LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › DentaQuest LLC Data Breach Notice (Oregon Attorney General)

HIGH severityConfirmedHow we verify

DentaQuest LLC Data Breach Notice (Oregon Attorney General): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·July 16, 2026
DentaQuest LLC Data Breach Notice (Oregon Attorney General)

Occurred May 17, 2026 · publicly disclosed July 16, 2026. Approximately 15000000 people affected.

HIGH
Severity
15000000
People affected
1
Data types exposed
July 16, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

DentaQuest LLC disclosed a data breach on July 16, 2026, that affected 15 million individuals and exposed their personal information. Oregon residents who received dental-plan services from the company should review the notice issued to the state Attorney General and consider protective steps such as monitoring accounts and placing a fraud alert.

Severity & verification
HIGH severityConfirmed
Data types not itemised.
Corroborated by an official disclosure or a verified breach feed.
Check your exposure
15000000 accounts were exposed here. We can’t confirm any single incident against the sources we search — but we can show you every leak and listing tied to your email. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Large-scale breaches involving health-related administrators remain a persistent feature of the current threat landscape, where attackers continue to target organisations that sit between patients, providers and insurers. When those organisations hold records for millions of people, even a single incident can create lasting exposure risks that outlast the initial notice.

DentaQuest LLC notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on July 16, 2026. The filing places the incident itself on May 17, 2026, and indicates that approximately 15 million people were affected. The notice characterises the exposed material as personal information. Public detail beyond those points is limited, yet the scale alone makes the event consequential for anyone whose records may have been involved.

What happened

According to the Oregon Attorney General filing, DentaQuest LLC experienced a data breach on May 17, 2026. The company later submitted a breach notice that was reported on July 16, 2026, informing Oregon residents and the state Department of Justice. The filing states that roughly 15 million individuals were affected and that the data involved was personal information as described in the breach notification.

No further public detail is provided in the available record about how the incident was detected, what systems were involved, whether ransomware or another method was used, or how long unauthorised access lasted. The precise geographic distribution of the 15 million affected people beyond the Oregon notification is likewise undisclosed. What is established is the incident date, the reporting date, the approximate headcount, and the high-level category of data named in the notice.

How a breach like this happens

Incidents of this general type typically begin when an attacker gains an initial foothold—often through stolen or phished credentials, a vulnerable remote-access service, an unpatched application, or a compromised third-party connection. Once inside, the attacker may move laterally, locate repositories of member or patient data, and copy or exfiltrate files before defenders fully contain the activity.

In many cases the organisation discovers the intrusion days or weeks later through monitoring alerts, unusual outbound traffic, or notification from a security partner or law-enforcement contact. Containment then involves isolating affected systems, resetting credentials, and beginning forensic review. Notification to regulators and individuals follows once the scope is reasonably understood and legal timelines are met. None of these common patterns is confirmed for the DentaQuest event; they simply describe how comparable breaches frequently unfold when no specific threat group or technique has been publicly attributed.

Who is DentaQuest LLC?

DentaQuest LLC operates in the dental benefits and oral-health administration sector. Organisations of this kind typically manage dental insurance plans, process claims, maintain provider networks, and hold records that link members to coverage, treatment history and related administrative data. They sit at a junction between patients, dentists and payers, which means they routinely handle large volumes of personally identifiable and health-adjacent information.

A breach at such an entity is consequential because the data is both sensitive and reusable. Identity details can facilitate fraud; health-related administrative records can support more targeted social-engineering or medical-identity misuse. Even when clinical notes themselves are not involved, the combination of identity and coverage data creates practical risk for the people whose records are held. The 15-million figure reported in the Oregon filing underscores how widely those records can extend.

What data was at risk

The breach notification, as reflected in the Oregon filing, names the exposed material as personal information. No more granular inventory—such as specific fields, document types or whether Social Security numbers, dates of birth, addresses, insurance identifiers or clinical details were included—is provided in the available facts.

Organisations that administer dental benefits commonly maintain names, contact details, member or subscriber identifiers, dates of birth, insurance and claims-related data, and sometimes government identifiers required for eligibility or billing. It is not confirmed that any particular subset of those categories was involved here. Readers should treat the exact contents as unconfirmed beyond the broad label “personal information” used in the notice.

What's at stake

For affected individuals the primary risks are identity theft, account takeover and targeted fraud. Personal information can be combined with other leaked or publicly available data to open new accounts, file false claims, or craft convincing phishing messages. Because dental-benefits records often remain useful for years, exposure does not necessarily expire when the news cycle ends.

For the organisation the stakes include regulatory scrutiny, notification and remediation costs, potential civil claims, and erosion of trust among members, providers and plan sponsors. Large headcounts amplify those pressures. None of these outcomes is asserted as having already materialised; they are the ordinary consequences that follow incidents of this reported scale.

If your data was in this breach

If you believe you may be among the people covered by the notice, begin by reading any official communication you receive from DentaQuest and following the specific guidance it provides. Place fraud alerts or credit freezes with the major credit bureaus if you are concerned about new-account fraud, and monitor financial and insurance statements for unfamiliar activity. Change passwords on related accounts and enable multi-factor authentication where available. Keep records of any suspicious contacts that reference your dental coverage or personal details.

You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach data sets. That step does not replace official notices or credit monitoring, but it can help you gauge whether your address appears in broader compilations of compromised records and decide what further precautions to take.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

CompanyDentaQuest LLC security record
60/100
DoxxScan™ · Moderate doxx risk
D+ 56Weak record

1 reported incident on record.

See DentaQuest LLC’s full breach history →
RelatedMore incidents at DentaQuest LLC

More recent breaches

Abbott Cancer Diagnostics Data Breach Notice (Oregon Attorney General)August 6, 2026Aesto, LLC Data Breach Notice (Oregon Attorney General)August 5, 2026Wilmer Cutler Pickering Hale and Dorr LLP Data Breach Notice (Oregon Attorney General)August 5, 2026JRK Property Holdings, Inc. Data Breach Notice (Oregon Attorney General)August 4, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the DentaQuest LLC Data Breach Notice (Oregon Attorney General) →

Source: Oregon Department of Justice breach notification

Verified breach

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram