eAssist Dental Solutions, a Utah-based dental billing company owned by Henry Schein, was reportedly struck by a ransomware attack claimed by the Direwolf hacker group in September, potentially affecting thousands of dental practices across the U.S.
- Direwolf hacker group claimed responsibility for the eAssist Dental ransomware attack in September.
- eAssist Dental serves approximately 3,000 dental practices with about 1,750 dental billers across the U.S.
- The attack used a double-extortion model combining system encryption with threats to release sensitive data.
- Neither eAssist nor Henry Schein has publicly confirmed or denied the attack claims.
- This is the second major cybersecurity incident for Henry Schein in recent years, following a 2023 BlackCat ransomware attack.
A hacker group has claimed responsibility for a ransomware attack against eAssist Dental Solutions, a Utah-based outsourced dental billing and revenue cycle management company, according to multiple technology and web monitoring sites.
In September, cybercriminal group Direwolf claimed on a dark web leak site that it had struck eAssist, which is majority-owned by Henry Schein, according to the sites.
As of this writing of this story, neither eAssist nor Henry Schein has confirmed, denied, or commented publicly about these claims. eAssist and Henry Schein could not be immediately reached for comment.
Direwolf claims that it gained access to the internal systems of eAssist, which runs a cloud-based platform that integrates with dental practice management software and employs about 1,750 dental billers that serve about 3,000 dental practices throughout the U.S. However, the possible scope of exposed data remains unknown, according to the posts.
Direwolf, which emerged in 2015, has been linked to targeted, financially motivated attacks against a variety of businesses, including healthcare organizations. The gang uses a double-extortion model that combines encrypting a business’s system combined with the threat of releasing sensitive data. In the past, Direwolf has claimed responsibility for attacks on global merchant of record and billing platform Dodo Payments and the Legal Practice Board of Western Australia.
Furthermore, this isn’t the first time that Henry Schein businesses have been embroiled in a cybersecurity incident.
In October 2023, Schein announced that its manufacturing and distribution businesses were struck by a ransomware attack. Actions were taken, including taking certain systems offline, to contain the cyber incident, which disrupted some of Schein’s business operations.
The ransomware as a service hacker BlackCat claimed responsibility for the strike.
In December 2023, a data breach notification revealed that cybercriminals that hit Henry Schein not only may have accessed the personal data of about 29,000 people, but the ransomware gang infiltrated the company's network for more than two weeks before it was discovered.
The cyberstrike occurred on September 27, 2023, but Henry Schein did not discover it until October 14. A day later, the dental distributor notified the public of the cybersecurity incident and that it was taking most of its systems offline.




















