CSIDB logo
Incident

Arakyta

Incident posture

Attack window
Sep 2018
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-11-28 00:00

Linked entities

Victim
Arakyta
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Sep 2018
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A ransomware attack targeting IT vendor Arakyta compromised systems containing personal information of a dental healthcare provider's patients and employees. The vendor notified the provider, which confirmed potential unauthorized access but found no evidence of data misuse. In response, the organization initiated an investigation, offered complimentary credit monitoring and identity theft protection services, and began enhancing its data security measures and policy reviews.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

The ransomware attack impacting the Dental Center of Northwest Ohio originated through its third-party IT vendor, Arakyta, with the vendor notifying the healthcare provider of a potential breach around September 1, 2018. Arakyta, based locally in Toledo, experienced a ransomware incident that compromised systems containing sensitive personal data belonging to the Dental Center's current and former patients and employees. The Dental Center disclosed the incident publicly on December 28, 2018, via a press release, indicating a nearly four-month gap between initial notification and public acknowledgment. While the exact ransomware variant, initial attack vector, and specific systems compromised at Arakyta were not detailed in available sources, the breach potentially exposed patient and employee information stored on the vendor's systems.

On November 7, 2018—over two months after Arakyta's initial notification—the Dental Center confirmed that its data housed on Arakyta's systems had been potentially accessible to unauthorized actors during the ransomware event. Despite finding no evidence of actual data access or misuse, the Dental Center proactively initiated breach notifications to affected individuals due to the inherent risk. The organization launched an internal investigation and offered free credit monitoring and identity theft protection services to potentially impacted parties. Additionally, the Dental Center implemented undisclosed additional safeguards and initiated a review of its data privacy and security policies and procedures in response to the incident. The attack underscored third-party risks in healthcare cybersecurity, as the compromise occurred entirely within the vendor's infrastructure rather than the Dental Center's direct systems. No operational disruptions, ransom demands, or financial impacts specific to the Dental Center were disclosed in available reporting.

Sources

Sources available to members: 1 source.

CSIDB