eAssist Cyber Attack

I am writing as your IT partner because a ransomware group known as Dire Wolf (Direwolf) listed eAssist Dental Solutions (dentalbilling.com) as a victim on dark-web leak sites around September 6, 2026. eAssist is a large dental billing and administrative vendor used by thousands of practices. That is why this matters even if your office network was never touched.

What is confirmed vs. what is not

Multiple ransomware-tracking sources recorded the listing and attributed it to Dire Wolf.

Dire Wolf is an active double-extortion group: they typically encrypt systems and steal data, then threaten to publish it if a ransom is not paid. Healthcare is among the sectors they have targeted.

A listing is not the same as a verified, official confirmation from eAssist of what (if anything) was accessed, encrypted, or stolen. As of this writing I have not seen a public incident notice from eAssist describing scope, data types, or dates. Treat the claim as a serious vendor-risk event until they say otherwise.

Why dental practices should care

eAssist handles insurance billing, claims, patient billing, and related records for many offices. If a business associate that holds or processes your patients’ information is compromised, your practice can still have HIPAA and patient-notification obligations, even when the attack happened at the vendor. Billing files can include names, DOB, insurance IDs, treatment/coding data, and sometimes SSNs or financial details.

What you should do now

1. Contact eAssist in writing today. Ask whether they experienced an incident, what systems and data were involved, whether your practice’s data is in scope, when they will issue a formal notice, and how they will meet BAA / HIPAA breach-notification duties. Keep the email and any ticket numbers.

2. Pull your Business Associate Agreement and note notification timelines. Do not wait for patients to ask; document that you inquired promptly.

3. Rotate anything shared with eAssist or their staff: portal passwords, remote-access accounts, VPN, RDP, practice-management “biller” logins, shared mailboxes, and API/integration credentials. Turn on MFA everywhere it is not already on.

4. Review who can reach your practice-management system from outside the office. Notify Wildcard Dental if you have authorized remote access for a vendor without our knowledge.

5. Watch for follow-on phishing. After vendor incidents, staff often get emails that look like “eAssist security update”, “claim portal lockout,” or “verify your billing login.” Do not click. Call eAssist or us on a known number.

6. Alert your cyber / malpractice carrier that a key vendor was listed. Early notice often matters more than waiting for a confirmed letter.

7. Do not pay or negotiate with attackers. Do not visit leak sites from practice computers. If you receive a ransom note or “proof pack,” forward it to us and counsel; do not open attachments.

8. Prepare a short patient script for the front desk: we are monitoring a reported vendor incident, we have no confirmed impact to this office yet, we will notify if required. Avoid speculation.

What we will do as your MSP

- Review remote access, vendor accounts, MFA, and logging on your environment.

- Hunt for unusual logins, new admin users, unexpected remote tools, and large outbound file transfers.

- Help you document vendor outreach for HIPAA / insurance files.

- Coordinate with eAssist’s technical contacts if you authorize us.

Please reply to this email if you use eAssist (or used them in the last several years), if you have shared credentials with their team, or if anything looks off on your systems. We would rather check a false alarm than miss a real one.

This situation can change quickly if eAssist publishes an official statement. We will update you if material new facts appear.

Sincerely,

Wildcard Dental

(206) 686-1755 · support@wildcarddental.com

---

This notice is based on public ransomware-tracker listings as of September 9, 2026, and is not a determination that your practice’s data was accessed.

You don’t think you need IT. Until you need IT.

Get in touch.