On April 3, 2024, Sutton Dental Arts, a dental clinic in Roseburg, Oregon, appeared on the leak site operated by the Medusa ransomware group. The listing states that internal files totaling 20.2 GB were exfiltrated during a ransomware attack. The clinic, which provides a full range of dental services from its office at 1729 W Harvard Ave Ste 5, has three employees, and the disclosure does not specify how many patients or individuals may be affected.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.
Details in the Medusa Listing
The primary disclosure on the Medusa leak site states that Sutton Dental Arts suffered a ransomware incident in which attackers exfiltrated internal files before encrypting systems. The entry lists 20.2 GB of data as the volume leaked and provides a sample of the allegedly stolen material. No patient record count is given, nor does the listing detail the exact categories of information taken beyond describing them as internal files. The clinic’s location and employee count are noted in publicly available business records that align with the leak-site description.
Why This Matters for You and Your Family
If you or your family members have ever received dental care at Sutton Dental Arts, your personal information may now sit inside a 20.2 GB archive controlled by extortionists. Dental records frequently contain full names, dates of birth, Social Security numbers, addresses, phone numbers, insurance details, and sometimes medical history or payment card data. Once that material leaves the clinic’s control, it can be traded or sold on underground forums for years. The breach therefore creates long-term exposure for every current or former patient, especially children whose records often include guardian contact information that links entire households.
Doxxing and Identity-Chain Risks
Ransomware operators rarely stop at posting a single file dump. They understand that one leaked email or phone number can be chained to dozens of other accounts. A dental patient’s address and date of birth, for example, can be combined with credentials from earlier breaches to take over email, banking, or government portals. Public reporting on similar incidents shows these chains frequently lead to doxxing, SIM-swapping attempts, or fraudulent loan applications in the victim’s name. When children’s records are included, gaming accounts tied to the same household email become targets as well, turning a clinic breach into a gateway for broader identity compromise across the family.