ConfirmedData breach

DentaQuest: a data breach

In May 2026, the dental benefits administrator DentaQuest was the target of a ShinyHunters "pay or leak" extortion campaign that resulted in the group publicly publishing hundreds of gigabytes of data allegedly obtained from the company. The data included 2.6M unique email addresses along with names, addresses and phone numbers. Much of the data appeared in healthcare enrollment files ( ASC X12 transaction sets ) with some containing Medicaid IDs, while additional data appeared in member records and related files. DentaQuest acknowledged "a cybersecurity incident involving unauthorized access to a limited portion of our network" , and advised they had contained the attack and mitigated the threat.

The record

Organisation
DentaQuest
Identity
DentaQuestidentified by its domain in a verified breach record
Records affected
2,553,599 records
Data exposed
Dates of birth, Email addresses, Genders, Government issued IDs, Health insurance information, Names, Phone numbers, Physical addresses
Sector
Not recorded
Occurred
2026-05-23
Disclosed
2026-06-03
First recorded here
2026-09-09

Sources (1)

One source so far.

  1. Have I Been PwnedFirst reported

    2026-06-03