal corporate data can expose business processes, partner lists, or employee information, creating secondary risk for staff and suppliers. For the organization, a public ransomware listing can disrupt operations, strain customer trust, and trigger regulatory or contractual notification duties depending on jurisdiction and the nature of the data. Because the count of affected individuals is unknown and full contents are not independently catalogued in the facts, the practical exposure for any one person cannot be stated with precision; the prudent assumption is that anyone who has been a customer, employee, or close partner should monitor for unusual contact and account activity.
If your data was in this claimed breach
Start with basics: watch financial and email accounts for unexpected messages or password-reset attempts that reference Sunstar or dental products; enable multi-factor authentication where available; and change passwords that may have been reused on related services. If you receive notices from the company, follow only official channels. Keep records of any suspicious contact. You can also run a free exposure scan of your email to check whether your information has already surfaced in known breach data, which helps prioritize further monitoring without assuming you were or were not included in this specific incident.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Kretek International Listed by royal Ransomware GroupSteve Silver furniture Listed by royal Ransomware GroupVending Group Listed by royal Ransomware GroupFerretería EPA Listed by royal Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Sunstar Americas Listed by royal Ransomware Group →
Publicly posted by royal — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.