Skip to main content

DentaQuest Data Theft Hack Affects 15M Patients

Errol Weiss, Health-ISAC Chief Security Officer, on ShinyHunters pay-or-leak data extortion model and DentaQuest breach.

Number of Victims Is 5 Times Higher Than Claims by ShinyHunters Ransomware Gang

DentaQuest, one of the largest dental and vision benefits administrators in the United States, is notifying 15 million people that their sensitive information was compromised in a May hack.

Health-ISAC pulled quotes:

“Attacker claims often reflect what they think they stole – or what they choose to claim – while a company’s notification numbers need to account for the broader set of data that was potentially accessible during the intrusion window,” said Errol Weiss, chief security officer at the Health Information Sharing and Analysis Center. “It’s also common that the confirmed affected count can rise as the forensic investigation continues.”

The flurry of ShinyHunters data thefts has prompted some industry groups, including the Health-ISAC, to warn the healthcare sector of gang’s evolving and persistent threats.

“ShinyHunters operates a pure ‘pay-or-leak’ data extortion model rather than the traditional malware encrypting scheme,” said Health-ISAC’s Weiss.

The group is a prolific and dominant threat right now, representing a massive wave of cloud-scale data exfiltration, he said. “In just a few short months in 2026, we’ve seen ShinyHunters successfully target major medical device manufacturers, dental administrators and primary care networks, exposing millions of sensitive records,” he said.

Read the article in Data Breach Today. Read More