The largest health data breach reported so far in 2026 is expanding in real time: DentaQuest, one of the biggest US dental and vision benefits administrators, has begun mailing notices to more than 15 million people whose records were stolen in a May intrusion claimed by the ShinyHunters extortion gang. Owned by Sun Life Financial, the company said attackers held access from May 17 to May 20 before it locked them out, and an investigation assisted by Kroll is still sizing up the damage.
Compromised fields per individual could include Social Security numbers, Medicaid and Medicare identifiers, member IDs, and dental or vision health information such as diagnosis, treatment and billing details. ShinyHunters dumped 234 GB of stolen data on its leak site in May, saying talks with the company had failed. The total posted to Oregon’s attorney general portal this week runs more than five times the 2.6 million people the gang claimed, and an independent analysis of unique name and birth-date combinations suggests the figure could climb toward 23.4 million.
If it does, the incident would rank as the fourth-largest breach in the roughly 7,900 HIPAA cases logged since 2009. The HHS breach tool still carries DentaQuest’s initial May estimate of 3,086. Notifications began July 17 with 24 months of credit monitoring, and because the stolen records are already circulating online, affected members should enroll immediately. For benefits administrators, the episode underscores that data rich in Social Security and Medicaid identifiers is a prime extortion target, and that early victim estimates are often a floor, not a ceiling.
