Large U.S. dental referral firm hit with cyberstrike

Busch Melissa 2 Crop Headshot

A Russian-linked cybercriminal gang claims to have infiltrated dental referral and marketing service firm 1-800-Dentist and has threatened to leak the health data of millions of individuals, according to a story published June 30 on Cybernews.

On June 28, the Qilin ransomware gang published on its dark victim blog that it had stolen a cache of personal information files that are potentially linked to millions of people and dental practices from the Los Angeles-based 1-800-Dentist. Qilin did not disclose exactly how much or the type of data it had allegedly stolen, according to the story.

On its blog, the cybercriminals claimed it would leak the data soon if the company did not contact them. Additionally, Qilin threatened to leak the company’s sensitive data unless it paid an undisclosed ransom. Furthermore, Qilin posted 11 sample files from 1-800-Dentist to prove it had stolen data from the company, according to the story.

1-800-Dentist has not confirmed the hack.

1-800-Dentist serves more than 5,000 dental practices in the U.S., handles 70,000 average calls per month, and 2 million appointments have been scheduled via its platform, according to the company website.

Originally known as Agenda, Qilin emerged in 2022 as a ransomware as a service criminal operation that provides customizable malware platforms to affiliates.

In 2024, Qilin struck the medical lab Synnovis in the U.K., causing severe disruptions to National Health Service hospitals. The cybercriminals demanded a $50 million ransom.

In 2025, the group crippled manufacturing at Asahi Group Holdings, a brewing company in Japan.

So why do healthcare and dental organizations continue to be prime ransomware targets? Gary Salman, CEO and co-founder of Black Talon Security, offered some thoughts below.

"Many healthcare organizations, including dental practices, DSOs, vendors, and suppliers are still woefully unprotected against cyberattacks. We often do assessments for dental groups and find that basic security measures which should be in place are not. In addition to a lack of visibility in firewall vulnerabilities and misconfigurations, computers within a practice or business may have an exorbitant number of exploitable vulnerabilities that hackers can exploit to gain access to a network. Hackers are now leveraging AI more than ever to find vulnerabilities and build hacking tool kits that give them the ability to bypass security measures.

"Hackers are also very aware that healthcare organizations almost always pay the ransom demand because the hacking group will steal some or all of the confidential information from the servers or cloud technology. If the victim does not pay the ransom, the hacking group will publish the data, which exposes the patients to even more risk. It also exposes the practices or business to class action lawsuits that will be filed on behalf of patients.

"Phishing and other forms of social engineering are still very popular with hacking groups. A phishing email can easily be crafted with the use of AI to convince a victim to give up their credentials and click on a link that downloads a malicious payload that almost always bypasses defenses like anti-virus software. 

"Most organizations believe their anti-virus software is going to protect them from an attack. Unfortunately, many hacking groups know how to bypass anti-virus, or work around it so that it does not alert. Some groups are installing legitimate software that anti-virus software knows is “safe” unless it is used maliciously.

"Some warning signs may include:

  1. A click on a link in an email that appears to “do nothing,” even if the email comes from a known source. Keep in mind that known or friendly email account may have been taken over by a hacker and used to send out malicious emails.
  2. The appearance that someone is controlling your computer by opening windows, typing or moving the mouse.
  3. Anti-virus alerts over a course of a few days or weeks that appear to be “nothing” but may be the hackers staging an attack.
  4. A call from someone you know stating that they are receiving emails from your email account that don’t seem legitimate.

"Overall, most organizations no longer utilize technologies or human intellect that provide a true and real-time picture into their cyber risk. The cyber world is moving so fast that if you are not testing all your systems on a daily basis for vulnerabilities, then you will have a cyber event."

Page 1 of 2
Next Page