DentaQuest, the largest Medicaid dental benefits administrator in the US, is notifying over 23 million individuals that their personal and dental health information was stolen in a May 2026 data breach.
The company, a subsidiary of Sun Life US Dental operating across all 50 states, discovered on May 20 that unauthorized actors had accessed its network between May 17 and May 20. Exposed data may include names, addresses, Social Security numbers, Medicaid and Medicare IDs, and dental or vision health records covering diagnoses, treatments, and billing details.
The ShinyHunters extortion crew took credit for the intrusion, claiming to have exfiltrated 234 GB of data that it published on its dark web portal after ransom talks broke down. Have I Been Pwned found 2.6 million unique email addresses in the leaked dataset along with names, phone numbers, birth dates, and insurance enrollment records that may include Medicaid IDs.
A folder inside the archive appears to hold more than 1.7 million Social Security numbers, a significant portion believed to belong to minors in Texas. The leaked data spans hundreds of thousands of files dating back to at least 2009, and investigators continue to assess the full scope of exposure.
DentaQuest has engaged Kroll to identify affected individuals and is offering 24 months of free credit monitoring and identity theft recovery services. The company said it secured its systems, notified law enforcement, and launched an investigation with independent cybersecurity experts.
