Dental and vision benefits administrator DentaQuest has begun notifying more than 15 million individuals that their personal and health information was exposed in a breach discovered in May, according to a notice DentaQuest filed with the California Attorney General’s office on July 16. The company says an unauthorized party accessed its network between May 17 and May 20, 2026, and that exposed data includes names, addresses, Social Security numbers, Medicaid and Medicare numbers, and dental or vision treatment and billing records. Notification letters began going out on a rolling basis starting July 17, and DentaQuest is offering affected individuals 24 months of credit monitoring and identity theft protection.
The extortion group ShinyHunters has claimed responsibility for the attack and posted data it says came from DentaQuest to a dark web leak site, a claim DentaQuest’s own notice does not confirm or name. That gap between an extortion group’s public claim and a company’s own breach notice is now a routine feature of these disclosures, and it means the 15 million figure DentaQuest confirms should be read as a floor, not a ceiling, until the company’s investigation closes.
For security and privacy leaders, DentaQuest is another entry in a pattern CyberTech has tracked all year: the same extortion crew claiming credit across unrelated sectors and company sizes, from enterprise SaaS platforms to healthcare administrators, the way ShinyHunters did in its OAuth-driven campaign against Salesforce customers. The operative question for a healthcare vendor risk review is no longer whether a given administrator has been targeted, but whether the organization has confirmed what data that vendor holds, and how quickly it commits to disclosing a confirmed number rather than a range.
Source: California Attorney General