Soniva Dental Care
Incident posture
Linked entities
- Victim
- Soniva Dental Care
- Threat actors
- 1 actor
- Sources
- 1 source
Timeline
Summary
Soniva Dental Care, a multi‑location dental practice with 14 offices in the United States, disclosed a breach after a ransomware attack on its remote desktop web services was detected. The attackers, identifying themselves as The Gentlemen, claimed responsibility and later released patient data that included names, addresses, dates of birth, driver’s license numbers, government IDs and protected health information, with Social Security numbers among the exposed details. The incident affected at least 30,000 Texans, with individual location impacts reported as 11,790 at Agave Dental Floresville, 4,013 at Allwyn Dental, 9,444 at Azle Smiles, 6,027 at Kashi Dental, 3,394 at Mysa Dental and 3,476 at Wilson Dental. The practice is providing free identity‑protection monitoring to those affected and has notified the Texas Attorney General and the U.S. Department of Health and Human Services.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
Soniva Dental Care, a multi-location dental practice with 14 locations across the United States, disclosed a data breach after a ransomware attack was discovered in late May 2026. The attack targeted the company's remote desktop web services infrastructure. The incident was identified when the company's IT support provider observed irregularities related to remote access session hosts. Within a few minutes of noticing those irregularities, it became clear that an attack had occurred. The breach was initially detected internally before any public disclosure was made.
On June 1, 2026, six days after the breach was first discovered, a ransomware group known as The Gentlemen claimed responsibility for the attack on a dark web forum hosted on the Tor network. The group stated that it had obtained Soniva Dental Care's data and intended to publish the information within nine to ten days. By July 28, 2026, the ransomware group indicated that the full dataset had been made publicly available and that it included additional information types such as patients' Social Security numbers. Soniva Dental Care's investigation determined that certain personal information belonging to patients associated with the practice might have been accessed during the incident. The disclosed types of personally identifiable information that may have been exposed included names, addresses, dates of birth, driver's license numbers, and government-issued IDs. Protected health information was also among the data that may have been compromised.
To inform affected individuals, several of Soniva Dental Care's locations posted notices to patients, specifying the numbers of Texans impacted at each site: Agave Dental Floresville reported 11,790 affected individuals, Allwyn Dental reported 4,013, Azle Smiles reported 9,444, Kashi Dental reported 6,027, Mysa Dental reported 3,394, and Wilson Dental reported 3,476. The combined figure exceeds 38,000 Texans, supporting the earlier statement that at least 30,000 Texans were affected. In response to the breach, Soniva Dental Care is offering complimentary identity protection monitoring services at no cost to affected patients and has provided a toll-free telephone number, 844-473-3900, for inquiries or enrollment. The company's locations have reported the breach to the Texas Attorney General and to the U.S. Department of Health and Human Services.
Sources
Sources available to members: 1 source.