Were you recently affected by a data breach?

All Smiles Dental of Falls Church Data Breach

All Smiles Dental of Falls Church, a Northern Virginia dental practice, has reportedly been targeted by the ransomware group The Gentlemen, according to dark web monitoring sites. The practice has not publicly confirmed a breach, and the scope remains unknown.

All Smiles Dental of Falls Church
Date of Breach: Reportedly October 6, 2026 (unconfirmed)
CAU logo

Who was affected:

Clients of All Smiles Dental of Falls Church

Impacted Data:

Not yet disclosed. The practice has not confirmed a breach or the types of information involved.

All Smiles Dental of Falls Church, a dental practice serving Northern Virginia, was listed in early October 2026 by cybersecurity monitoring sites as a possible victim of a ransomware attack. The practice has not publicly confirmed a data breach.

Here is what has been reported so far and what you can do now.

All Smiles Dental of Falls Church’s Data Breach Investigation

All Smiles Dental of Falls Church is a dental practice based in Falls Church, Virginia, that provides general dental care to patients in the Northern Virginia area. Dental offices keep detailed records on their patients, including contact details, insurance information, health histories, X-rays and billing records, which is one reason healthcare practices of every size are regular targets for cybercriminals.

According to a post on the dark web monitoring site Ransomware.live, a hacker group known as The Gentlemen listed the practice as a victim. The post is dated October 9, 2026 and gives an estimated attack date of October 6, 2026. Another cybersecurity tracking platform, Breachsense, similarly reports that The Gentlemen claimed responsibility for an attack on the practice and lists a discovery date of October 7, 2026.

These are claims made by a criminal group and relayed by monitoring services. They are not a confirmation from the practice itself. As of this writing, we did not find a notice from All Smiles Dental of Falls Church, a filing with a state attorney general or a statement to patients that confirms a breach occurred, explains how it happened or says what information was involved. Breachsense lists the size of the alleged leak as unknown.

That distinction matters. Ransomware groups sometimes post a victim’s name on a leak site before the victim has finished investigating, and some claims are later shown to be exaggerated or incomplete. In other cases the claim is accurate and the practice later sends formal notices to patients. At this stage, it is not possible to say which category this report falls into, and this page does not suggest that any particular person’s information was taken.

What can be said is general. When a ransomware group lists a healthcare practice on a leak site, the usual concern is that files were copied from the practice’s systems before or while they were locked, and that the group may publish them if a ransom is not paid. If that happened here, the information could in theory include the kinds of records a dental office keeps. We have no evidence about which records, if any, were involved, and this paragraph describes the typical pattern only.

Under federal and state law, healthcare providers that confirm a breach of protected health information generally have to notify affected patients, often within a set number of days after discovery, and they may also have to notify regulators. Those notices can take weeks or months to appear, because the practice first has to investigate, identify which files were accessed and work out whom to contact. A formal letter, if one comes, would be the first reliable source of detail about what was exposed.

The monitoring reports we found do not say whether the practice’s systems were disrupted, whether appointments were affected, or whether patient records were encrypted or copied. Without a statement from the practice, those questions remain open, and readers should be careful about secondhand claims that go beyond what the monitoring sites actually state.

If you are a current or former patient or an employee of the practice, you do not need to wait for a letter to take sensible precautions. You can review your explanation-of-benefits statements and bank accounts, watch for unexpected calls or emails that mention dental care or your insurance, and consider placing a free fraud alert or credit freeze. These steps are low-cost and useful whether or not this report turns out to involve your information.

We will treat this as a developing situation. Reports from monitoring sites can change quickly, and the practice may later confirm, deny or clarify what happened. If you receive a notice from All Smiles Dental of Falls Church, keep it, since it should describe the type of information involved and any protection services being offered to you.

When Did This Breach Occur?

Ransomware.live estimates the attack took place on October 6, 2026 and posted about it on October 9, 2026. Breachsense lists a discovery date of October 7, 2026.

These dates come from third-party monitoring sites reporting a criminal group’s claim. The practice has not confirmed any dates, so the actual timeline, if there was an incident, may differ.

What Information Was Breached?

It is not known what information, if any, was taken. The monitoring reports do not itemize the data, and Breachsense lists the size of the alleged leak as unknown.

Dental practices typically hold patient names, contact details, dates of birth, insurance information and treatment records, but this page does not say that any of those were involved here. Only a confirmed notice from the practice can say what applied to you.

What You Can Do

If you received a notice from All Smiles Dental of Falls Church or believe you may be affected, consider these steps:

  • Read the notice carefully and keep it, along with any enrollment details for protection services it offers.
  • Place a free fraud alert or a credit freeze with Equifax, Experian and TransUnion, and get your reports free at annualcreditreport.com.
  • Watch your financial accounts, tax records and any insurance or medical statements for activity you do not recognize.
  • Be skeptical of unexpected calls, texts or emails that mention the organization, and report suspected identity theft to the Federal Trade Commission at identitytheft.gov and to your state Attorney General.

File a Data Breach Lawsuit Against All Smiles Dental of Falls Church

If you are a patient or employee of this practice and you receive a breach notice, you may have legal options. Healthcare providers are expected to protect the sensitive records they hold, and a class action can help hold a provider accountable when it fails to do so.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Reportedly October 6, 2026 (unconfirmed)
Date of Breach: Discovered August 10, 2026
Date of Breach: Not publicly disclosed
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.