On February 17, 2026, the LockBit5 ransomware group added smilescare.com to its leak site, claiming that internal files had been exfiltrated from the dental-care information platform during a ransomware attack.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch smilescare.com
Get alerted the next time smilescare.com files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about smilescare.com’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates the incident involves a ransomware deployment that led to both encryption and data theft. The LockBit5 leak page lists SmilesCare.com and displays samples of the stolen material. Available reporting describes the exposed data as internal files, though the exact volume and full list of records remain undisclosed by the attackers. No confirmed victim count has been published, leaving an unknown number of patients, employees, and partners potentially affected. The breach follows the group’s standard pattern of posting a deadline before public release of larger data sets.
Why This Matters for You and Your Family
When a health-related service like SmilesCare is breached, the information involved often includes names, addresses, dates of birth, phone numbers, email accounts, and treatment details. These records are valuable to identity thieves because medical data is difficult to change and can be used for insurance fraud, prescription scams, or targeted phishing. If you or your family members have used the platform for dental-care information, appointments, or account registration, your personal details may now sit in a criminal repository. Even without direct confirmation of your exposure, the uncertainty itself creates stress and forces extra vigilance over accounts and mail.
The Doxxing and Identity-Chain Risks
Stolen internal files frequently contain not just patient records but also employee spreadsheets, vendor contacts, and login credentials. Once these appear on a ransomware leak site, other criminals scrape them and begin linking disparate pieces of information. A single email address can connect to social-media handles, reused passwords, and children’s accounts. This chaining turns one breach into repeated targeting: doxxing attempts, SIM-swapping attempts, or gaming-account takeovers that expose family photos, home addresses, and real-time location data. Credential leaks like this one regularly cascade into children’s gaming accounts because kids often reuse simplified versions of family passwords.