Benjamin H. Wang DDS Inc. Data Breach

Alleged

Ransomware claim involving Benjamin H. Wang DDS Inc.

Published: Jul 9, 2026 CRPxO
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Benjamin H. Wang DDS Inc.
Industry
Healthcare
Threat Actor
CRPxO
Date of Incident
Jul 9, 2026

Executive Summary

Benjamin H. Wang DDS Inc., a dental practice based in the United States, has been identified as a victim of the CRPxO ransomware group. The listing appeared on the group’s dark web portal on July 9, 2026, as reported by SOCRadar’s Dark Web Monitoring. This incident is part of a recent trend where CRPxO has targeted multiple dental and healthcare providers, indicating a focused campaign within the healthcare sector. Benjamin H. Wang DDS Inc. is representative of this targeted group, which primarily consists of small clinics in the United States. The ransomware group has also claimed victims in other regions, including China. This specific targeting of healthcare providers is a concerning pattern, amplifying the potential impact on patient data and services.

Technical Analysis

SOCRadar’s analysis of stealer-log telemetry showed no direct records for benjaminhwangdds.com in the queried data. However, the absence of evidence does not confirm the absence of an attack. Small clinics often utilize personal email and shared platforms, which can result in a subtle corporate footprint in stealer feeds, making detection difficult. Ransomware groups like CRPxO commonly use credentials obtained from infostealers as an initial access vector. These credentials, sourced from underground marketplaces, are used to access systems like Microsoft 365, VPNs, and remote-access portals before deploying ransomware. The lack of direct evidence in the stealer logs does not rule out this method, as credentials might have been sourced from different feeds, rotated, or used under personal aliases. CTI teams are advised to maintain vigilance and conduct regular credential hygiene checks rather than interpreting a null query as a sign of no compromise.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.