United States
DentaQuest
The May 2026 ransomware attack on DentaQuest, one of the largest dental and vision benefits administrators in the U.S., has now been confirmed to have affected 15 million individuals.
The incident first came to light on May 20, and DentaQuest’s investigation determined that attackers had access to the organization’s network between May 17 and May 20. The victim count, now published on the Oregon Attorney General’s data breach reporting website, is almost six times higher than the number initially claimed by the ShinyHunters extortion gang. In May, the group published 234 GB of DentaQuest data on its dark web leak site, claiming it related to 2.6 million individuals.
The incident now ranks as the largest health care data breach reported so far in 2026 and the fourth largest among nearly 7,900 HIPAA data breaches reported since federal regulators began tracking such incidents in September 2009.
How it could affect your business
DentaQuest is one of a growing number of organizations across multiple sectors that have fallen victim to data theft attacks linked to the ShinyHunters gang, highlighting the increasing scale and persistence of modern ransomware and extortion campaigns. Organizations should strengthen their defenses through proactive threat monitoring, layered security controls and rapid incident detection, while maintaining ransomware-resilient backups and a robust business continuity and disaster recovery (BCDR) strategy to enable fast recovery and minimize operational disruption following an attack.
