[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fiedlztf9znml":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":32,"seoTitle":33,"seoTitleEn":34,"seoDescription":33,"seoDescriptionEn":35,"logoUrl":36,"isVerified":4,"isSensitive":4,"isSpamList":37,"isMalware":37,"company":38},"68e3266eda11adda488252b1","mmgfusion","MMG Fusion Data Breach","mmg-fusion","mmgfusion.com","2020-12-20T00:00:00.000Z","2021-08-07T23:46:32.000Z","2026-07-18T23:54:28.244Z","Dental practice management breach","https:\u002F\u002Fwww.riskbasedsecurity.com\u002F2021\u002F02\u002F19\u002Fdark-web-roundup-january-2021\u002F",[15],2660295,"known",null,"unknown","Critical",[23,24,25,26,27,28,29,30,31],"Appointments","Dates of birth","Email addresses","Genders","Marital statuses","Names","Passwords","Phone numbers","Physical addresses","\u003Cp>The MMG Fusion data breach concerns patient and account data exposed in December 2020 on the mmgfusion.com service, which is used for dentistry and clinical appointment management. The verified record contains 2,660,295 unique email addresses. The dataset includes appointment information, birth dates, email addresses, genders, marital statuses, names, phone numbers, physical addresses, and bcrypt password hashes in a small subset of records. This incident should not be considered as a direct payment card or full medical file content breach; nevertheless, due to the combination of the healthcare appointment context, contact data, and password hashes, it has a high impact from the user perspective.\u003C\u002Fp>\n\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\n\u003Cp>The data classes confirmed in this incident are appointments, dates of birth, email addresses, genders, marital statuses, names, passwords, phone numbers, and physical addresses. Appointment information can provide sensitive context about the period or clinic where a person received healthcare. When email, phone, and physical address fields are found together, fraudulent messages themed around fake clinic notifications, appointment confirmations, payment reminders, or document updates can become more convincing. Fields such as date of birth and marital status create additional risk in authentication questions or profile matching attempts.\u003C\u002Fp>\n\u003Cp>The password field has been reported as bcrypt hashes for a small set of records. This is not a plain text password claim; nevertheless, the risk remains for weak or reused passwords. If a user used the same password on email, patient portal, social media, or other healthcare accounts, an old breach could affect current accounts. Due to the healthcare appointment context, attackers may not be limited to just account login attempts; they could craft messages appearing to come from patient support lines, appointment centers, or insurance units using real contact information.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The verified event date is taken as December 20, 2020, and the record addition and source change date is taken as August 7, 2021. The unique email count is 2,660,295. Data classes are limited to appointment information, birth dates, email addresses, genders, marital statuses, names, bcrypt password hashes, phone numbers, and physical addresses. For this record, social security number, payment card, bank account, detailed diagnosis, prescription, laboratory result, or full clinical file are not among the verified data classes.\u003C\u002Fp>\n\u003Cp>It is important to read the scope correctly. A match does not indicate that the user's entire medical history has been exposed; however, the presence of appointment and communication data together is sufficiently serious in terms of health privacy. The company context is dental practice management services; therefore, the record should be classified as a dental appointment and patient communication system, not a general technology site. The password risk has also been reported only in a small group of records; nevertheless, a security action is recommended due to the possibility of passwords being reused on other accounts.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>Patients in the highest risk group who use MMG Fusion and are related to dental or clinical services, people with appointment information, and users who use the same email address for healthcare accounts are included. Users with name, phone number, address, and date of birth can be targeted with fake appointment, clinical debt notification, or insurance-themed messages. Fields such as gender and marital status can contribute to making personalized messages appear more convincing. Such information cannot be changed as quickly as financial card data; therefore, it can have long-term privacy effects.\u003C\u002Fp>\n\u003Cp>Dental clinic staff, patients who frequently communicate with the appointment center, and individuals who use the same email address for appointment procedures on behalf of family members should also be careful. Attackers may call the person with real phone and address information, requesting appointment confirmation, document completion, or payment instructions. There is an additional risk for individuals in the small record group containing password hashes; if the same password is valid for other services, account security may be affected. Therefore, a person with a positive match should consider both communication fraud and password reuse together.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>The user who finds a match in this record should primarily be cautious of unexpected emails, SMS, and phone calls related to appointments and clinics. Even if the message contains a real name, phone number, address, or appointment context, it should not be considered trustworthy. Appointment confirmations, payment notifications, document updates, or patient form messages containing links should be verified directly through a known clinic or service address. When requests come by phone, birth date, verification code, card information, or password should not be shared.\u003C\u002Fp>\n\u003Cp>A unique password should be preferred for accounts that use a password. If the user has used the password from the MMG Fusion related account on other services, they should start by changing the passwords for their email and critical accounts. Multi-factor authentication should be enabled on services that support it, active sessions should be closed, and recovery email and phone information should be reviewed. The email account should be especially protected, because notifications for medical appointments and account recovery messages often come to this account.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>In breaches involving health appointments and communication data, the long-term risk is that the data can be used in fraud messages even years later. Users should use unique passwords for health, shopping, social media, and email accounts; phone and address information should be shared only with necessary services. Multi-factor authentication should be preferred for patient portals and clinical communication channels, and old appointment accounts should be periodically reviewed. Personal data and registered contact information should be minimized in unused accounts.\u003C\u002Fp>\n\u003Cp>From the perspective of institutions, this incident demonstrates the importance of data inventory, access control, and password storage quality in dental and health appointment systems. Appointment records are not just calendar information; when combined with patient identity, communication channels, and the context of healthcare, they carry sensitive value. For users, persistent defense means strongly protecting their email account, being cautious against phone scams, verifying clinical messages through a separate channel, and completely eliminating repeated passwords.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>A match in this record indicates that the email address is among the verified addresses in the MMG Fusion data set. A match does not prove that the social security number, payment card, full medical record, or detailed diagnosis information is present in this data set. The verified fields are appointment information, date of birth, email, gender, marital status, name, phone, physical address, and bcrypt password hashes for a small group. The user should correctly read this limitation and focus on both health communication risk and password reuse.\u003C\u002Fp>\n\u003Cp>The first step is to identify accounts that use the same email and similar password patterns. Then, unique passwords should be adopted for the email account, patient portals, healthcare accounts, and social accounts, multi-factor authentication should be enabled, and active sessions should be checked. Links in appointment, clinic, insurance, or payment-themed messages should be verified through a separate channel. This record presents verified data fields without exaggeration and provides actionable steps for the user regarding health privacy, communication security, and password management.\u003C\u002Fp>","","MMG Fusion Data Breach (2.7 Million Reported Records)","MMG Fusion Data Breach. 2.7 Million reported records were reported. Reported data: Appointments, Dates of birth, Email addresses. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fmmgfusion_com.webp",false,{"name":39,"sector":40,"country":41,"website":10,"websiteArchiveUrl":33,"websiteStatus":33,"websiteCheckedAt":19},"MMG Fusion","Dental Practice Management \u002F Healthcare","United States"]