DentaQuest Data Breach (2026): What Was Exposed & What To Do
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
DentaQuest disclosed a data breach on May 23, 2026, affecting 2.6 million individuals whose dates of birth, email addresses, genders, government-issued IDs, and health insurance information were exposed. Anyone who received services from DentaQuest should check their status on the company’s site and take steps to protect their accounts.
In May 2026, DentaQuest, a dental benefits administrator, was the target of an extortion campaign attributed to the group ShinyHunters. The group publicly released hundreds of gigabytes of data that it claimed originated from the company, affecting 2.6 million individuals. The incident was reported on May 23, 2026, and included names, addresses, phone numbers, and 2.6 million unique email addresses, along with other personal and health-related details found in enrollment and member files.
The breach matters because DentaQuest processes sensitive information for dental coverage and related services. When such records are exposed, affected individuals face potential misuse of their data in contexts that involve both identity and health details. Public reporting indicates the company acknowledged unauthorized access, though further internal details remain limited in available disclosures.
Inside the incident
The facts show that ShinyHunters conducted a "pay or leak" extortion effort against DentaQuest. After the campaign, the group published a substantial volume of data on its leak site. The released material contained 2.6 million unique email addresses accompanied by names, physical addresses, and phone numbers. Portions appeared in healthcare enrollment files formatted as ASC X12 transaction sets, some of which included Medicaid IDs, while other records came from member files. DentaQuest confirmed a cybersecurity incident involving unauthorized access, but the precise timeline of the intrusion, the method of entry, and the full scope of files accessed have not been disclosed publicly.
Who is shinyhunters?
ShinyHunters is a known threat actor that specializes in data extortion. The group typically gains access to corporate networks, exfiltrates large volumes of information, and then demands payment in exchange for not publishing the material. When payment is not made, it posts the data on public leak sites. The actor has been linked to similar campaigns against organizations in multiple sectors over recent years, often releasing structured files such as databases or transaction records. In this case, the group claims responsibility for obtaining and publishing the DentaQuest material; independent confirmation of the full contents or the initial access vector has not been provided beyond the public listing.
About DentaQuest
DentaQuest operates as a dental benefits administrator. Organizations of this type manage dental insurance plans, process claims, maintain member enrollment records, and coordinate with healthcare providers and government programs such as Medicaid. They routinely collect and store personal identifiers, contact information, insurance details, and clinical or eligibility data to administer coverage. A breach at such an entity is consequential because the records combine standard personal information with elements tied to health coverage and government identifiers, increasing the potential downstream uses of the exposed material.
What data was at risk
The reported data types include dates of birth, email addresses, genders, government-issued IDs, health insurance information, names, phone numbers, and physical addresses. The published files contained healthcare enrollment records in ASC X12 format, some holding Medicaid IDs, as well as additional member records. Exact confirmation of every field present across all released files has not been made public, and the complete inventory of data accessed during the incident remains unconfirmed beyond these categories.
The real-world impact
Individuals whose information appears in the published data may encounter risks of targeted phishing, account takeover attempts, or misuse of insurance details. Government-issued IDs and health coverage information can be leveraged for fraud that extends beyond typical financial crimes. For the organization, the incident adds to operational costs associated with investigation, notification, and potential regulatory review. No specific figures on financial loss or regulatory action have been released at this stage.
If your data was in this breach
Begin by monitoring accounts linked to the exposed email addresses and phone numbers for unusual activity. Place fraud alerts with credit bureaus if government-issued IDs were involved, and review any health insurance statements for discrepancies. Use reputable breach-checking services to scan your email address against known exposed datasets. Organizations recommend changing passwords for any accounts that reuse the affected email and enabling multi-factor authentication where available. Keep records of any suspicious contacts that reference the incident.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Sysco Data Breach (2026)BCD Travel Data Breach (2026)Cushman & Wakefield Data Breach (2026)Vimeo Data Breach (2026)Latest breaches
Read GalaxyWarden’s full analysis of the DentaQuest Data Breach (2026) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.