ALITEQ.

shinyhunters just leaked 15 million people's dental records because DentaQuest wouldn't pay

The same crew behind the Snowflake and Salesforce mega-breaches just handed the US its biggest healthcare data breach of 2026 — and the number keeps climbing.

Priya NairUpdated 2h ago6 min readWeb story
Rows of medical record file folders, representing the DentaQuest data breach

DentaQuest, the second-largest dental benefits administrator in the United States, spent three days in May with an intruder sitting inside its network — and by the time anyone noticed, the intruder had already copied Social Security numbers, Medicaid and Medicare IDs, addresses, and treatment histories belonging to at least 15 million people. That makes this the largest healthcare data breach confirmed anywhere in the US this year, and the number reported to federal regulators has already moved once, from an initial estimate of 23.4 million potentially affected down to a confirmed 15 million — still roughly the entire population of Pennsylvania.

The intrusion ran from May 17 to May 20, 2026. DentaQuest caught it on the last day, which is also the day the timeline stops being about DentaQuest and starts being about ShinyHunters — the extortion crew that's spent the past two years turning corporate data theft into a subscription business.

Who ShinyHunters actually is

If the name sounds familiar, it should. ShinyHunters is the group behind the 2024 Snowflake customer breaches — the one that hit AT&T, Ticketmaster, and Santander through stolen cloud credentials — and it's kept working the same playbook since: get in, take the database, threaten to publish it, and let the deadline do the negotiating. There's no ransomware payload here, no encrypted files, no locked hospital systems. It's data theft and extortion, and DentaQuest is just the latest company that decided not to pay.

ShinyHunters posted a demand on its dark web leak page around May 22, gave DentaQuest until May 27, and when that deadline passed, published roughly 234GB of the stolen data. Have I Been Pwned independently verified the leak and found 2.6 million unique email addresses in it, alongside names, addresses, phone numbers, dates of birth, government-issued IDs, and Medicaid enrollment records — which is the part that should actually worry you. A Medicaid ID paired with a Social Security number and a real diagnosis history isn't just useful for opening a fraudulent credit card. It's a complete kit for medical identity fraud, the kind where someone bills a real insurer for a real procedure using your identity, and the record lands on your file, not theirs.

A padlock icon glowing over a laptop keyboard, representing stolen personal data
Roughly 234GB of DentaQuest's stolen data went public after the company didn't meet ShinyHunters' ransom deadline. · Unsplash

Why a dental insurer had 15 million people's medical data in the first place

This is the part that's easy to miss: DentaQuest isn't a hospital. It's a benefits administrator — the company that sits between a state Medicaid program and the dentists who actually see patients — and it processes exactly the kind of aggregated, high-value dataset that makes a single breach this catastrophic. One compromised system, one company, fifteen million records. That's the same structural problem behind Framework's Metabase breach and CareCloud's four-month notification gap earlier this year: healthcare has consolidated its data into fewer, bigger, more attractive targets, and the security spend hasn't kept pace with the consolidation.

15,000,000+

People affected

Confirmed to HHS OCR, down from an initial 23.4M estimate

~234GB

Data leaked

Published after DentaQuest didn't pay the ransom

2.6M

Verified emails

Unique addresses confirmed by Have I Been Pwned

24 months

Free monitoring

Credit monitoring plus identity restoration

What to actually do if you're a DentaQuest patient

1

Check whether your email shows up in the leak via Have I Been Pwned — DentaQuest's own notice may undercount who's affected.

Sign up for the 24 months of free credit monitoring and identity restoration DentaQuest is offering — it's free, use it.

3

Request an Explanation of Benefits review from your Medicaid or Medicare plan for any dental claims you don't recognize.

Freeze your credit with all three bureaus if you haven't already — a leaked SSN plus date of birth is enough to open new accounts.

Was DentaQuest hit by ransomware?
Not in the traditional sense — no files were encrypted. This was data theft and extortion: ShinyHunters stole the data, demanded payment to prevent publication, and leaked roughly 234GB once DentaQuest didn't pay by the deadline.
How many people were actually affected?
DentaQuest initially disclosed a potential impact of up to 23.4 million individuals; the figure confirmed to HHS's Office for Civil Rights is 15 million, and it could still move.
What data was stolen?
Names, addresses, Social Security numbers, dates of birth, Medicaid and Medicare member IDs, dental provider names, diagnosis and treatment details, and billing information.
Is there a lawsuit?
Yes — a class action was filed in Massachusetts federal court on June 4, 2026, alleging DentaQuest failed to implement adequate security safeguards.

This is the fourth time in five months I've written about a healthcare vendor losing control of data it was trusted to protect, and the pattern repeats: a mid-sized administrator holding a database worth more than the company itself, discovered weeks after the fact, disclosed to patients even later. If your dental or medical benefits run through a third-party administrator you've never heard of — and most people's do — this is worth ten minutes of checking whether your information showed up somewhere it shouldn't have.

Software & Systems Editor

Priya Nair

Priya has daily-driven more Linux distros than she can name and treats her setup like a workshop. She covers the operating systems, apps and settings worth your time — and cheerfully calls out the 'optimizations' that just quietly break your machine.

Work out the hardware

The Aliteq brief

The tech worth knowing — hardware, AI, gaming, deals. No spam, unsubscribe anytime.

Keep reading