Skip to content
Cyber Security Firms
ConfirmedHealthcare

DentaQuest Data Breach (May 2026)

The dental benefits administrator confirmed unauthorized access to its network over three days in May, ShinyHunters published hundreds of gigabytes of data, and DentaQuest has confirmed at least 15 million individuals are affected.

Disclosed Updated
Organization
DentaQuest
Country
United States, MA
Incident date
May 17, 2026
Disclosed
June 3, 2026
Records affected
15 million
Attack type
Undisclosed
Threat actor
ShinyHunters
Status
Confirmed
Data exposed
  • Names
  • Email addresses
  • Physical addresses
  • Phone numbers
  • Dates of birth
  • Genders
  • Health insurance information
  • Government issued IDs
Timeline
  1. Unauthorized access to parts of the DentaQuest network begins, per the company's investigation
  2. DentaQuest discovers the access and, per its notice, contains it
  3. Have I Been Pwned loads 2.6 million verified email addresses from the published data
  4. ShinyHunters claims responsibility; DentaQuest says it is actively managing a cybersecurity incident
  5. DentaQuest begins notifying individuals, confirming at least 15 million are affected

What Happened

DentaQuest, the Wellesley, Massachusetts dental benefits administrator that manages benefits for about 32 million Americans, found on May 20, 2026 that unauthorized individuals had accessed data on its network. Its investigation put the access window at May 17 to May 20, according to HIPAA Journal's reporting and the notification letter filed with the Massachusetts Attorney General. The company said it contained the attack and mitigated the threat.

The ShinyHunters extortion group claimed responsibility on June 5 and, when no payment followed, published hundreds of gigabytes of data it said came from the company. Have I Been Pwned analyzed the published files and loaded 2.6 million unique email addresses with names, addresses, phone numbers, dates of birth and genders. Much of the material was in healthcare enrollment files in the ASC X12 transaction format, some carrying Medicaid IDs, with more in member records.

The email count understates the breach. Enrollment files identify people who never registered an email address with the administrator. DentaQuest began notifying individuals on July 23 and confirmed that at least 15 million people are affected, which is the figure on the fact grid. HIPAA Journal also reports that an independent researcher's count of unique name, surname and date-of-birth combinations suggests the total could rise past 23 million as the review continues, and that one folder appears to contain more than 1.7 million unique Social Security numbers linked to an organization in Texas. Neither of those is a confirmed figure.

DentaQuest has not said how the attackers got in, so the attack type is recorded as undisclosed.

What was Exposed

Names, contact details, dates of birth, genders and health insurance information, with government-issued identifiers in part of the data. That is the set that supports medical identity theft and benefits fraud, not just spam: a name, a date of birth and an insurance ID are enough to bill a plan for care that never happened, and a Social Security number, where present, is enough to open credit.

Around two thirds of the email addresses were already in Have I Been Pwned from earlier breaches, per HIPAA Journal, which is typical for a large consumer set and does not reduce the risk from the new fields.

What to do if you are Affected

The full order of operations, including how a freeze differs from a fraud alert, is in what to do after a data breach. This is one of several large healthcare breaches on record here in 2026, and the same group's methods appear in the RingCentral report.

What is not Known Yet

The final individual count, whether the Social Security numbers are confirmed as part of the DentaQuest data, and how the attackers gained access. The HHS Office for Civil Rights portal entry will fix the count when the company's report is filed.

Sources

  1. Have I Been Pwned: DentaQuest
  2. HIPAA Journal, DentaQuest Starts Notifying 15 Million+ Individuals About May 2026 Cyber Incident
  3. DentaQuest notification letter filed with the Massachusetts Attorney General
On this page
Reviewed by

Daniel Reyes

  • CISSP
  • 12 years in security operations
  • Austin, TX

Daniel Reyes is a CISSP who spent twelve years in security operations, most recently leading a detection and response team for a mid-sized healthcare group in Texas. He reviews every resource and breach report on Cyber Security Firms for technical accuracy before it publishes.

Most of the people he has trained arrived having been told too much: a dozen acronyms, six vendors, and no clear idea which risk was theirs. His approach is to explain what an attack actually does before naming the tool that stops it, on the basis that most breaches start with something a reader could have recognised.

Read the full bio and how we research →