DentaQuest Breach Exposes Health DataDentaQuest Breach Exposes Health DataCoverage from Medical Daily, Data Breach Rights, and others
00/00/0000
DailyWeekly
DentaQuest, a Sun Life subsidiary and dental benefits administrator, suffered unauthorized network access in May 2026 that exposed personal, insurance, and potentially protected health information.
ShinyHunters claimed responsibility, alleged theft of roughly 234 gigabytes of data, and reportedly published the material after failed extortion negotiations. Reported impact estimates vary substantially, but multiple accounts place the affected population in the millions and identify risks of identity theft, phishing, medical fraud, and targeted scams.
Key Issues
01
Affected population remains unresolved
Current reporting places the affected population at least in the 15-million range, while other accounts cite more than 23 million or 2.6 million records and DentaQuest's review is described as incomplete. The incident is consistently characterized as affecting millions, but its final scope remains unsettled.
Stable
Drawn from 4 articles
02
Identity-rich health data is exposed
Reports describe exposure of permanent identifiers, government-benefit information, contact data, and dental or other health-related records. The combination creates durable risks of identity theft, medical identity theft, benefits fraud, phishing, and targeted social engineering.
Stable
Drawn from 4 articles
03
Alleged theft progressed to public disclosure
Multiple publications attribute the incident to ShinyHunters and report that roughly 234 GB of DentaQuest data was allegedly stolen and published after extortion negotiations failed. The reported publication means the exposure may persist through copying and reuse beyond the original intrusion.
Stable
Drawn from 4 articles
04
Remediation is paired with notification and legal scrutiny
DentaQuest is reported to be providing credit-monitoring and identity-restoration support while notification and scope-review processes continue. Reports also point to delayed disclosure concerns, HIPAA notification obligations, and at least six class-action suits, keeping response timing and accountability central to the incident.
Stable
Drawn from 4 articles
Contested Issue
1 open dispute
How many individuals were affected by the DentaQuest breach?
The corpus contains materially different estimates of the affected population. DentaQuest-linked reporting identifies at least 15 million affected individuals, while independent analysis and other reports estimate more than 23 million. Earlier reporting cited approximately 2.6 million accounts, which may represent a narrower account or dataset count rather than the full affected population.
At least 15 million affected
5 articles · across 5 publications
DentaQuest and breach-reporting sources identify at least 15 million affected individuals.
More than 23 million affected
3 articles · across 3 publications
Independent analysis and related reporting estimate that the breach may have affected more than 23 million individuals, exceeding the company-linked count.
Looking Back
110 Day Timeline
Articles published over time. Hover any bar for the period and its article count.
May 11
May 29
Jun 16
Jul 4
Jul 22
Aug 9
Aug 27
The Story So Far
No material change
The new reporting reiterates that DentaQuest’s breach may affect members, dependents, and minors while leaving the exposed data and overall scope unresolved; it does not establish a material change.
Previously
DentaQuest, a Sun Life subsidiary and dental benefits administrator, suffered unauthorized network access in May 2026 that exposed personal, insurance, and potentially protected health information. ShinyHunters claimed responsibility, alleged theft of roughly 234 gigabytes of data, and reportedly published the material after failed extortion negotiations. Reported impact estimates vary substantially, but multiple accounts place the affected population in the millions and identify risks of identity theft, phishing, medical fraud, and targeted scams.
History
08/24/2026
The main change is greater uncertainty over the breach’s scale: the current version adds a low estimate of 2.6 million accounts and reframes the impact as disputed rather than anchored at 15 million. It also notes reported regulatory notifications, but the underlying breach, threat-actor claims, and risks remain unchanged.
08/05/2026
The main change is a modest reframing and clarification of the DentaQuest breach, with the new version tightening the data description and emphasizing the scale remains unsettled. It also adds a separate note about unrelated Zara and Mount Royal University incidents, suggesting source contamination rather than a change in the DentaQuest event itself.
DentaQuest disclosed unauthorized access to its network affecting at least 15 million people nationwide after an intrusion occurred from May 17 to May 20.
8/14/2026 • Data Breaches & Exposure Events • General
DentaQuest notified Washington regulators and affected individuals in July 2026 after unauthorized system access potentially exposed dental insurance members' personal and health information.
8/28/2026 • Data Breaches & Exposure Events • General
DentaQuest notified 15 million people in the United States after a May intrusion potentially exposed health and identity information through compromised company systems.
7/31/2026 • Data Breaches & Exposure Events • General
DentaQuest disclosed a May 2026 breach discovered May 20, exposing health and identity data and prompting 24 months of credit monitoring for affected members.
7/27/2026 • Data Breaches & Exposure Events • General
DentaQuest disclosed a May 2026 cyber intrusion affecting about 23 million people in Medicaid dental programs, triggering HIPAA breach notification to HHS OCR and affected individuals.
7/27/2026 • Data Breaches & Exposure Events • General
Yahoo disclosed in 2016-2017 that 2013-2014 cyberattacks exposed up to three billion accounts, with DOJ indictments and SEC penalties for delayed disclosure.
7/18/2026 • Data Breaches & Exposure Events • General
CMD Organization ransomware stole and deleted files from Mount Royal University shared drives in Calgary, after passport-scan proof and a 30 Bitcoin demand.
7/9/2026 • Cybersecurity (Privacy-Relevant) • General
DentaQuest reported a May 2026 unauthorized-access incident that may have exposed health insurance and Medicaid identifiers affecting about 2.6 million people in the USA.
6/10/2026 • Data Breaches & Exposure Events • General
ShinyHunters breached DentaQuest on a ransom timeline and publicly posted data for 2.6 million Medicaid and Medicare Advantage accounts after June 2 confirmation.
6/9/2026 • Data Breaches & Exposure Events • General
DentaQuest disclosed a cybersecurity incident while ShinyHunters claimed extortion and publication of leaked data affecting about 2.6 million accounts.
6/9/2026 • Data Breaches & Exposure Events • General
ShinyHunters published 234 GB of stolen DentaQuest files, and DentaQuest confirmed June 2 unauthorized access affecting 2.6 million Medicaid and Medicare Advantage beneficiaries.
6/8/2026 • Data Breaches & Exposure Events • General
ShinyHunters claimed a May 2026 breach of DentaQuest cloud systems, exposing PII and PHI for about 2.6 million people and prompting notification compliance concerns.
6/7/2026 • Data Breaches & Exposure Events • General
DentaQuest disclosed an early-June 2026 unauthorized access incident after ShinyHunters leaked 234GB of stolen data exposing about 2.6 million accounts.
6/5/2026 • Data Breaches & Exposure Events • General
BlackFog reported ransomware-group claims against ViaQuest in Ohio during early 2026, potentially exposing health and disability data and implicating Ohio and HIPAA breach-notification timelines.
6/3/2026 • Data Breaches & Exposure Events • General
Cure Dental in Belton, Texas disclosed in 2026 that a 2025 ransomware attack potentially exposed 878 patients' identity data, including Social Security numbers.
7/24/2026 • Data Breaches & Exposure Events • General
Zara and Inditex reported an Anodot-linked breach affecting about 200,000 customers, with leaked data analysis identifying 197,400 unique email addresses.
5/11/2026 • Data Breaches & Exposure Events • General
DentaQuest began notifying individuals in the United States on July 17, 2026, after a May cyberattack exposed sensitive personal and health information.
8/13/2026 • Data Breaches & Exposure Events • General
DentaQuest disclosed in 2026 that unauthorized actors accessed its U.S. systems in May, potentially exposing personal and medical information belonging to more than 15 million individuals.
8/12/2026 • Data Breaches & Exposure Events • General
DentaQuest reported that hackers accessed its Massachusetts-based network from May 17 to May 20, potentially exposing health and personal data of more than 15 million individuals.
8/11/2026 • Data Breaches & Exposure Events • General
Health Information Sharing and Analysis Center / Julia Annaloro60
DentaQuest notified 15 million people in the United States in 2026 after a May hack potentially exposed sensitive records in a ShinyHunters data theft.
8/4/2026 • Data Breaches & Exposure Events • General
Federman & Sherwood is investigating a Wilson Dental data breach disclosed through a Texas Attorney General filing after approximately 3,476 Texas residents were affected.
7/29/2026 • Data Breaches & Exposure Events • General
Azle Smiles notified the Texas Attorney General on July 29, 2026, about a breach potentially affecting 9,444 Texas residents and exposing medical and identity information in Azle, Texas.
7/29/2026 • Data Breaches & Exposure Events • General
Allwyn Dental notified Texas authorities of a data breach affecting approximately 4,013 residents in Rockport and involving personal, medical, insurance, and identification information.
7/29/2026 • Data Breaches & Exposure Events • General
Federman & Sherwood investigates a DentaQuest data breach reported to the Texas Attorney General on July 21, 2026, affecting about 3.97 million Texas residents.
7/21/2026 • Data Breaches & Exposure Events • General
DentaQuest reported a breach affecting up to 2.6 million people, after ShinyHunters posted claimed customer data in May and multiple class actions were filed in Massachusetts federal court.
6/8/2026 • Data Breaches & Exposure Events • General
Soniva Dental Care disclosed in May 2026 that a ransomware attack compromised patient identity and health information across its Texas dental network, including 9,444 Azle Smiles patients in Azle.
7/29/2026 • Data Breaches & Exposure Events • General
DentaQuest, CEVA Logistics, and other organizations reported data breaches during the week, while attackers exploited Cisco, Apple, VMware, and N-able flaws globally.
8/17/2026 • Data Breaches & Exposure Events • General
DentaQuest, Origin Energy, water utilities, Analog Devices, and Omnicell reported or faced cyberattacks in 2026 across the United States and Australia, potentially exposing millions of records.
8/5/2026 • Data Breaches & Exposure Events • General
Former customer Lariesha Lincoln filed a proposed class action on July 6 in Florida alleging Futuredontics failed to protect patient data after Qili ransomware claimed theft from 1-800-Dentist.
7/9/2026 • Data Breaches & Exposure Events • General
DentaQuest reported a cybersecurity breach involving unauthorized access on a limited network portion, with about 2.6 million accounts exposed and notifications planned.
7/4/2026 • Data Breaches & Exposure Events • General
Qilin ransomware posted 1-800-dentist to a data leak site on June 28, 2026, alleging exposure risks for millions of consumer callers and dental practice data.
6/29/2026 • Data Breaches & Exposure Events • General
ShinyHunters claimed responsibility for a May 2026 DentaQuest breach affecting about 2.6 million records, with DentaQuest confirming unauthorized access on June 2, 2026.
6/5/2026 • Data Breaches & Exposure Events • General
Melissa King filed a June 4 class action in Massachusetts alleging DentaQuest cybersecurity failures after a ShinyHunters ransomware-linked attack exposed Social Security and health data.
6/29/2026 • Data Breaches & Exposure Events • General
On June 2, DentaQuest disclosed an unauthorized access incident after ShinyHunters posted a claimed 234 GB leak affecting 2.6 million account records in the United States.
6/4/2026 • Cybersecurity (Privacy-Relevant) • General
Bridle Trails Family Dentistry disclosed in 2026 an unauthorized employee email account access in 2024 affecting about 20,976 individuals in Kirkland, Washington.
6/3/2026 • Data Breaches & Exposure Events • General