LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › DentaQuest Data Breach (2026)

HIGH severityConfirmedHow we verify

DentaQuest Data Breach (2026): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·May 23, 2026

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

DentaQuest Data Breach (2026)

Reported May 23, 2026. Approximately 2.6M people affected.

HIGH
Severity
2.6M
People affected
8
Data types exposed
May 23, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

DentaQuest disclosed a data breach on May 23, 2026, affecting 2.6 million individuals whose dates of birth, email addresses, genders, government-issued IDs, and health insurance information were exposed. Anyone who received services from DentaQuest should check their status on the company’s site and take steps to protect their accounts.

Severity & verification
HIGH severityConfirmed
Contact / identity PII exposed.
Corroborated by an official disclosure or a verified breach feed.
Check your exposure
2.6M accounts were exposed here. We can’t confirm any single incident against the sources we search — but we can show you every leak and listing tied to your email. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

In May 2026, DentaQuest, a dental benefits administrator, was the target of an extortion campaign attributed to the group ShinyHunters. The group publicly released hundreds of gigabytes of data that it claimed originated from the company, affecting 2.6 million individuals. The incident was reported on May 23, 2026, and included names, addresses, phone numbers, and 2.6 million unique email addresses, along with other personal and health-related details found in enrollment and member files.

The breach matters because DentaQuest processes sensitive information for dental coverage and related services. When such records are exposed, affected individuals face potential misuse of their data in contexts that involve both identity and health details. Public reporting indicates the company acknowledged unauthorized access, though further internal details remain limited in available disclosures.

Inside the incident

The facts show that ShinyHunters conducted a "pay or leak" extortion effort against DentaQuest. After the campaign, the group published a substantial volume of data on its leak site. The released material contained 2.6 million unique email addresses accompanied by names, physical addresses, and phone numbers. Portions appeared in healthcare enrollment files formatted as ASC X12 transaction sets, some of which included Medicaid IDs, while other records came from member files. DentaQuest confirmed a cybersecurity incident involving unauthorized access, but the precise timeline of the intrusion, the method of entry, and the full scope of files accessed have not been disclosed publicly.

Who is shinyhunters?

ShinyHunters is a known threat actor that specializes in data extortion. The group typically gains access to corporate networks, exfiltrates large volumes of information, and then demands payment in exchange for not publishing the material. When payment is not made, it posts the data on public leak sites. The actor has been linked to similar campaigns against organizations in multiple sectors over recent years, often releasing structured files such as databases or transaction records. In this case, the group claims responsibility for obtaining and publishing the DentaQuest material; independent confirmation of the full contents or the initial access vector has not been provided beyond the public listing.

About DentaQuest

DentaQuest operates as a dental benefits administrator. Organizations of this type manage dental insurance plans, process claims, maintain member enrollment records, and coordinate with healthcare providers and government programs such as Medicaid. They routinely collect and store personal identifiers, contact information, insurance details, and clinical or eligibility data to administer coverage. A breach at such an entity is consequential because the records combine standard personal information with elements tied to health coverage and government identifiers, increasing the potential downstream uses of the exposed material.

What data was at risk

The reported data types include dates of birth, email addresses, genders, government-issued IDs, health insurance information, names, phone numbers, and physical addresses. The published files contained healthcare enrollment records in ASC X12 format, some holding Medicaid IDs, as well as additional member records. Exact confirmation of every field present across all released files has not been made public, and the complete inventory of data accessed during the incident remains unconfirmed beyond these categories.

The real-world impact

Individuals whose information appears in the published data may encounter risks of targeted phishing, account takeover attempts, or misuse of insurance details. Government-issued IDs and health coverage information can be leveraged for fraud that extends beyond typical financial crimes. For the organization, the incident adds to operational costs associated with investigation, notification, and potential regulatory review. No specific figures on financial loss or regulatory action have been released at this stage.

If your data was in this breach

Begin by monitoring accounts linked to the exposed email addresses and phone numbers for unusual activity. Place fraud alerts with credit bureaus if government-issued IDs were involved, and review any health insurance statements for discrepancies. Use reputable breach-checking services to scan your email address against known exposed datasets. Organizations recommend changing passwords for any accounts that reuse the affected email and enabling multi-factor authentication where available. Keep records of any suspicious contacts that reference the incident.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyDentaQuest security record
68/100
DoxxScan™ · Moderate doxx risk
D+ 56Weak record

1 reported incident on record.

See DentaQuest’s full breach history →

More recent breaches

Sysco Data Breach (2026)June 15, 2026BCD Travel Data Breach (2026)May 29, 2026Cushman & Wakefield Data Breach (2026)May 5, 2026Vimeo Data Breach (2026)April 28, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the DentaQuest Data Breach (2026) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram