Contained High impact Data breach Checked 7h ago

DentaQuest breach hits 15 million people

Unauthorized people accessed DentaQuest's network from May 17 to May 20. At least 15 million members, providers and other people had personal, dental or vision data compromised, and an independent researcher cited by the HIPAA Journal estimated the true total could be more than 23.4 million. The access has ended, but DentaQuest is still reviewing the stolen data with help from Kroll and notifying people. The extortion group ShinyHunters claimed responsibility and reportedly leaked about 234 GB of stolen data online. A proposed class action filed on August 21 alleges DentaQuest failed to protect the data, but a court hasn't decided those claims.

Started
May 17, 2026
Latest activity
Sep 10, 2026
Attributed to
ShinyHuntersSuspected
Where
United States
Sectors
Healthcare
Scale
one U.S. dental and vision benefits administrator

Current status

A September 10 Health-ISAC warning said ShinyHunters was still targeting healthcare providers, but no renewed DentaQuest access was reported.

Contained: The attack has been stopped or blocked. Recovery and investigation are still running.

Who is behind it

ShinyHunters claimed responsibility and multiple outlets reported the claim, but DentaQuest has not publicly named an attacker and no government agency has confirmed attribution.

Impact

Personal and health data was compromised, including some names, addresses, Social Security numbers, government health program numbers, diagnoses, treatments and billing details. Have I Been Pwned earlier found about 2.6 million unique email addresses in the leaked data along with names, addresses, phone numbers, dates of birth and genders, and one folder reportedly held more than 1.7 million unique Social Security numbers. DentaQuest said its operating systems were not impaired.

What to do

People who receive a notice should enroll in DentaQuest's free 24-month identity monitoring, freeze their credit and watch financial statements for fraud.

Timeline

  1. Sep 10, 2026

    Health-ISAC warned healthcare providers that ShinyHunters was continuing a campaign using phone-based social engineering to target employees and steal data.

    Containedhealthcareitnews.com
  2. Sep 9, 2026

    AdaptHealth confirmed that 4.1 million people were exposed in a separate July cyberattack that reporting linked to ShinyHunters.

    Containedbleepingcomputer.com
  3. Sep 7, 2026

    Top Class Actions reported that Amanda Whitlow filed a proposed class action over the breach. Court records show the case was filed on August 21, and its claims haven't been decided.

    Containedtopclassactions.com
  4. Aug 29, 2026

    McKesson confirmed unauthorized access to third-party applications and data theft in a separate incident. ShinyHunters claimed responsibility.

    Containedinfosecurity-magazine.com
  5. Aug 22, 2026

    Health-ISAC reported that actors linked to ShinyHunters targeted ReliaQuest. Controls blocked access beyond an identity dashboard, and no data was stolen.

    Containedaha.org
  6. Aug 13, 2026

    DentaQuest reported more than 15 million affected individuals to federal regulators and said it had notified those affected and bolstered its security controls.

    Containedtechrepublic.com
  7. Aug 13, 2026

    TechRepublic reported DentaQuest hired Kroll to analyze the compromised data, that ShinyHunters claimed responsibility and reportedly leaked about 234 GB of stolen data, and that an independent researcher cited by the HIPAA Journal estimated the true number of affected people could exceed 23.4 million.

    Containedtechrepublic.com
  8. Aug 11, 2026

    Healthcare Dive reported the breach is the largest health data breach reported to federal regulators so far this year, and noted the H-ISAC issued a threat bulletin in July warning that ShinyHunters uses social engineering, such as phone calls, to trick people into compromising accounts.

    Containedhealthcaredive.com
  9. Aug 1, 2026

    DentaQuest said no operating systems were impaired, no malware was involved and its review of the data continued.

    Containeddatabreachtoday.com
  10. Jul 31, 2026

    A state breach filing reported that DentaQuest was notifying 15 million people.

    databreachtoday.com
  11. Jul 17, 2026

    DentaQuest began sending notices and offered affected people 24 months of identity monitoring.

    dentaquest.com
  12. Jul 16, 2026

    DentaQuest said its data review was ongoing and confirmed that personal, dental and vision information was involved.

    Containeddentaquest.com
  13. Jun 5, 2026

    DentaQuest confirmed the incident after data tied to 2.6 million accounts surfaced in a public breach listing.

    Activetechrepublic.com
  14. May 20, 2026

    DentaQuest discovered unauthorized access to parts of its network, which it later determined began on May 17.

    Emergingtechrepublic.com
  15. May 20, 2026

    DentaQuest discovered the breach, secured its network and determined that the unauthorized access had ended by that day.

    Containeddentaquest.com
  16. May 17, 2026

    DentaQuest later determined that unauthorized access to its network began on May 17.

    Activedentaquest.com

Sources

Related reports