DentaQuest Data Theft Hack Affects 15M Patients
Data Breach Notification
,
Data Privacy
,
Data Security
Number of Victims Is 5 Times Higher Than Claims by ShinyHunters Ransomware Gang

DentaQuest, one of the largest dental and vision benefits administrators in the United States, is notifying 15 million people that their sensitive information was compromised in a May hack.
See Also: The Unstructured Data Blindspot: Why Your Most Valuable Assets Are Your Least Protected
The DentaQuest hack is on track to rank as the biggest health data breach so far in 2026, and as the fourth largest of nearly 7,900 HIPAA breaches reported to date since federal regulators began keeping tally in September 2009.
The DentaQuest victim count posted to the Oregon attorney general’s breach reporting website this week is more than five times higher than the number claimed by prolific extortion gang ShinyHunters, which took credit for the data theft (see: ShinyHunters Leaks 234GB DentaQuest Data Trove).
ShinyHunters boasted on its darkweb leak site in May of publishing 234 gigabytes of DentaQuest data related to 2.6 million people after the company “failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don’t care.”
Some experts said the huge discrepancy in the number of victims claimed by an extortion gang and the insurer isn’t uncommon.
“Attacker claims often reflect what they think they stole – or what they choose to claim – while a company’s notification numbers need to account for the broader set of data that was potentially accessible during the intrusion window,” said Errol Weiss, chief security officer at the Health Information Sharing and Analysis Center. “It’s also common that the confirmed affected count can rise as the forensic investigation continues.”
As of Friday, the U.S. Department of Health and Human Services’ HIPAA Breach Reporting Tool website still had the DentaQuest hack listed with an initial estimate the company reported in May of only 3,086 affected people.
DentaQuest didn’t immediately respond to ISMG’s request for comment on ShinyHunters’ claims and for additional details about the hack.
In a breach notice posted on DentaQuest’s website, the company said that on May 20 it discovered that “unauthorized individuals” accessed data on its computer network.
DentaQuest’s investigation determined that the incident began on May 17 and ended by May 20.
A review and analysis is ongoing, but so far the investigation has found that compromised information varies by individual but could include name, address, Social Security number, member identification number, Medicaid number and Medicare number, as well as dental or vision health information, including provider name, diagnosis, treatment and billing information.
DentaQuest is offering affected patients 24 months of identity and credit monitoring.
Long, Growing List of Victims
ShinyHunters’ hack on Massachusetts based- DentaQuest – a company owned by Canada-based Sun Life Financial – is among a long and growing list data theft attacks the cybercrime gang has claimed in recent months, including healthcare sector organizations.
The flurry of ShinyHunters data thefts has prompted some industry groups, including the Health-ISAC, to warn the healthcare sector of gang’s evolving and persistent threats.
“ShinyHunters operates a pure ‘pay-or-leak’ data extortion model rather than the traditional malware encrypting scheme,” said Health-ISAC’s Weiss.
The group is a prolific and dominant threat right now, representing a massive wave of cloud-scale data exfiltration, he said. “In just a few short months in 2026, we’ve seen ShinyHunters successfully target major medical device manufacturers, dental administrators and primary care networks, exposing millions of sensitive records,” he said.
Other alleged ShinyHunters’ healthcare sector victims range from medical device maker Medtronic to East of England Ambulance Service, a U.K.-based ambulance firm.
“They are thriving because they expertly exploit third-party repositories, SaaS platforms like Microsoft 365 and legacy systems that organizations may have stopped actively monitoring,” Weiss said.
What also makes ShinyHunters so dangerous is that they weaponized social engineering “to an entirely new level,” said Weiss, who has spoken with a variety of health sector CISOs whose organizations were successfully attacked and compromised by the gang.
“By aggressively vishing and berating employees, they manipulate staff into authorizing multifactor authentication resets and handing over the keys to the target environment,” he said.
Because ShinyHunters relies so heavily on identity compromise, organizations “must get identity and access right,” Weiss said.
“The key is to break the chain between the initial vishing call and SSO takeover. This means hardening help desk workflows by requiring out-of-band verification for password resets and strengthening multifactor authentication against social engineering by using phishing-resistant MFA, such as FIDO2 security keys, for administrators, help desk staff, execs and other high-risk groups,” he advised.
While ShinyHunters is successful with aggressive social engineering, the group doesn’t use “exotic malware,” Weiss said. “Train for the reality of this threat.”
“Your staff needs to know it’s OK to slow down, verify requests through known good channels and report pressure tactics immediately. If you only train for email phishing, you won’t be ready for attackers like this,” he said. “These campaigns blend email, text, and voice to create urgency and credibility,” he said.
“In healthcare, that resilience matters because cybersecurity is patient safety.”