Attorneys at Almeida Law Group are investigating whether a class action lawsuit can be filed on behalf of individuals affected by a possible O2 Dental Group data breach. According to dark web monitoring sources, a hacker group calling itself interlock claimed responsibility for a cyberattack on O2 Dental Group in a post first observed in October 2026, alleging it had gained access to internal company systems. As of this writing, O2 Dental Group has not issued a public confirmation of the incident, and the exact scope of any exposed data remains unknown. If you believe you were affected, contact Almeida Law Group.
About O2 Dental Group
O2 Dental Group is a multi-location dental practice based in North Carolina, co-founded by Dr. Olu Oyegunwa and Dr. Lydia Oyegunwa. The practice first opened in 2018 in Wilmington, NC, and has since grown to six locations across the state, including offices in Durham, Fayetteville, Raleigh, Siler City, Southern Pines, and Wilmington. The practice offers general, cosmetic, restorative, emergency, and implant dentistry services. As a healthcare provider operating under HIPAA, O2 Dental Group handles patient health records and related documentation, making any potential compromise of its systems a serious concern for patients.
What Happened?
O2 Dental Group was listed in a ransomware leak-site allegation reported by Ransomware.live. On October 5th, 2026, the Interlock ransomware group posted a claim on its dark web leak site identifying O2 Dental Group as a victim. The attacker’s posting specifically references the Wilmington location and alleges that O2 Dental Group failed to comply with required security measures. The claim further alleges that patient health records (PHI), billing and insurance documents, and consent and authorization forms were compromised. These are attacker-side assertions only and have not been confirmed by O2 Dental Group or any independent source. No regulatory filing with HHS or the Office for Civil Rights has been located, and no independent corroborating sources have been found.
Interlock is a ransomware group that has been active since September 2024. It operates as a closed group rather than using the ransomware-as-a-service model common among other threat actors, and it has been tracked by IBM X-Force under the designation Hive0163. Researchers at IBM and Amazon have published detailed technical analyses of Interlock’s operations. In early 2026, the group was found to have exploited a critical Cisco Secure Firewall zero-day vulnerability (CVE-2026-20131) and deploys custom malware tools including NodeSnake and InterlockRAT. While Interlock is a well-documented and capable threat actor, its operational history does not confirm any specific claim made against O2 Dental Group.
Key Facts at a Glance
- Company or Organization: O2 Dental Group
- Industry: Healthcare — Dental
- Location: Headquartered in North Carolina, with offices in Durham, Fayetteville, Raleigh, Siler City, Southern Pines, and Wilmington
- Incident type: Ransomware leak-site allegation (unverified)
- Date claim first observed: October 5th, 2026
- Source: Ransomware.live — Victim: O2 Dental Group; IBM X-Force — Interlock and Rhysida within the ransomware ecosystem; GovInfoSecurity — Interlock Ransomware Exploited Cisco Firewall Flaw for Weeks; O2 Dental Group — About Us
What Should You Do?
If you are a patient of O2 Dental Group and are concerned about this allegation, there are practical steps you can take now. Consider placing a fraud alert or credit freeze with the three major credit bureaus — Equifax, Experian, and TransUnion — to make it harder for anyone to open new accounts in your name. Monitor your existing financial accounts closely for any suspicious activity and request your free credit reports at AnnualCreditReport.com. Because the attacker’s claim specifically references patient health records, also review any Explanation of Benefits statements from your insurer and check your medical records for services you do not recognize. If you discover signs of identity theft or fraud, report them to the Federal Trade Commission at IdentityTheft.gov.
Your Legal Rights
If your personal or health information was involved in this breach, you may have legal rights depending on the facts of the incident and the law in your state. Almeida Law Group represents consumers in data breach and privacy litigation and can help you evaluate whether you may have a claim. Contact us at (708) 529-5418 or through our contact page for a free case evaluation.