DentaQuest Breach Exposes Up to 23.4M Records After Ransom Talks Fail
The ShinyHunters group leaked 234GB of sensitive health data including children's Social Security numbers after negotiations with the dental benefits administrator collapsed.
The Breach
DentaQuest, a Sun Life subsidiary and major U.S. dental benefits administrator, suffered a cybersecurity incident in May 2026 that compromised sensitive personal and health information belonging to millions of Americans. Unauthorized access occurred between May 17 and May 20, 2026, and was discovered on May 20.
The ShinyHunters threat group claimed responsibility, stealing approximately 234GB of data after ransom negotiations failed. The group listed DentaQuest on its leak site in late May 2026, with sources citing dates between May 23 and May 30.
What Was Stolen
Compromised data includes names, dates of birth, Social Security numbers, government IDs, Medicaid and Medicare numbers, and dental and vision health information including diagnoses, treatments, and billing records. A researcher analyzing the stolen dataset found approximately 1.7 million unique Social Security numbers, most appearing to belong to children. Some files date back to at least 2009.
DentaQuest began notifying approximately 15 million affected individuals on July 17, 2026. Independent analysis suggests the actual impact could be higher: a researcher estimated that unique name and date-of-birth combinations in the leaked data indicate up to 23.4 million people may have been affected.
Response and Remediation
DentaQuest is providing 24 months of complimentary credit monitoring and identity theft protection services to affected individuals.
Why It Matters
The inclusion of children's Social Security numbers raises particular concern, as child identity theft can go undetected for years and create long-term financial harm. The breach also underscores continued targeting of healthcare infrastructure by sophisticated extortion groups. ShinyHunters has established itself as a persistent threat actor in the health sector, exploiting the sensitive nature of medical records and pressure on providers to protect patient data.
Privacy advocates have characterized the incident as a major data breach in terms of both the number of people affected and the types of personal information involved. The core sentiment regarding failed negotiations has been confirmed, though exact wording from the threat group varies across sources.