CSIDB logo
Incident

Arkansas Oral & Maxillofacial Surgeons

Incident posture

Attack window
Apr 2026
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-01 09:49

Linked entities

Victim
Arkansas Oral & Maxillofacial Surgeons
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Pending
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Arkansas Oral & Maxillofacial Surgeons identified a breach on April 7, 2026, where an unauthorized party exfiltrated patient files; PEAR threat group claimed responsibility for data theft and extortion.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On April 7, 2026, Arkansas Oral & Maxillofacial Surgeons, a Hot Springs, Arkansas-based provider of oral surgery, dental implants, and other dental and cosmetic dentistry services, identified a data security incident affecting its network. Following the detection, the organization initiated an investigation to determine the nature and scope of the unauthorized activity. The probe continued for nearly two months, and on June 2, 2026, investigators confirmed that an unauthorized third party had gained access to the organization's network and had exfiltrated files containing patient information. The confirmation marked the transition from initial containment and review efforts to a full data analysis process to identify what categories of information had been exposed.

The subsequent file review determined that the compromised data included a broad range of sensitive patient information. Specifically, the exfiltrated files were found to contain patient names, contact information, birth dates, medical record numbers, government identification numbers including Social Security numbers, diagnoses, treatment records, health insurance information, prescription histories, and payment information. This combination of identifiers, clinical details, and financial data indicated that the breach carried a significant risk of identity theft, medical fraud, and other forms of misuse for the affected individuals. The variety of data elements exposed suggested that the attacker had obtained access to a substantial portion of the practice's clinical and administrative records.

Once the affected files had been identified and reviewed, Arkansas Oral & Maxillofacial Surgeons began notifying impacted individuals by mail. The notifications included recommendations on how patients could protect themselves against potential data misuse. Based on the substitute breach notice published on the organization's website, credit monitoring and identity theft protection services did not appear to have been offered as part of the response. As of the publication date of the source article in August 2026, the incident had not yet appeared on the U.S. Department of Health and Human Services' Office for Civil Rights breach portal, leaving the total number of affected patients unclear. This delay in posting to the federal breach portal further obscured the full scope of the incident from public view.

The nature of the attack aligned with the tactics of the PEAR threat group, which claimed responsibility for the breach. Unlike traditional ransomware operations, PEAR does not encrypt victim files; instead, the group engages in data theft and extortion, threatening to publish stolen data if the ransom demand is not paid. This confirmed that the Arkansas Oral & Maxillofacial Surgeons incident was a data theft and extortion attempt rather than a ransomware encryption event. The reliance on the threat of public exposure rather than system disruption reflected the group's focus on leveraging the sensitivity of healthcare data to pressure victims into paying.

The incident at Arkansas Oral & Maxillofacial Surgeons was one of five security events disclosed by small healthcare organizations around the same period. The breadth of data exposed, including government identification numbers, clinical details, and payment information, underscored the operational and reputational impact such breaches can have on specialty medical and dental practices. The organization's response involved detection on April 7, 2026, confirmation of exfiltration on June 2, 2026, and subsequent patient notification, while leaving questions about the final patient count, the specific attack vector used to gain initial network access, and the resolution of any extortion attempt unanswered in the public record.

Sources

Sources available to members: 1 source.

CSIDB