CSIDB logo
Incident

700Credit LLC

Incident posture

Attack window
May 2026
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-01 09:45

Linked entities

Victim
700Credit LLC
Threat actors
1 actor
Sources
6 sources

Timeline

Occurred
Pending
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A data breach at a major U.S. dental and vision benefits administrator, discovered after hackers accessed its network over a roughly three-day window in May, compromised the personal and health information of more than 15 million individuals, with some reports suggesting the potential impact could exceed 23 million people. Exposed data included names, addresses, Social Security numbers, member identification numbers, Medicaid and Medicare numbers, as well as dental and vision health details such as provider names, diagnoses, treatments, and billing information. The ShinyHunters extortion group claimed responsibility, asserting it stole and later leaked roughly 234 gigabytes of data after failed ransom negotiations, though the company stated no malware was involved and engaged independent cybersecurity experts to investigate. Affected individuals are being offered 24 months of complimentary credit monitoring and identity protection services.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

Between May 17 and May 20, 2026, unauthorized individuals gained access to a portion of DentaQuest's computer network, exposing the personal and dental health information of a very large swath of the company's beneficiaries. DentaQuest, one of the largest dental and vision benefits administrators in the United States and a unit of Sun Life Financial, discovered the intrusion on May 20, 2026, and subsequently determined that the unauthorized activity had begun three days earlier on May 17 and concluded by May 20. Upon detection, the company activated its incident response procedures, notified law enforcement, and engaged independent cybersecurity and forensic specialists, including third-party data analysis firm Kroll, to investigate the scope of the compromise and identify affected individuals. DentaQuest confirmed that none of its operating systems were impaired and that no malware was involved in the incident.

The information potentially accessed during the intrusion window varied by individual but included names, addresses, Social Security numbers, member identification numbers, Medicaid numbers, Medicare numbers, benefits provider names, diagnosis and treatment details, and billing information. According to analysis of data subsequently leaked online, the exposed records also contained email addresses, phone numbers, dates of birth, gender, healthcare enrollment records, and government-issued IDs, along with a folder appearing to hold more than 1.7 million Social Security numbers, many believed to belong to children in Texas. The leaked archive contained hundreds of thousands of files dating back to at least 2009, suggesting a broad historical exposure of records held by the benefits administrator.

In late May 2026, the extortion gang ShinyHunters posted a notice on its dark web leak site claiming responsibility for the DentaQuest theft, stating it had exfiltrated 234 gigabytes of data covering approximately 2.6 million people. The group asserted that it published the trove after DentaQuest "failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care." Screenshots were posted as evidence of the stolen data. DentaQuest did not confirm the identity of the threat actor and declined to rely on external claims, stating instead that its third-party data analysis expert Kroll continued to review and assess the data independently.

The reported victim count rose substantially as the forensic investigation progressed. In early July, DentaQuest posted a breach notice on its website and began sending written notifications to affected individuals on July 17. Initial filings with state Attorney General's Offices in Texas, Massachusetts, and South Carolina indicated that at least 4.5 million people were receiving letters. By late July 2026, the HIPAA Journal reported that more than 23.4 million individuals were potentially impacted by the breach, and DentaQuest reportedly confirmed to regulators that at least 15 million people were affected. The breach entry posted to the U.S. Department of Health and Human Services' HIPAA Breach Reporting Tool at the time reflected the 15 million figure, making it the largest health data breach posted to the portal so far in 2026 and the fourth largest of nearly 7,900 HIPAA breaches reported since federal regulators began keeping tally in September 2009. A separate DentaQuest breach listing on the HHS tool from the same month, affecting 3,086 people, was confirmed by a company spokeswoman to be unrelated to the May hacking incident.

The ShinyHunters leak drew attention from independent researchers and breach-tracking services. Have I Been Pwned reported in early June 2026 that it had identified 2.6 million unique email addresses within the leaked data set, alongside names, addresses, phone numbers, birth dates, gender, and healthcare enrollment records that may have included Medicaid IDs and insurance details. The wide discrepancy between the number of individuals claimed by the extortion gang and the figure ultimately reported by DentaQuest was attributed by industry observers to the difference between what attackers chose to claim and the broader set of data potentially accessible during the three-day intrusion window, with the confirmed affected count expected to continue evolving as Kroll's review advanced.

In response to the breach, DentaQuest took steps to further safeguard its systems, including enhancing its security and monitoring controls, strengthening defense and detection capabilities, and providing additional employee training. The company began mailing breach notification letters to affected individuals on July 17 and offered 24 months of complimentary identity theft protection and credit monitoring services to those impacted, along with fraud consultation and identity theft restoration services through its provider. Notifications were filed with the relevant state attorneys general and federal regulators as required.

DentaQuest serves roughly 32 to 35 million dental and vision beneficiaries nationwide across all 50 U.S. states and operates as part of Sun Life U.S. Dental, making it the largest Medicaid and Children's Health Insurance Program dental benefits administrator in the country. The full impact of the breach continued to be assessed in the weeks and months following the initial discovery, as Kroll's review of the compromised data proceeded and additional notifications were issued to victims identified through the analysis.

Sources

Sources available to members: 6 sources.

CSIDB