Last Update: 08/01/2026 at 12:00 PM EST

DentaQuest Breach Exposes Millions

Coverage from SecurityWeek, Cybernews, and others

Articles

28

Active Days

78

The Topic

DentaQuest Breach Exposes Millions topic image

DentaQuest, a Sun Life-owned dental benefits administrator, disclosed unauthorized access to part of its network after ShinyHunters claimed to have stolen and publicly released a large dataset. Breach analyses and regulatory reporting indicate that millions of accounts or Texas residents may be affected, with exposed information potentially including contact, government identification, insurance, and medical data. The incident has increased risks of identity theft, medical fraud, phishing, and legal action while the final scope remains unsettled.

First Article: 05/11/26

Latest Article: 07/27/26

Summary

  • DentaQuest confirmed unauthorized access to a limited portion of its network and said it took containment and mitigation measures.
  • ShinyHunters claimed to have stolen more than 234 gigabytes and publicly posted data after an alleged failed ransom negotiation.
  • Have I Been Pwned identified records associated with about 2.6 million accounts, including email addresses and other contact details.
  • A Texas Attorney General filing reported potential exposure of approximately 3.97 million Texas residents and listed Social Security, medical, insurance, and birth-date information.
  • At least six federal class-action lawsuits were reported in connection with the DentaQuest incident.
  • The exposed information could support phishing, social engineering, identity theft, medical identity theft, and insurance fraud.
  • The supplied reporting also contains separate Zara and Mount Royal University breaches, which are related to the broader breach landscape but not clearly part of the DentaQuest incident.

History

07/22/2026

The update mainly tightens and confirms the DentaQuest breach story with more explicit reporting on unauthorized access, regulatory filing, and litigation. It also clarifies that Zara and Mount Royal University are separate incidents in the broader breach landscape, not part of the core DentaQuest case.

07/22/2026

The story broadens from a DentaQuest breach into a wider multi-incident pattern of stolen-data extortion, adding Mount Royal University and Zara as comparable victims. The new version also tightens the DentaQuest narrative around the alleged ShinyHunters leak and the categories of exposed data, while preserving the same overall scale and legal fallout.

Featured

Timeline: 78 Days

Jul 21Jul 22Jul 23Jul 25Jul 26Jul 27

Additional Articles

⭐⭐⭐⭐⭐

Patient Protect07-27-2026
DentaQuest disclosed a May 2026 cyber intrusion affecting about 23 million people in Medicaid dental programs, triggering HIPAA breach notification to HHS OCR and affected individuals.
QPulse07-27-2026
DentaQuest disclosed a May 2026 breach discovered May 20, exposing health and identity data and prompting 24 months of credit monitoring for affected members.
Security Affairs / Pierluigi Paganini07-27-2026
DentaQuest notified more than 23 million people in 2026 after unauthorized access exposed Medicaid and children-related health and identity data.
Becker's Dental / Ariana Portalatin07-24-2026
Cure Dental reported a June 25 cyber incident in Belton, Texas, potentially exposing personal identifiers for up to 878 patients.

⭐⭐⭐

Federman & Sherwood / Caroline Chesher07-21-2026
Federman & Sherwood investigates a DentaQuest data breach reported to the Texas Attorney General on July 21, 2026, affecting about 3.97 million Texas residents.