DentaQuest Data Breach: Up to 23 Million People's Dental and Health Records Exposed

A three-day network intrusion at one of America's largest dental benefits administrators may have handed criminals the Social Security numbers, treatment records, and government IDs of tens of millions of people.

ThreatVectr Newsdesk· 3 min read
Full-frame edge-to-edge photoreal editorial shot of a darkened enterprise server room, with one rack illuminated by amber warning light, reflecting faintly on p
Share

Key points

  • Hackers accessed DentaQuest's network between 17 and 20 May, stealing records that may cover more than 23 million people.
  • Stolen data includes Social Security numbers, Medicaid and Medicare numbers, diagnosis details, and billing information.
  • The extortion group ShinyHunters claimed responsibility and leaked roughly 234 gigabytes of stolen files.
  • DentaQuest serves approximately 35 million people across all 50 US states as a Sun Life subsidiary.
  • Affected individuals will receive 24 months of free credit monitoring and identity theft restoration services.

DentaQuest, a dental and vision benefits administrator that serves around 35 million Americans, is sending breach notification letters to at least 4.5 million people after criminals broke into its computer network in May. The true figure may be far higher: the HIPAA Journal, which tracks healthcare data breaches, reports that more than 23.4 million individuals were potentially caught up in the incident, and DentaQuest reportedly confirmed at least 15 million were affected.

What was actually taken?

The exposed records are unusually sensitive, even by healthcare breach standards. Names, home addresses, Social Security numbers, Medicaid and Medicare identification numbers, diagnosis and treatment details, billing information, dates of birth, phone numbers, email addresses, and government-issued ID numbers all appear in the breach.

Data type exposed Why it matters
Social Security number Used to open fraudulent credit accounts or file fake tax returns
Medicare / Medicaid numbers Can be used to submit false medical billing claims
Diagnosis and treatment details Sensitive medical history that cannot be changed
Government-issued ID Enables identity document fraud
Billing information Potential financial fraud and account takeover

The breach notification site HaveIBeenPwned flagged the leak in early June after the extortion group ShinyHunters, which has previously claimed large-scale data thefts from other companies, published roughly 234 gigabytes of files it says came from DentaQuest.

Who is at risk, and what should they do?

If you receive dental or vision benefits through DentaQuest, treat your details as exposed until you hear otherwise. Written notification letters are going out now, first reported by SecurityWeek, following filings with attorney general offices in Texas, Massachusetts, and South Carolina.

DentaQuest is offering 24 months of free credit monitoring, fraud consultation, and identity theft restoration to affected people. Take it. Credit monitoring won't stop fraud, but it will flag suspicious new accounts quickly.

Beyond that, four practical steps are worth taking now. First, place a free credit freeze with each of the three major credit bureaus (Equifax, Experian, and TransUnion), which prevents anyone from opening new credit in your name. Second, watch your Medicare or Medicaid statements for treatments you never received, a sign that someone is billing your benefits fraudulently. Third, ignore any calls or emails claiming to help you with the breach unless you initiated contact. Fourth, if DentaQuest emails you about free monitoring, go directly to the company's official website to enrol rather than clicking links in the message.

DentaQuest has not publicly named the attack method or shared technical details. The three-day window of access, 17 to 20 May, suggests the intrusion was caught relatively quickly, but three days is more than enough time to copy hundreds of gigabytes of records.

© 2026 Threat Vectr