
Arkansas Oral & Maxillofacial Surgeons (AMOS), an oral surgery practice with locations in Conway, Russellville and Fort Smith, Arkansas, disclosed a data breach involving unauthorized access to its computer systems in early April 2026.
The breach was reported to the Massachusetts Office of Consumer Affairs and Business Regulation on Aug. 4, 2026. The practice began notifying consumers in August 2026 and posted a notice on its website providing information about the incident and steps individuals can take to protect themselves.
The breach was a ransomware attack carried out by a threat actor known as PEAR.
On April 7, 2026, the practice learned of potential unauthorized access to its computers and initiated an investigation. Just three days later, on April 10, 2026, the PEAR ransomware group posted on the dark web, claiming it had obtained 2.1 terabytes of the organization's data.
The stolen information allegedly included financials, human resources records, providers' and vendors' data, numerous patients' personally identifiable information and protected health information records, payment details, mailboxes and email correspondence, cloud-stored data and database exports.
On June 2, 2026, the practice's investigation determined that an unauthorized third party had acquired some of its files containing patient information, according to the company's notification.
The types of personally identifiable information potentially exposed included government identification numbers such as Social Security numbers, patient names, contact information, dates of birth and payment information.
The types of protected health information potentially exposed included medical record numbers, diagnosis information, treatment records, health insurance information and prescription history.
AMOS is offering affected individuals complimentary credit monitoring, health information monitoring, and identity theft protection services through CyEx. To register for the services, follow the steps included in the notification letter mailed to individuals.
The deadline to enroll is specified on each individuals' letter.
Individuals with questions about the incident can call the practice at 1-844-540-3159. Additionally, AMOS set up a dedicated email address for individuals who have questions about the incident or want additional information. Those who may have been affected can contact the company at SecurityEvent2026@aoms.info.








.webp)
.webp)
.webp)

.webp)
.webp)
.webp)
.webp)