Quick Summary
AllegedExecutive Summary
SF Smile Doctor, a healthcare provider in the United States specializing in dental services, was identified as a victim by the CRPxO ransomware group. The listing, published on July 9, 2026, was detected by SOCRadar’s Dark Web Monitoring service. This incident is part of a recent campaign by CRPxO specifically targeting dental and healthcare providers, with other similar small clinics in the US also being named in the same period. The group’s activity shows a concentration of victims in the United States, with an additional victim noted in China.
Technical Analysis
SOCRadar’s threat intelligence did not find direct evidence of SF Smile Doctor’s online presence (sfsmiledoctor.com) in its stealer-log telemetry within the queried timeframe. However, this absence of immediate telemetry does not confirm a lack of compromise. Small organizations may use personal email aliases or rely on shared practice management platforms, potentially obscuring their digital footprint in public stealer feeds. Moreover, credentials harvested by infostealers are a known initial access vector for groups like CRPxO, who source these credentials from underground markets to gain access to corporate networks before deploying ransomware. CTI teams are advised to continue monitoring and implement credential hygiene measures, as a null query result does not equate to a clean bill of health.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.