Cyber Incident Victim: DentaQuest
Date:
May 2026
Location:
United States of America
Summary
DentaQuest discovered a breach after attackers accessed its network, obtaining names, addresses, Social Security numbers, member identification numbers, Medicaid and Medicare numbers, provider names, diagnosis, treatment details, and billing information; the incident also exposed email addresses, phone numbers, dates of birth, and government‑issued IDs according to leaked data. The organization is offering affected individuals 24 months of free credit monitoring, fraud consultation, and identity theft restoration, and has sent written notification letters to at least 4.5 million people based on filings with state attorneys general, while estimates indicate that more than 23.4 million individuals were potentially impacted and at least 15 million were confirmed affected. The extortion group ShinyHunters claimed responsibility and released roughly 234 gigabytes of the stolen data. A Sun Life subsidiary that administers dental benefits for about 35 million people nationwide, it is managing the response.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 0 techniques |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
DentaQuest discovered the data breach on May 20, 2026, after noticing unauthorized activity on its network. An investigation determined that attackers had gained access to the organization’s systems between May 17 and May 20 of the same year. During this window, the intruders were able to view and copy a range of personal and health‑related information stored by the benefits administrator. The accessed data included names, mailing addresses, Social Security numbers, member identification numbers, Medicaid and Medicare numbers, benefits provider names, diagnosis and treatment details, and billing records.

Based on filings with the attorneys general of Texas, Massachusetts, and South Carolina, DentaQuest began sending written notification letters to at least 4.5 million individuals whose information was involved. The HIPAA Journal reported that more than 23.4 million people were potentially affected by the incident, while DentaQuest itself confirmed that at least 15 million individuals had their data compromised. The breach exposed not only traditional identifiers but also sensitive health information such as diagnoses, treatment specifics, and insurance numbers.
In response, DentaQuest offered all affected persons 24 months of free credit monitoring, fraud consultation, and identity theft restoration services. The company also coordinated with state authorities as part of the notification process required by the Attorney General’s offices. Shortly after the breach became public, the extortion group ShinyHunters claimed responsibility for the attack and stated that it had leaked approximately 234 gigabytes of data allegedly taken from DentaQuest. Early June postings on the HaveIBeenPwned breach notification site indicated that the leaked material additionally contained email addresses, phone numbers, dates of birth, and various government‑issued identification numbers.
