DentaQuest data breach exposed info of 2.6 million accounts
DentaQuest says its networks were breached. BleepingComputer reports leaked data tied to 2.6 million accounts, including IDs, health insurance details, and birth dates.
Intelligence analysis by GPT-5.4 Mini

DentaQuest, a major U.S. dental benefits administrator, confirmed a breach and said service disruption was limited. A leaked dataset analyzed by Have I Been Pwned reportedly contains sensitive information for 2.6 million accounts.
A company that helps manage dental insurance got broken into, and a big pile of private details may have leaked out. It is like someone stealing a folder with names, phone numbers, and insurance cards, then using that information to trick people later.
Analysis
What happened
DentaQuest, part of Sun Life and one of the largest dental benefits administrators in the United States, confirmed on June 2 that it had suffered a cybersecurity incident involving unauthorized access to part of its network. The company said it took immediate steps to secure its environment, contain the attack, and reduce the impact on customers. It also said its systems remained operational with limited disruption.
What data was exposed
According to BleepingComputer, Have I Been Pwned analyzed leaked material linked to the incident and found records for 2.6 million accounts. The exposed data reportedly included email addresses, full names, phone numbers, government-issued IDs, health insurance information, genders, and dates of birth.
Threat actor context
The incident surfaced after the extortion group ShinyHunters listed DentaQuest on its leak site and claimed to have stolen more than 234 GB of data. The article says the data was later published after the threat actor said talks with the company did not result in an agreement.
What it means for affected people
The exposure is especially sensitive because it combines identity data with insurance-related information. That makes follow-up scams more convincing, including messages that reference real personal details. The article advises people who may be affected to treat incoming communications carefully and watch for phishing attempts.
One additional caveat: HIBP noted that about 66% of the exposed records already appeared in its database from earlier incidents affecting other organizations and services. That means some of the leaked data may have been reused from prior breaches, but it does not reduce the seriousness of the exposure for the people involved.
Key points
- DentaQuest confirmed a cybersecurity incident involving unauthorized access to part of its network.
- BleepingComputer reports that Have I Been Pwned found records for 2.6 million accounts in leaked data tied to the breach.
- The exposed data reportedly included names, emails, phone numbers, government-issued IDs, health insurance information, genders, and dates of birth.
- ShinyHunters claimed responsibility on its leak site and said more than 234 GB of data was stolen.
- The article warns affected people to be careful with incoming messages because the leak increases phishing and social engineering risk.
DentaQuest says it contained the incident and kept systems running, which may limit further damage if the response holds. If the company and outside experts identify exactly what was taken, affected people can be warned and protected sooner.
The exposed mix of IDs, birth dates, and insurance details could fuel convincing phishing and identity theft attempts. If the leaked dataset spreads further, affected people may face long-tail fraud risk even after the original intrusion is contained.



