Last Update: 09/22/2026 at 11:34 PM EST

DentaQuest Breach Exposes Health Data

Coverage from Medical Daily, Data Breach Rights, and others

DentaQuest Breach Exposes Health Data topic image

DentaQuest, a Sun Life subsidiary and dental benefits administrator, suffered unauthorized network access in May 2026 that exposed personal, insurance, and potentially protected health information.

ShinyHunters claimed responsibility, alleged theft of roughly 234 gigabytes of data, and reportedly published the material after failed extortion negotiations. Reported impact estimates vary substantially, but multiple accounts place the affected population in the millions and identify risks of identity theft, phishing, medical fraud, and targeted scams.

History
08/24/20266 new articles

The main change is greater uncertainty over the breach’s scale: the current version adds a low estimate of 2.6 million accounts and reframes the impact as disputed rather than anchored at 15 million. It also notes reported regulatory notifications, but the underlying breach, threat-actor claims, and risks remain unchanged.

08/05/20261 new articles

The main change is a modest reframing and clarification of the DentaQuest breach, with the new version tightening the data description and emphasizing the scale remains unsettled. It also adds a separate note about unrelated Zara and Mount Royal University incidents, suggesting source contamination rather than a change in the DentaQuest event itself.

08/04/20260 new articles

The main update is that DentaQuest’s response and impact estimates are now more concrete: the company has said about 15 million people were affected and has moved into notification, investigation, and monitoring steps. The current version also sharpens the exposed-data description and confirms the alleged extortion-and-publication sequence attributed to ShinyHunters.

  • DentaQuest later reported approximately 15 million affected people.
  • DentaQuest engaged Kroll and notified law enforcement.
  • DentaQuest offered 24 months of credit and identity-theft monitoring.
  • ShinyHunters allegedly published stolen data after DentaQuest declined payment.
  • Exposed records included Social Security numbers and Medicaid and Medicare numbers.
08/02/202613 new articles

The story has broadened from a single DentaQuest breach into a larger healthcare-and-dental breach pattern, with the DentaQuest incident now looking bigger and more uncertain in scope. New reporting also adds stronger evidence of ongoing remediation and regulatory response, plus smaller Texas dental-practice breaches that reinforce the sector-wide pressure.

  • DentaQuest intrusion timing is now placed between May 17 and May 20, 2026.
  • Notification estimates rose to 15 million, with external estimates above 23 million.
  • Exposed data now includes Medicaid, Medicare, dental, vision, billing, and treatment records.
  • Multiple Texas dental practices reported separate smaller breaches.
  • Regulatory notices, external investigations, and credit monitoring are underway.
07/22/20260 new articles

The update mainly tightens and confirms the DentaQuest breach story with more explicit reporting on unauthorized access, regulatory filing, and litigation. It also clarifies that Zara and Mount Royal University are separate incidents in the broader breach landscape, not part of the core DentaQuest case.

07/22/20260 new articles

The story broadens from a DentaQuest breach into a wider multi-incident pattern of stolen-data extortion, adding Mount Royal University and Zara as comparable victims. The new version also tightens the DentaQuest narrative around the alleged ShinyHunters leak and the categories of exposed data, while preserving the same overall scale and legal fallout.

  • Mount Royal University suffered ransomware-driven file theft and deletion.
  • Zara-related exposure included order and support data, not sensitive customer fields.
  • The story now includes Canada and Calgary, Alberta.
  • The broader pattern now spans education and retail, not just dental benefits.
07/22/2026Topic Formed

DentaQuest reported unauthorized access to part of its network after ShinyHunters claimed to have stolen and publicly released more than 234 GB of data. Breach-monitoring analysis linked the leak to about 2.6 million accounts, while a later Texas filing cited potential exposure affecting approximately 3.97 million residents and involving personal and healthcare information. The incident has prompted warnings about identity and medical fraud, investigations by law firms, and multiple federal lawsuits, while related reporting highlights the continuing impact of extortion-based data theft against organizations holding sensitive records.