Back to Blog
high severity August 12, 2026 · 4 min read Unverified claim — what this is

ProSmile Family Dental Care Listed by Crpx0 Ransomware Group

If you have an account with ProSmile Family Dental Care, here’s what is being claimed, and what it would mean for you.

ProSmile Family Dental Care was listed on the Crpx0 ransomware leak site. The group claims to have stolen internal data.

— from Crpx0’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
ProSmile Family Dental Care Listed by Crpx0 Ransomware Group

Your ProSmile Family Dental Care account details have appeared in a listing published by the ransomware group Crpx0. The company has not publicly confirmed any breach or data theft as of this writing. This means the only information currently available comes from the attacker’s own claims on their leak site.

Already exposed?
You can’t unleak a breach. You can take away what it’s worth.
Deep Sweep shows you every leak tied to you and exactly what to change. Then it strips your name, address and family off the look-up sites that turn a leaked record into somebody knocking on your door — $29 one-time, includes 30 days of Protection. We write to 637 companies. No subscription to start.
Scan free, then Deep Sweep — $29 →
Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.

That single fact shapes everything that follows. You are not being told your patient file is circulating on the dark web. You are being told that one ransomware crew has chosen to list ProSmile as part of its extortion campaign. The difference matters, because it changes both how seriously you should treat the listing today and what practical steps remain under your control.

What the listing actually claims — and what it does not prove

Crpx0 states that it obtained files from ProSmile Family Dental Care and is prepared to publish them unless a ransom is paid. The group’s post includes the usual screenshots and a generic description typical of these announcements. No independent party — not ProSmile, not a cybersecurity firm, not a regulator — has verified that any data was taken, that the screenshots are current, or that the files even belong to this specific practice.

Leak-site listings like this are produced under pressure. Ransomware operators often publish the name of a target early in negotiations to create urgency. In many documented cases the same listing later turns out to contain data recycled from an earlier unrelated breach, data taken from a business partner rather than the named victim, or in some instances no stolen data at all. Until the company itself issues a statement, posts a notification on its website, or regulators require disclosure, the listing remains an unconfirmed accusation rather than established fact.

This is why the strongest lens on the incident is the industry pattern itself: ransomware groups routinely list small and mid-size healthcare providers, especially dental practices, because patient records create immediate emotional pressure on the business owner. The appearance on a leak site therefore tells you more about the attackers’ standard playbook than it does about what, if anything, actually happened inside ProSmile’s systems.

What exposure would mean if patient records were taken

If files were taken, dental practices typically hold names, addresses, dates of birth, phone numbers, email addresses, treatment notes, insurance details, and sometimes Social Security numbers for billing. None of these fields are permanently secret in the way a government-issued ID is, but several remain sensitive for years.

A date of birth paired with a name and address can be used to strengthen identity-theft attempts or to answer security questions on other accounts you own. Treatment history, while private, is not usually the first thing thieves monetize; it is more often used as additional leverage against the clinic or sold in bulk to data brokers.

Importantly, the listing does not disclose how any passwords were stored. The storage scheme itself remains unknown. This means you cannot assume the passwords were safely hashed with a slow, salted algorithm such as bcrypt, nor can you assume they were stored in plain text. The only rational response is to treat your ProSmile password as potentially compromised and replace it immediately on that site and anywhere else you have reused it.

The wider pattern of healthcare extortion listings

Ransomware crews have made healthcare providers a consistent target category for the last several years. Small dental and orthodontic practices are listed with notable frequency because they often operate with limited internal security staff and because patients react strongly when their dental records are threatened with release. The appearance of ProSmile fits this established pattern exactly.

What this pattern gives you for the future is a simple rule: when you receive dental, orthodontic, or general medical care, assume that your basic contact and demographic information could eventually surface in an incident. That assumption lets you make calmer decisions now instead of reactive ones later. It also means the password you choose for every healthcare portal should be unique and strong, because the next listing could belong to any provider you use.

Actions you can take today

  1. Change your ProSmile password immediately. Use a unique, randomly generated password you have never used on any other site. This is the single most useful step available while the facts remain unconfirmed.
  2. Enable two-factor authentication on the ProSmile patient portal if the option exists. Even if the current password may have been exposed, a second factor blocks most direct account takeover attempts.
  3. Review recent statements from any insurance provider linked to your ProSmile account. Look for claims you did not file or addresses that do not match your own. Early detection of fraudulent use of your insurance information is more practical than trying to prevent every possible misuse.
  4. Place a fraud alert with the three major credit bureaus. This adds an extra verification step if someone attempts to open accounts using your name and date of birth. It is a low-effort, reversible measure that remains useful long after this particular listing fades.
  5. Monitor your accounts for unusual login attempts or password-reset emails over the next several weeks. Treat any unexpected communication from ProSmile or connected insurance carriers as suspicious until you verify it through a known contact method.

If you maintain accounts at other dental or medical providers, repeat the password-change step there as well. Reusing credentials across healthcare sites turns one potential incident into many.

GalaxyWarden provides continuous monitoring across 13.1 billion breach records and more than 100 platforms, along with identity-chain mapping and remediation support by specialists.

What the free scan actually returns

Sample resultyou@email.comIllustrative — not a real person

Found on people-search siteswe remove these

These listings are live, public, and legal to remove. That’s what a Deep Sweep buys.

value redacted in this sampleage, relatives, address historySpokeo
value redacted in this samplephone, household, property recordsBeenVerified
value redacted in this sample637 companies checked

Found in breach recordsverifiedreported — unverified

Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.

verifiedvalue redacted in this samplepassword + phone · 2024telecom breach
unverifiedvalue redacted in this sampleclaimed in ransomware listing · 2026leak-site claim

Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.

Check your exposure
ProSmile Family Dental Care is one breach. Your email is probably in others.
We can’t confirm any single incident against the sources we search, so we won’t pretend to. What we can show you is your own exposure — your email against 13.1B+ leaked records and the sites that publish your address. About 15 seconds. No account, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Report details & sourcing

Severity High
Disclosed August 12, 2026
Affected Unconfirmed
Unverified claim — what this report is
This page documents a public listing on a ransomware/extortion group’s leak site, tracked via public threat-intelligence sources. A listing is the attacker’s claim. GalaxyWarden aggregates and reports such claims; we have not independently verified that a breach occurred, what data (if any) was taken, or the accuracy of anything the group asserts, and the named organisation has not necessarily confirmed the incident. Sections above describe what the listing shows and the group’s documented history — not verified findings about the named organisation. If you represent this organisation and believe anything here is inaccurate, tell us and we’ll review it promptly.
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email