DentaQuest Data Breach: Over 23 Million Individuals Affected – Veri Sızıntısı

DentaQuest Data Breach: Over 23 Million Individuals Affected

DentaQuest, the largest Medicaid dental benefits administrator in the U.S., has confirmed a massive cyberattack that exposed the personal and health data of over 23.4 million individuals. The breach, claimed by the ShinyHunters group, includes critical data such as Social Security numbers.

A broken lock icon superimposed over the DentaQuest logo, symbolizing a data breach.

What Happened

U.S.-based dental insurance giant DentaQuest has publicly disclosed a massive data breach affecting more than 23 million people. The company, part of Sun Life U.S. Dental and the nation's largest administrator of Medicaid and Children’s Health Insurance Program (CHIP) dental benefits, reported that it detected unauthorized access to its network in May 2026. According to the company's statement, cyberattackers remained in its systems for three days, gaining access to sensitive data belonging to millions of customers.

The notorious ShinyHunters ransomware group has claimed responsibility for the attack. The group alleged that after ransom negotiations with the company failed, it published the 234 GB of stolen data on its dark web leak site. This development indicates that the data is no longer just in the hands of the attackers but is now accessible to other criminals.

What Data Was Compromised

The official notification from DentaQuest and initial analyses of the leaked data by cybersecurity researchers reveal the staggering scale of the breach and the critical nature of the compromised information. The leak contains much more than basic customer identification. The stolen data includes:

  • Personal Identifiable Information (PII): Full names, home addresses, dates of birth, and gender information.
  • Contact Information: Phone numbers and email addresses. An analysis by the Have I Been Pwned platform identified 2.6 million unique email addresses in the leak.
  • Government-Issued ID Numbers: Social Security numbers (SSNs), Member IDs, and Medicaid and Medicare IDs for millions of individuals. Researchers discovered a folder within the leaked archive containing what appears to be more than 1.7 million SSNs, many believed to belong to children in Texas.
  • Protected Health Information (PHI): Extremely sensitive dental and vision health information. This includes private data such as provider names, diagnoses, treatments, and billing details.
  • Insurance Information: Health insurance enrollment records and policy details.

The dataset reportedly contains records dating back to at least 2009 and consists of hundreds of thousands of files. This indicates that the impact of the attack spans a long history, and a full assessment of the damage is still underway.

How the Attack Occurred

According to DentaQuest's statement, the attackers managed to breach the company network between May 17, 2026, and May 20, 2026. The company stated it discovered the unauthorized access on May 20 and immediately took action to secure its network. However, technical details about the specific vulnerability or method used for the attack have not yet been shared. Following the incident, the company launched an investigation with leading independent cybersecurity experts, such as Kroll, to determine the full scope of the attack and what information was precisely exfiltrated.

Who Is Affected

The breach directly targets DentaQuest customers. The company operates in all 50 U.S. states and is the country's largest provider of Medicaid and CHIP dental benefits. Therefore, those affected include millions of low-income adults, children, and individuals with private insurance plans. While The HIPAA Journal initially reported the number as 15 million, it is now stated that the final impact could cover more than 23.4 million people. The leak of children's Social Security numbers is particularly concerning, as it exposes them to the risk of identity theft that could last for many years into the future.

What You Can Do

If you are or have been a DentaQuest customer, you must take immediate steps to protect yourself against the possibility that your data was compromised. Here are the actions you can take:

  • Take Advantage of the Company's Offerings: DentaQuest is offering 24 months of free credit monitoring, fraud support, and identity theft recovery services to affected individuals. Wait for the official notification from the company and enroll in these services.
  • Freeze Your Credit Reports: The exposure of your Social Security Number can lead to serious fraud, such as new credit card applications or loans being taken out in your name. Contacting the three major credit bureaus—Equifax, Experian, and TransUnion—to freeze your credit is the most effective way to prevent such attempts.
  • Monitor Your Accounts: Regularly review your bank, credit card, and insurance statements. Report any transaction you don't recognize or find suspicious to the respective institution immediately.
  • Be Wary of Phishing Attacks: Attackers can use your stolen personal and health information to create convincing phishing emails or messages targeted at you. Be vigilant against suspicious communications claiming to be from DentaQuest or other institutions, do not click on links, and never share your personal information.

What the Company Is Saying

In its data breach notification, DentaQuest emphasized its immediate response to the incident. The company's statement read: "On May 20, 2026, DentaQuest discovered that unauthorized individuals accessed certain data on the DentaQuest computer network. This included some personal identification and dental health information. We took immediate action to secure the network and we reported the incident to law enforcement. We also began an investigation with leading, independent cybersecurity experts to learn what information was accessed. We then determined that the incident began on May 17, 2026, and ended by May 20, 2026." The company added that it is working with Kroll to identify affected individuals and understand the full scope of the breach.

Source

https://securityaffairs.com/196100/data-breach/dentaquest-disclosed-a-data-breach-that-impacted-23-million-individuals.html

This content was generated with AI assistance through our Argus Flow application. We are continuously working to improve Argus Flow; if you encounter any issues such as translation errors, incorrect sources, or unverified information, you can report them using the button below. We appreciate your feedback.

Weekly Newsletter

Curated data breach news delivered to your inbox every week.