Creative Smiles Pediatric Dentistry Data Breach

Alleged

Ransomware claim involving Creative Smiles Pediatric Dentistry.

Published: Jul 9, 2026 CRPxO
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Creative Smiles Pediatric Dentistry
Industry
Healthcare
Threat Actor
CRPxO
Date of Incident
Jul 9, 2026

Executive Summary

Creative Smiles Pediatric Dentistry, a healthcare provider based in the United States, was listed as a victim by the CRPxO ransomware group on July 9, 2026. This incident was detected by SOCRadar’s Dark Web Monitoring service. The organization operates as a pediatric dental practice, falling within the small-clinic healthcare segment. CRPxO has recently targeted multiple dental and healthcare providers in a concentrated campaign.

Technical Analysis

Initial access to Creative Smiles Pediatric Dentistry’s systems was likely gained through compromised credentials, as evidenced by stealer-log telemetry pointing to the creativesmilesprosper.com domain. The exposed data included corporate credentials, with critical access to Microsoft Entra ID and a healthcare-sector identity provider, potentially unlocking patient and clinical systems. Additionally, several corporate email accounts were linked to third-party dental, insurance, and payment portals. This pattern, featuring reused passwords and a single compromised workstation, suggests a classic credential harvesting scenario. The exposure window for these credentials spans from October 2025 to June 2026. The direct exposure of an identity provider in a healthcare setting represents a severe risk. Ransomware groups like CRPxO frequently use credentials obtained from infostealers as an initial access vector, logging into systems before deploying ransomware. While direct confirmation of CRPxO using these specific credentials is not available, the observed pattern aligns with their typical attack kill chain. Recommended actions include immediate password resets, session revocations, implementing phishing-resistant MFA, and conducting endpoint forensics.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.