DentaQuest is notifying more than 23 million people of a data breach after hackers accessed its network in May 2026. The incident may have exposed customers’ personal information and dental health data.
DentaQuest, part of Sun Life U.S. Dental, is the largest Medicaid and Children’s Health Insurance Program dental benefits administrator in the country, operating in 50 U.S. states.
The company is notifying impacted individuals while investigating the breach and assessing its full impact.
DentaQuest said unauthorized actors accessed its network between May 17 and May 20, 2026, exposing some personal and dental health information. The company secured its systems, notified law enforcement, and launched an investigation into the incident.
“On May 20, 2026, DentaQuest discovered that unauthorized individuals accessed certain data on the DentaQuest computer network. This included some personal identification and dental health information. We took immediate action to secure the network and we reported the incident to law enforcement.” reads the notice of data breach. “We also began an investigation with leading, independent cybersecurity experts to learn what information was accessed. We then determined that the incident began on May 17, 2026, and ended by May 20, 2026.”
According to the notice, the exposed data may include names, addresses, Social Security numbers, member, Medicaid and Medicare IDs, along with dental or vision health information such as provider names, diagnoses, treatments, and billing details. The company hired Kroll to identify affected individuals and determine the full scope of the compromised data.
DentaQuest is offering affected individuals 24 months of free credit monitoring, fraud support, and identity theft recovery services following the data breach.
The HIPAA Journal reported that the data breach impacted over 15 Million individuals, however, the security incident may have impacted more than 23.4 million people.
The ShinyHunters extortion group claimed responsibility for the DentaQuest breach, saying it stole 234 GB of data and published it on its dark web leak site after ransom negotiations failed. Analysis by Have I Been Pwned found 2.6 million unique email addresses alongside names, addresses, phone numbers, birth dates, gender, and healthcare enrollment records that may include Medicaid IDs and insurance details.
Researchers also identified a folder containing what appears to be more than 1.7 million Social Security numbers, many believed to belong to children in Texas. The leaked archive contains hundreds of thousands of files dating back to at least 2009, and its full impact is still being assessed.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, DentaQuest)