Cyber Incident Victim: Soniva Dental Care
Timeline
Summary
Soniva Dental Care experienced a ransomware attack on its remote desktop web services that was discovered after irregularities in remote access session hosts were noticed. Shortly after, the ransomware group The Gentlemen claimed responsibility on a dark web forum, stating it had obtained the data and intended to publish it within days, later indicating the full dataset had been made publicly available. The compromised information included names, addresses, dates of birth, driver's license numbers, government‑issued IDs, and protected health information, affecting at least 30,000 Texans across the provider’s locations with patient counts of 11,790, 4,013, 9,444, 6,027, 3,394, and 3,476. The organization reported the breach to the Texas Attorney General and the U.S. Department of Health and Human Services and offered complimentary identity protection monitoring to those impacted.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
Soniva Dental Care, a dental practice operating 14 locations across the United States, disclosed a data breach after a ransomware attack was discovered in late May 2026. The attack specifically targeted the company's remote desktop web services infrastructure. Irregularities in remote access session hosts were noticed by the practice's IT support company, leading to the identification of the breach within a few minutes. On June 1, 2026, six days after the breach was first detected, the ransomware group known as The Gentlemen claimed responsibility for the incident on a dark web forum hosted on the Tor network. The group stated that it had obtained Soniva Dental Care's data and intended to publish the information within nine to ten days. By July 28, 2026, The Gentlemen indicated that the full dataset had been made publicly available and included additional information types such as patients' Social Security numbers.

Through its investigation, Soniva Dental Care determined that certain personal information belonging to patients associated with the practice might have been accessed during the incident. The disclosed types of personally identifiable information that may have been exposed included names, addresses, dates of birth, driver's license numbers, and government-issued IDs, while protected health information was also among the data that could have been compromised. Individual locations posted notices to patients detailing the impact: Agave Dental Floresville reported that 11,790 Texans were affected, Allwyn Dental reported 4,013 Texans affected, Azle Smiles reported 9,444 Texans affected, Kashi Dental reported 6,027 Texans affected, Mysa Dental reported 3,394 Texans affected, and Wilson Dental reported 3,476 Texans affected. The combined figures indicate that at least 30,000 Texans had their information potentially exposed. In response to the breach, Soniva Dental Care began offering complimentary identity protection monitoring services at no cost to affected patients. Those wishing to participate or with questions about the incident can contact the company toll-free at 844-473-3900. Soniva Dental Care's locations have reported the breach to the Texas Attorney General and the U.S. Department of Health and Human Services.
