DentaQuest, LLC Data Breach Investigation

Data Breach Blog

Data Breach

DentaQuest, LLC Data Breach Investigation

Almeida Law Group Calendar Icon

Date of data breach:

July 17, 2026

by: Almeida Law Group

Almeida Law Group is investigating a data breach at DentaQuest, LLC. The breach occurred on May 17th–19th, 2026 and was discovered on May 20th, 2026. If you were affected, contact Almeida Law Group.


About DentaQuest, LLC

DentaQuest, LLC is one of the largest dental benefits administrators in the United States, managing dental and vision benefits for approximately 32 to 35 million Americans through Medicaid, CHIP, Medicare Advantage, employer groups, health plans, and individual customers. It also operates more than 70 oral health centers providing direct patient care in underserved communities. Headquartered in Wellesley Hills, Massachusetts, DentaQuest is a subsidiary of Sun Life U.S., which acquired the company for approximately $2.5 billion in 2022. Because DentaQuest is the largest Medicaid and CHIP dental benefits administrator in the country, the personal, medical, and health insurance information it handles on behalf of members makes a breach of this scale especially serious.


What Happened?

DentaQuest, LLC was listed in a Texas Attorney General data security breach report published on July 17th, 2026 (record BR-0005182). The filing identifies the incident as unauthorized access to DentaQuest’s systems between May 17th, 2026 and May 19th, 2026, with the breach discovered the following day on May 20th, 2026. The Texas AG filing reports that 15 million people total were affected, and identifies the following categories of compromised information: name, address, Social Security number, medical information, health insurance information, and date of birth. As of the filing date, DentaQuest had not yet provided notice to affected consumers — a significant concern under both HIPAA and state breach notification laws.

The extortion group ShinyHunters claimed responsibility for the attack, with their claim first appearing on Ransomware.live around May 22nd through May 23rd, 2026. This was a data theft and extortion attack, not a ransomware encryption event. After DentaQuest did not meet ransom demands, ShinyHunters publicly leaked over 234 GB of data. Have I Been Pwned independently verified that the leaked dataset contained 2.6 million unique email addresses along with names, addresses, phone numbers, dates of birth, government-issued IDs, health insurance information, and Medicaid IDs found in healthcare enrollment files. DentaQuest confirmed on June 2nd, 2026 that it was managing “a cybersecurity incident involving unauthorized access to a limited portion of our network.” The 15 million total figure reported in the Texas AG filing is substantially larger than the 2.6 million accounts independently verified in the publicly leaked dataset, suggesting the company’s broader assessment of affected individuals may extend well beyond what ShinyHunters released publicly. A class action lawsuit was filed on June 4th, 2026 in Massachusetts federal court by plaintiff Melissa King against DentaQuest Group Inc., alleging the company failed to prevent the breach, stored consumer data without knowledge or consent, and delayed victim notification. Multiple additional law firms have announced investigations, and BenefitsPro reported on June 8th, 2026 that Sun Life’s subsidiary faces multiple lawsuits. DentaQuest also disclosed a separate, prior cybersecurity incident to the U.S. Department of Health and Human Services on January 6th, 2025.


Key Facts at a Glance

  • Company or Organization: DentaQuest, LLC
  • Industry: Healthcare – Dental Benefits Administration / Managed Care
  • Location: Wellesley Hills, Massachusetts
  • Incident type: Unauthorized access; data theft and extortion
  • Date of breach: May 17th, 2026 – May 19th, 2026
  • Date breach discovered: May 20th, 2026
  • Date of consumer notification: Not yet provided as of July 17th, 2026
  • Total persons affected: 15,000,000
  • Prior breach: Yes — DentaQuest disclosed a separate cybersecurity incident to HHS on January 6th, 2025
  • Litigation status: Class action filed June 4th, 2026 in Massachusetts federal court (King v. DentaQuest Group Inc.); multiple additional law firm investigations announced; BenefitsPro reported plural lawsuits as of June 8th, 2026
  • Source: Texas Attorney General data security breach report (BR-0005182), https://oag.my.site.com/datasecuritybreachreport/apex/DataSecurityReportsPage#BR-0005182; BleepingComputer, https://www.bleepingcomputer.com/news/security/dentaquest-data-breach-exposed-info-of-26-million-accounts/; Have I Been Pwned, https://haveibeenpwned.com/Breach/DentaQuest; Top Class Actions, https://topclassactions.com/lawsuit-settlements/lawsuit-news/dentaquest-data-breach-class-action-filed-over-shinyhunters-cyberattack/; BenefitsPro, https://www.benefitspro.com/2026/06/08/sun-life-subsidiary-faces-lawsuits-after-mass-data-breach/

What Should You Do?

If you believe you may have been affected by this breach, act quickly. Because Social Security numbers, medical information, and health insurance information were reportedly compromised, you should place a fraud alert or credit freeze with all three major credit bureaus — Equifax, Experian, and TransUnion — and review your credit reports for unauthorized accounts or activity at AnnualCreditReport.com. Monitor your existing financial and insurance accounts closely for suspicious transactions. Review any Explanation of Benefits statements from your health insurer and check your medical records for services you did not receive, which could indicate medical identity theft. If you receive identity theft protection enrollment instructions from DentaQuest, enroll promptly and note any enrollment deadline. If you discover problems, report them to the Federal Trade Commission at IdentityTheft.gov, which will generate a personalized recovery plan.


Your Legal Rights

If your personal or health information was involved in this breach, you may have legal rights depending on the facts of the incident and the law in your state. Almeida Law Group represents consumers in data breach and privacy litigation and can help you evaluate whether you may have a claim. Contact us at (708) 529-5418 or through our contact page for a free case evaluation.

Were You a Victim of a Data Breach?

"*" indicates required fields

By clicking the SEND button and submitting this form, I consent to receive communications from Almeida Law Group LLC and their co-counsel by phone call, email, and/or SMS regarding this matter and other potential legal matters. I understand that message and data rates may apply and that consent to such contact is not required for use of these services. Message frequency varies. Reply STOP to opt-out and HELP for help. I also agree to the Privacy Policy. I understand that my information may be shared with advertising partners to deliver targeted advertisements and optimize outreach efforts. I confirm that I am at least 18 years old. I have read and understand the disclaimer above. I agree my use of this site and the information provided here is not intended to create and does not create an attorney client relationship with the Almeida Law Group and/or attorneys employed by the Firm. No attorney client relationship is intended or created unless and until an engagement agreement is signed by all relevant parties. The contents of this site constitute attorney advertising and not legal advice; therefore you should not act or rely upon any information contained herein, and should always seek the advice of an attorney.

Resourceful. Resilient. Relentless.

Contact us today to get the justice you and your family deserve.