
On May 20, 2026, DentaQuest detected unauthorized access to parts of its network and launched a forensic investigation, which determined that attackers had access between May 17 and May 20, 2026. On June 5, 2026, DentaQuest publicly disclosed the cybersecurity incident, while the ShinyHunters hacking group claimed responsibility, stating it had stolen 234 GB of data after unsuccessful ransom negotiations and had begun leaking the information online.
On July 17, 2026, DentaQuest began mailing notification letters to affected individuals and offered 24 months of complimentary credit monitoring and identity theft protection. DentaQuest has confirmed that at least 15 million individuals were affected, although the total could ultimately exceed 23.4 million as the ongoing data review continues.
The compromised information includes names, addresses, Social Security numbers, member identification numbers, Medicaid numbers, Medicare numbers, and dental or vision health information, including provider names, diagnoses, treatment details, and billing information. Earlier analysis of the leaked files also found email addresses, phone numbers, dates of birth, gender, health insurance enrollment information, government-issued identification numbers, and more than 1.7 million unique Social Security numbers, with some records reportedly dating back to at least 2009.
Read more about it here.