DentaQuest disclosed a breach after unauthorized actors accessed its network between May 17 and May 20, exposing personal and dental health information tied to more than 23 million individuals. The company said the compromised data may include names, addresses, Social Security numbers, member IDs, Medicaid and Medicare numbers, provider names, diagnoses, treatment details, and billing information; some reporting said vision-related health data may also be involved. Public filings indicate at least 4.5 million notification letters are being sent, while DentaQuest has confirmed that at least 15 million people were affected and broader estimates place the total potential impact above 23.4 million.
The ShinyHunters extortion group claimed responsibility, alleging it stole about 234 GB of data and later posted the material on its dark web leak site after ransom talks failed. Reporting on the leaked files found roughly 2.6 million unique email addresses and a folder that appeared to contain more than 1.7 million Social Security numbers, many believed to belong to children in Texas. DentaQuest said it secured its systems, notified law enforcement, hired outside cybersecurity experts and Kroll to assess the incident, and is offering affected individuals 24 months of credit monitoring, fraud consultation, and identity theft restoration services.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
DentaQuest disclosed that the breach potentially affected more than 23 million people, with public filings indicating at least 4.5 million notification letters were being sent and the company confirming at least 15 million affected. The company also offered 24 months of free credit monitoring, fraud consultation, and identity theft restoration services to affected individuals.
The ShinyHunters extortion group claimed responsibility for the DentaQuest intrusion and said it stole about 234 GB of data. Reporting cited in the references says the group published the data on its dark web leak site after ransom negotiations failed.
DentaQuest said it discovered the incident on May 20, 2026. After discovery, the company secured its systems, notified law enforcement, engaged outside cybersecurity experts, and retained Kroll to identify affected individuals and assess the breach's scope.
DentaQuest said unauthorized actors accessed its computer network between May 17 and May 20, 2026, exposing personal and dental health information. The potentially compromised data included names, addresses, Social Security numbers, member and government insurance IDs, provider names, diagnoses, treatment details, and billing information.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.