DentaQuest Data Breach Potentially Impacts Over 23 Million People
Dental and vision benefits administrator DentaQuest is notifying millions of people that their personal and dental health information might have been stolen in a data breach.

Dental and vision benefits administrator DentaQuest is notifying millions of individuals that their personal and dental health information may have been compromised in a significant data breach.
The incident was first detected on May 20, 2026, and an internal investigation by DentaQuest confirmed that unauthorized actors had access to the organization's network between May 17 and May 20.
During this period, the attackers exfiltrated a wide range of sensitive data. This included names, addresses, Social Security numbers, member identification numbers, Medicaid and Medicare numbers, benefits provider names, diagnosis and treatment details, and billing information. The breach potentially affects over 23.4 million individuals, with DentaQuest reportedly confirming at least 15 million were impacted.
In response to the incident, DentaQuest is offering affected individuals 24 months of complimentary credit monitoring, fraud consultation, and identity theft restoration services. Written notification letters are being sent to at least 4.5 million people, as indicated by filings with Attorney General's Offices in Texas, Massachusetts, and South Carolina.
While DentaQuest has not officially identified the threat actor, the notorious extortion group ShinyHunters has claimed responsibility for the attack. The group allegedly leaked approximately 234 GB of data stolen from the dental benefits administrator. This leaked information, as reported by HaveIBeenPwned in early June, also contained email addresses, phone numbers, dates of birth, and government-issued identification documents.
DentaQuest, a subsidiary of Sun Life, serves as one of the largest administrators of dental benefits in the United States, providing services to 35 million people across all 50 states.
The scale of this breach places it among the larger healthcare-related data compromises in recent times, highlighting the persistent threat to sensitive personal and health information held by large benefit administrators. The involvement of a known ransomware and data extortion group like ShinyHunters underscores the financial motivations behind such attacks.
This incident serves as a stark reminder of the critical need for robust cybersecurity measures within the healthcare and benefits administration sectors, which handle vast amounts of highly sensitive personal data. Organizations must continuously assess and strengthen their defenses against sophisticated threat actors.