Breach tracker

Breach report

DentaQuest notifies at least 15 million people after May network intrusion

ConfirmedDisclosed United StatesHealthcareBy Vivek Kumar
Records 15MCause Data theftAttributed / claimed ShinyHunters
Conceptual illustration: A sculptural porcelain tooth beside anonymous dental-benefits folders and a fractured glass data panel. Headline: DENTAQUEST DATA BREACH.

AI-generated illustration by CyberShitty. Not a photograph or a document from the organisations named.

The US dental benefits administrator says an intruder was in its network from 17 to 20 May 2026. ShinyHunters claimed the attack and published data after talks failed.

What happened

DentaQuest, part of Sun Life U.S. Dental and the largest Medicaid and CHIP dental benefits administrator in the US, learned of unauthorised access to its network on 20 May 2026. According to its notice to the California Attorney General, as reported by the HIPAA Journal, the intruder had access to parts of the network between 17 and 20 May. The company began sending letters on a rolling basis from 17 July and has confirmed at least 15 million people are affected. The review is ongoing, so the total may rise.

Confirmed vs. claimed

Confirmed by DentaQuest: names, addresses, Social Security numbers, member IDs, Medicaid and Medicare numbers, and dental or vision health information such as provider, diagnosis, treatment and billing details. It is offering 24 months of credit monitoring.

Claimed: ShinyHunters said it took 234 GB and published it after DentaQuest did not pay. DentaQuest's notice does not name the group. Have I Been Pwned says the published files contained 2.6 million unique email addresses, much of it in healthcare enrollment files, some with Medicaid IDs. An independent researcher told the HIPAA Journal the final count could exceed 23.4 million; that figure is unverified.

Who is affected

Current and former members of dental and vision plans that DentaQuest administers, many of them Medicaid and Medicare beneficiaries.

What to do

  • Enrol in the free credit monitoring in your letter.
  • Place a credit freeze with the US bureaus, including for children on your plan, whose unused credit files are easy to abuse.
  • Report any Medicaid or Medicare statements for care you did not get.
  • Because the data is public, expect targeted phishing that quotes your member ID.
  • See our guides on ShinyHunters extortion emails and what to do after a data breach notice.

Sources

More breaches in United States