DentaQuest health data breach leaks 23M records
Attackers broke into DentaQuest's network in May 2026 and stole personal and dental health records on millions of people. The dental benefits administrator says Social Security numbers, Medicaid and Medicare numbers, and treatment details were exposed.
- Report priority
- Medium
- Victim
- DentaQuest
What is known
- Attackers had access to DentaQuest's computer network for several days in May 2026 and pulled out member data before the company detected the intrusion.
- The extortion group ShinyHunters later claimed the attack and posted roughly 234 GB of the stolen files online.
What to do
Check your mail and email for a breach notification letter from DentaQuest, or watch for your state Attorney General's data breach filings. You can also check haveibeenpwned.com for your email address since the leaked data was indexed there.
DentaQuest is offering 24 months of free credit monitoring, fraud consultation, and identity theft restoration to affected members, so enroll through the instructions in your notice.
Reported details
Attackers get into DentaQuest's network on May 17 and stay inside until the company detects them on May 20. During that window they copy member records including names, Social Security numbers, Medicaid and Medicare numbers, and dental treatment and billing details. ShinyHunters then claims the breach and leaks about 234 GB of the stolen data, which HaveIBeenPwned says also includes email addresses, phone numbers, and government ID numbers.
DentaQuest, a Sun Life subsidiary and one of the largest US dental benefits administrators, detected unauthorized network access on May 20, 2026, tracing intruder activity back to May 17. Exfiltrated data included names, addresses, Social Security numbers, member IDs, Medicaid/Medicare numbers, provider names, diagnosis and treatment details, and billing information. ShinyHunters claimed the attack and leaked about 234 GB of data; HaveIBeenPwned reported the leak also contained emails, phone numbers, dates of birth, and government IDs. Regulatory filings put written notifications at 4.5 million, with HIPAA Journal citing 23.4 million potentially affected and DentaQuest confirming at least 15 million.