On June 6, 2025, Nunez Dental in Jackson Heights, New York, appeared on the leak site of the incransom ransomware group. The dental practice, which has served 36,000 patients over 37 years, is claimed to have had internal files exfiltrated during a ransomware attack. While the exact number of affected individuals remains unknown, anyone who has been a patient there in the past three decades could have personal information now at risk.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.
What Public Reporting Shows
Public reporting indicates that incransom published a post on its dark web leak site listing Nunez Dental as a victim. The practice operates with a team of 31 staff members and holds 10 master certifications. Available reporting describes the incident as a ransomware attack in which internal files were allegedly exfiltrated. No specific patient count or detailed list of exposed data types has been publicly confirmed beyond the broad category of internal files. The leak site entry carries the identifier 6842d8c4ba689080131a5b6a.
Why This Matters for You and Your Family
If you or any member of your family has ever received dental care at Nunez Dental, your personal information may now sit on a ransomware leak site. Dental records frequently contain full names, addresses, dates of birth, Social Security numbers, phone numbers, email addresses, insurance details, and medical history. Once that information reaches criminal forums, it can be sold and reused for identity theft, tax fraud, or medical fraud targeting you or your children. The breach affects not just current patients but anyone treated there across nearly four decades.
The Doxxing and Identity-Chain Implications
Ransomware groups rarely stop at posting generic “internal files.” When patient data includes email addresses, phone numbers, or usernames, criminals can link those details across dozens of other services. A single leaked dental record can reveal your home address, children’s names, and even gaming usernames if family members used the same contact information for online accounts. These connections create doxxing chains that lead to harassment, SIM-swapping, or account takeovers. Credential leaks like this one routinely cascade into gaming account compromises because children often reuse passwords or security questions tied to family email addresses.