CSIDB logo
Incident

British Dental Association

Incident posture

Attack window
Jul 2020
Location
United Kingdom
Status
Historical
CIA posture
Available to members
Updated
2025-10-29 00:00

Linked entities

Victim
British Dental Association
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jul 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The British Dental Association experienced a ransomware attack compromising sensitive member and patient data. Attackers accessed bank account numbers and sort codes used for direct-debit payments, alongside correspondence logs and case notes potentially containing patient information. The hacker publicly disclosed stolen files on a dark web forum and leveraged social media to pressure the organization by sharing images of the exfiltrated data. While the breach did not involve stored payment card details, the exposure of financial identifiers and clinical case notes raised significant security concerns for affected dentists and their patients.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

In late July 2020, the British Dental Association (BDA) experienced a ransomware attack compromising sensitive member data. The breach first appeared on a Russian-language cybercrime forum, where threat actors posted evidence of unauthorized access to BDA systems. Attackers exfiltrated UK dentists' bank account numbers and sort codes, which the organization stored to process direct-debit membership payments. While payment card details remained unaffected, the theft of financial routing information created immediate fraud risks for dental professionals. The hackers escalated pressure tactics by creating a dedicated Twitter account to publicly share samples of stolen data, despite platform policies prohibiting such disclosures.

The BDA notified members via email that attackers likely accessed correspondence logs and clinical case notes alongside banking information, indicating potential exposure of sensitive patient details. Cybersecurity observers noted the persistent visibility of the hacker's Twitter account despite its violation of platform rules against sharing hacked materials. Meanwhile, the original forum where attackers first posted proof of compromise banned the perpetrator, though stolen records resurfaced on alternative dark web platforms. This incident exposed dental practitioners to financial fraud risks through compromised banking credentials while creating secondary privacy concerns through potential patient data exposure in clinical correspondence. The organization's breach disclosure confirmed data theft but did not specify remediation steps beyond initial member notifications.

Sources

Sources available to members: 1 source.

CSIDB