CSIDB logo
Incident

DentaQuest

Incident posture

Attack window
May 2026
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-08-28 16:45

Linked entities

Victim
DentaQuest
Threat actors
1 actor
Sources
6 sources

Timeline

Occurred
May 2026
Discovered
May 2026
Disclosed
Jul 2026
Resolved
Pending

Summary

DentaQuest discovered that unauthorized individuals accessed its network, exposing personal and health information such as names, addresses, Social Security numbers, member and medical IDs, diagnoses, treatments and billing details for millions of people. The company confirmed that at least 15 million individuals were affected, while investigations suggest the potential impact could exceed 23 million. ShinyHunters claimed responsibility for the intrusion, alleging theft of 234 gigabytes of data and publishing portions on a dark web leak site. In response, the company engaged external cybersecurity experts, secured its systems, notified law enforcement and began offering affected individuals free credit monitoring and identity theft protection services.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

In May 2026, DentaQuest detected unauthorized access to its computer network on May 20, after which an investigation determined that the intrusion had begun on May 17 and ended by May 20. The company stated that no operating systems were impaired and that no malware was involved in the incident. DentaQuest engaged an outside cybersecurity firm to assist with the response and later hired Kroll to conduct a forensic analysis and to help re‑secure its systems. The firm said it took immediate action to secure the network and to notify law enforcement.

The investigation found that the attackers accessed personal identification data such as names, addresses, Social Security numbers, member identification numbers, Medicaid and Medicare numbers, as well as dental or vision health information including provider names, diagnoses, treatment details, and billing information. Additionally, the leaked data that appeared on a dark web leak site included email addresses, phone numbers, dates of birth, and government‑issued IDs, according to HaveIBeenPwned. The extortion group ShinyHunters claimed responsibility for the breach, stating that it had exfiltrated 234 gigabytes of data and posted screenshots as proof. ShinyHunters asserted that the stolen data related to between 2.1 million and 2.6 million individuals, a figure that differed from the victim count later reported by DentaQuest and federal regulators.

Based on filings with the attorneys general of Texas, Massachusetts, and South Carolina, DentaQuest began sending written notification letters to at least 4.5 million individuals. The company later reported to the U.S. Department of Health and Human Services’ Office for Civil Rights that approximately 15 million patients were affected, a number that made the incident the largest healthcare data breach of 2026. DentaQuest also noted that the HIPAA Journal estimated that more than 23.4 million people could have been potentially impacted, although the firm confirmed that at least 15 million were actually affected. In response, DentaQuest offered affected individuals 24 months of free credit monitoring, fraud consultation, and identity theft restoration services. The firm said it had enhanced its security and monitoring controls and provided additional employee training to further safeguard its systems. DentaQuest notified law enforcement, continued its investigation with independent experts, and stated that it was complying with all applicable breach‑reporting requirements.

Sources

Sources available to members: 6 sources.

CSIDB