← DentaQuest

2026 DentaQuest — ShinyHunters; company notifying ≥15M (potential ~23.4M unique IDs cited)

2026 15.0M records affected Share on X

Data compromised

Names, addresses, SSNs, member/Medicaid/Medicare IDs, dental/vision health info (provider, diagnosis, treatment, billing); HIBP previously verified 2.6M unique emails in leak set

Technical writeup

DentaQuest (Sun Life dental/vision benefits administrator) confirmed unauthorized access to parts of its network between May 17 and May 20, 2026, after discovering the intrusion on May 20. ShinyHunters claimed a ~234GB theft and published data on its leak site around May 30 after reporting failed ransom negotiations. Have I Been Pwned verified about 2.6 million unique email addresses in the early public dump (enrollment-style files with contact and demographic fields). In July 2026 the company began rolling notification letters stating at least 15 million individuals were affected, with data categories including names, addresses, Social Security numbers, member/Medicaid/Medicare identifiers, and dental or vision health information (provider, diagnosis, treatment, and billing). DentaQuest engaged Kroll for data-mining review and 24-month identity monitoring enrollment (Enroll.krollmonitoring.com/redeem). Separate CA AG templates exist for adult members and for parents/guardians of affected minors. At indexing in August 2026, user and social-media reports also described parent/guardian notification letters received by individuals who are not the parents or guardians of the named children — suggesting Kroll-managed mailing list or guardian-linkage errors in a subset of minor notices; DentaQuest’s call center (1-844-959-7163) is the stated channel to verify eligibility. Attorney General filings in Texas, Massachusetts, and South Carolina reflected written notices to at least ~4.5 million people as of late-July press coverage. HIPAA Journal / SecurityWeek cite researcher analysis that unique name+DOB combinations in the published set could exceed ~23.4 million, with ~1.7 million unique SSNs appearing to belong largely to children. BreachHistory keeps recordsAffected at the company-attested ≥15M notification floor; the ~23.4M figure is a researcher/potential upper bound, not a separate company headcount. Kroll here is the notification/monitoring vendor — not a separate breach victim.

Root cause

Confirmed unauthorized network access May 17–20, 2026; ShinyHunters published alleged ~234GB dump after failed extortion; company rolling notifications from Jul 17

References