The Direwolf extortion gang has added eAssist Dental Solutions to its leak site, claiming it stole internal data from the company that runs outsourced billing for US dental practices. Trackers logged the posting on September 6, and the listing carries no file samples, data volume, or victim count. eAssist has not acknowledged the claim.
eAssist markets itself as a revenue cycle partner for dental offices, handling claims submission, insurance verification, and collections, and it promotes an AI-powered assistant as part of the service. That role puts the company in the middle of patient billing data: names, insurance identifiers, treatment codes, and financial details for the practices it serves. If the claim is accurate, client offices would face downstream notification duties of their own.
Direwolf has cycled through healthcare targets all summer, including ECG device maker AliveCor, Spain’s largest hospital group Quironsalud, a kidney exchange nonprofit, and hospitals in Turkey and Chile. Most of those listings never advanced to confirmed breaches, and trackers caution that leak-site posts are unverified pressure tactics.
The practical read for dental groups and other practices that outsource revenue cycle work is to ask their vendor about the claim, confirm whether any shared systems were involved, and review business associate agreements for notification obligations. Treat outreach from third parties citing this incident with caution until the company confirms scope.