August 24, 2026 Two Dental Groups on Leak Sites in One Week: What It Means When Your Practice’s Name Appears on a Ransomware Blog
Most practices picture a ransomware attack as the morning the screens go dark — every file locked, a ransom note where the schedule used to be. That picture is now half the story, and increasingly the less important half. In a single week this August, two dental organizations appeared not on the news for a system outage, but on the extortion “leak sites” that ransomware gangs use to name their victims. On 21 August 2026, the Rhysida group added Fairview Dental Group to its leak blog. Around the same time, Soniva Dental Care — a practice with roughly a dozen locations — disclosed a breach tied to a ransomware attack that exposed the data of at least 30,000 people. Neither story is fundamentally about locked files. Both are about stolen data being held for ransom in public, and that is a different emergency than the one most offices have prepared for.

What a “leak site” actually is
A ransomware leak site is a public web page — usually hosted on the dark web, sometimes mirrored on the open internet — where a criminal group posts the names of organizations it has breached. Each listing is an ultimatum: pay by the deadline, or we publish everything we took. Some gangs post a sample of the stolen files as proof, a countdown timer, and a running catalogue of victims who did not pay. Security researchers watch these sites closely, which is how a practice’s compromise often becomes public knowledge — a firm like Fairview Dental Group can find itself named on Rhysida’s blog before it has issued a single word of its own.
That is the first uncomfortable truth: for many victims, the leak-site listing is how they learn they were breached. There was no dramatic screen-lock, no obvious outage — just a quiet theft weeks earlier, and then, one day, the practice’s name on a criminal’s website with a timer running.
Steal first, then lock: the double-extortion shift
Early ransomware had a simple business model: encrypt your files, sell you the key. The countermeasure was equally simple — keep good backups, restore, and refuse to pay. Attackers noticed. So the modern playbook is double extortion: before encrypting anything, the intruders spend days or weeks quietly copying data out — patient records, financial files, staff information — and only then trigger the encryption. Now they hold two forms of leverage. Even if you restore every file from backup and never pay to unlock a thing, they still have your patients’ data, and the threat to publish it is entirely separate.

This is why the leak site exists at all. It is the tool that makes the theft profitable independent of the encryption. And it is why a dental practice can do everything right on the recovery side and still be facing the worst part of the incident. We have watched this pattern name dental targets repeatedly this year, from the Qilin gang’s claim against 1-800-Dentist to the string of dental breaches we catalogued earlier in 2026. Fairview and Soniva are not anomalies; they are the trend continuing.
Why your backups matter — and why they are no longer enough
Let there be no confusion: reliable, offline, immutable backups are still essential, and they are still your single best defence against the encryption half of the attack. An immutable backup — one written so that it cannot be altered or deleted, kept offline or in a form ransomware cannot reach — is what lets you rebuild without negotiating for a decryption key. Practices that skip this step are the ones that end up paying simply to reopen. Test those restores, too; a backup you have never successfully restored from is a hope, not a plan.

But notice what a perfect backup does not do: it does not un-steal the copy the attacker already carried out the door. Against double extortion, backups solve the operational crisis and leave the data-exposure crisis entirely intact. That is the mental shift this week’s listings should prompt — from “can we get our systems back?” to “can we keep the data from being taken in the first place?” The most valuable security work has moved earlier in the timeline: stopping the intrusion and the quiet exfiltration, not just recovering after the lock.
The clock that starts whether or not files were locked
Here is the part that catches practices off guard. Under Ontario’s Personal Health Information Protection Act (PHIPA) and, for those with U.S. exposure, HIPAA, your obligations key on whether protected health information was accessed or exposed — not on whether your computers stopped working. If an attacker copied a database of patient records, a reportable breach has occurred even if not one file was ever encrypted and the practice never missed an appointment. The notification duties to affected individuals, and to the Information and Privacy Commissioner of Ontario, begin from the exposure itself.

This is why a leak-site appearance is a legal and ethical event as much as a technical one, and why the response cannot be improvised. The same care you would apply to any handling of patient information under PHIPA and HIPAA applies here in its most acute form. And it is worth being clear-eyed about paying: even when a ransom is paid, there is no guarantee the stolen data is deleted rather than quietly sold or leaked later. You would be trusting the word of the people who just extorted you.
What a dental practice should do before its name could appear
The practices that come through these incidents best are the ones that made their decisions in advance. A practical readiness checklist:
Keep immutable, offline, tested backups. Write-once or air-gapped copies that ransomware cannot reach, and a restore you have actually rehearsed — so the encryption half of any attack is a nuisance, not a catastrophe.
Shut the front doors attackers use. Most intrusions begin with exposed remote access, unpatched internet-facing systems, or stolen credentials — including session cookies that slip past multi-factor authentication. Enforce strong MFA, lock down or remove exposed remote desktop, and patch the perimeter promptly.
Watch for data leaving. Double extortion depends on moving large volumes of data out of your network. Monitoring for unusual outbound transfers can catch the theft before the encryption, at the one moment intervention still prevents the leak.
Write the incident-response and notification plan now. Know who you call, who decides, and exactly what PHIPA and HIPAA require of you — on paper, before the timer is running. The same controls your cyber-insurer now expects you to attest to are largely the ones on this list; having them in place protects your coverage as well as your patients.

The bottom line for your practice
Fairview Dental Group and Soniva Dental Care are this week’s names on the board. The lesson they carry is not that ransomware is new — it is that the threat has quietly moved from locking your files to stealing your patients’ data and threatening to publish it. Backups still matter, but they are the answer to yesterday’s version of the attack. The version naming dental practices today is won or lost earlier: at the perimeter, in your credentials, and in the plans you make before you ever need them.
If you would like a clear, practical assessment of where your practice stands — whether your backups are truly immutable and tested, whether your remote access and MFA would stop an intrusion, whether anyone would notice data leaving, and whether your breach-notification plan is ready to go — contact Compudent Systems. We help dental practices across Ontario prepare for the incident they hope never comes, so that if a gang ever comes knocking, your name is one that stays off the list.
Sources & further reading:
- Dental Cyber Watch / dental ransomware coverage — Group Dentistry Now
- Ransomware.live — Fairview Dental Group claimed by Rhysida
Related Reading
- Ransomware Is Now a Patient-Safety Issue: What a 38% Hospital Mortality Study Means for Your Dental Practice
- Dental Practices Under Siege: The Rising Threat of Ransomware Targeting Healthcare Data
- The FBI Just Refreshed Its Medusa Ransomware Warning for Healthcare: The Real Lesson for Your Dental Practice