DentaQuest breach may have exposed data of 23 million
DentaQuest reported a May 17-20 cyberattack may have exposed personal and dental records of more than 23 million people, including Social Security numbers and medical and billing information.
DentaQuest discovered the incident on May 20 and said attackers had access to its network from May 17 to May 20. The company’s review found the exposed information may include names, addresses, Social Security numbers, member identification numbers, Medicaid and Medicare numbers, diagnosis and treatment details, and billing records.
Filings with state attorneys general in Texas, Massachusetts and South Carolina show the company is sending written notification letters to at least 4.5 million people. DentaQuest confirmed that at least 15 million people were affected and public estimates place the potential total above 23 million.
DentaQuest told regulators it will provide affected individuals with 24 months of free credit monitoring, fraud consultation and identity-theft restoration services.
An extortion group claimed responsibility for the attack and posted roughly 234 gigabytes of data it said were taken. That material reportedly included email addresses, phone numbers, dates of birth, government-issued IDs and medical and billing records.
DentaQuest, a Sun Life subsidiary that serves about 35 million people in all 50 states, said it implemented measures to contain the incident and opened an investigation. The company has not disclosed technical details about how the attackers gained access or identified a specific threat actor in its public notices.
State filings and notification letters are intended to meet legal disclosure requirements and inform members so they can take steps to protect financial and medical information. The company continues to communicate with regulators and affected members as it works to determine the full scope of the exposure.








