DentaQuest Data Breach May Affect 23.4 Million People
DentaQuest, a Sun Life U.S. subsidiary that administers dental and vision benefits across all 50 states, discovered unauthorized access on May 20. Its investigation found that intruders had access to part of its computer network from May 17 through May 20. A filing published by the California Department of Justice identifies May 17 as the known breach date.
According to DentaQuest's incident notice, the accessed records varied by person. They may include names, addresses, Social Security numbers, member identification numbers, Medicaid or Medicare numbers, benefit provider names, diagnoses, treatment information and billing details. The company has not publicly described the initial access method or identified a software vulnerability involved.
SecurityWeek reported that filings with attorneys general in Texas, Massachusetts and South Carolina account for notification letters to at least 4.5 million people. The higher estimate of more than 23.4 million reflects the potentially affected population reported by HIPAA Journal, while the confirmed total remains at least 15 million. These figures should not be treated as evidence that every listed data element was exposed for every person.
The ShinyHunters extortion group claimed responsibility and said it leaked roughly 234 GB of data, according to SecurityWeek and Security Affairs. Those claims have not established how the attackers entered the network. Have I Been Pwned previously identified 2.6 million unique email addresses in data associated with the incident, alongside identity and healthcare enrollment information.
DentaQuest said it secured the network, notified law enforcement and engaged independent cybersecurity specialists. It is offering affected individuals 24 months of credit monitoring, fraud consultation and identity theft restoration services. Recipients should review official notices, monitor financial and benefits statements, and treat unsolicited messages requesting personal, insurance or payment information with caution.