On January 2, 2026, Sai Oral Surgery appeared on the leak site operated by the qilin ransomware group. The listing states that internal files were exfiltrated during a ransomware attack on the dental surgery practice. While the exact number of patients and employees whose records were taken remains unknown, anyone who has visited the clinic or worked there could have personal information now in the hands of criminals.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.
What Public Reporting Shows
Public reporting indicates the practice was listed on the official qilin leak portal with a claim that internal data had been stolen. The group typically posts samples or announcements after encryption and exfiltration. No independent verification of the full dataset has been published, but ransomware.live tracks the entry as legitimate based on the group’s own site. The breach involves internal files rather than a single exposed database, which often means a mix of patient records, insurance details, contact information, and operational documents.
Why This Matters for You and Your Family
If you or a family member received treatment at Sai Oral Surgery, your name, address, date of birth, Social Security number, insurance policy numbers, and medical history may now be outside the clinic’s control. Medical data is especially sensitive because it can be used for identity theft, insurance fraud, or targeted scams that sound legitimate because they reference real procedures or diagnoses. Even if you were not a patient, employees’ payroll records, tax forms, and personal documents could also be exposed, putting household finances at risk. Once this information leaves a secure environment, it rarely stays contained.
The Doxxing and Identity-Chain Implications
Ransomware groups rarely stop at one leak. Stolen internal files frequently contain email addresses, phone numbers, and usernames that link to personal accounts across the internet. These connections create an identity chain: criminals combine the medical data with credential leaks from other breaches to take over email, banking, or social media accounts. Gaming accounts belonging to children are particularly vulnerable because kids often reuse passwords or email addresses tied to family records. A single breach like this can cascade into doxxing, harassment, or financial fraud that affects every member of the household.