DentaQuest Breach Exposes Millions
Coverage from SecurityWeek, Cybernews, and others
Articles
28
Active Days
78
The Topic

DentaQuest, a Sun Life-owned dental benefits administrator, disclosed unauthorized access to part of its network after ShinyHunters claimed to have stolen and publicly released a large dataset. Breach analyses and regulatory reporting indicate that millions of accounts or Texas residents may be affected, with exposed information potentially including contact, government identification, insurance, and medical data. The incident has increased risks of identity theft, medical fraud, phishing, and legal action while the final scope remains unsettled.
First Article: 05/11/26
Latest Article: 07/27/26
Summary
- DentaQuest confirmed unauthorized access to a limited portion of its network and said it took containment and mitigation measures.
- ShinyHunters claimed to have stolen more than 234 gigabytes and publicly posted data after an alleged failed ransom negotiation.
- Have I Been Pwned identified records associated with about 2.6 million accounts, including email addresses and other contact details.
- A Texas Attorney General filing reported potential exposure of approximately 3.97 million Texas residents and listed Social Security, medical, insurance, and birth-date information.
- At least six federal class-action lawsuits were reported in connection with the DentaQuest incident.
- The exposed information could support phishing, social engineering, identity theft, medical identity theft, and insurance fraud.
- The supplied reporting also contains separate Zara and Mount Royal University breaches, which are related to the broader breach landscape but not clearly part of the DentaQuest incident.
History
The update mainly tightens and confirms the DentaQuest breach story with more explicit reporting on unauthorized access, regulatory filing, and litigation. It also clarifies that Zara and Mount Royal University are separate incidents in the broader breach landscape, not part of the core DentaQuest case.
The story broadens from a DentaQuest breach into a wider multi-incident pattern of stolen-data extortion, adding Mount Royal University and Zara as comparable victims. The new version also tightens the DentaQuest narrative around the alleged ShinyHunters leak and the categories of exposed data, while preserving the same overall scale and legal fallout.
