DentaQuest Told Regulators 2.6 Million People Were Breached. The Notice Letters Went Out to More Than 15 Million.
One number went to the Maine Attorney General. A far larger one is showing up in the notification program — and a researcher's analysis of the stolen files points higher still. What is confirmed, what is not, and why there is still nothing to claim.
By Settlement Insight Data Desk ·
Two numbers, six times apart
DentaQuest, a dental benefits administrator that is part of Sun Life U.S., determined that intruders accessed its network between May 17 and May 20, 2026, discovering the intrusion on May 20. In its breach filing with the Maine Attorney General, the company put the count at exactly 2,643,348 individuals.
Then the notification program started. Letters began going out on a rolling basis on July 17, 2026, and reporting by HIPAA Journal, which tracks these filings, puts the number of people being notified at at least 15 million — roughly six times the figure filed in Maine.
A third number is circulating: an independent researcher's analysis of the leaked dataset, via Have I Been Pwned, suggests the true total could exceed 23.4 million. We flag that one clearly as an unconfirmed estimate — it has not been verified by DentaQuest or any regulator. At the time of writing the incident had not yet appeared on the federal HHS Office for Civil Rights breach portal, which is where an official national total would normally land.
Breach counts growing after the first filing is common; the initial number reflects what forensics had confirmed at that moment. A six-fold revision is still unusually large.
What was taken is worse than the average breach
Per notification letters filed with the California Attorney General, the exposed data includes names, addresses, Social Security numbers, member identification numbers, Medicaid and Medicare numbers, and dental or vision health information including provider name, diagnosis, treatment and billing detail.
That combination matters. An SSN enables ordinary financial identity theft. An SSN plus a Medicaid or Medicare number enables medical identity theft — someone obtaining treatment under your policy, which writes their information into your medical record. Unwinding that is materially harder than closing a fraudulent credit card, and it can affect later care.
The ransomware group ShinyHunters claimed credit around May 22, 2026 and threatened to publish the stolen data by May 27 if no ransom was paid. DentaQuest is offering 24 months of complimentary credit monitoring and identity-theft protection.
A dozen lawsuits, zero dollars
At least a dozen federal class actions are pending in the U.S. District Court for the District of Massachusetts, the first filed June 1, 2026 (King v. DentaQuest Group, Inc.), alleging negligence, breach of contract, unjust enrichment and invasion of privacy. Consolidation into a single case is the likely next step.
Here is what does not exist: a settlement, a settlement fund, a claims administrator, a claim form, or a deadline. Any website inviting you to file a DentaQuest claim today is collecting your personal information, not filing anything on your behalf.
Based on comparable health-data cases, a realistic path is consolidation, then motions to dismiss, then possible settlement negotiations — commonly 18 to 36 months before any money is distributed, if it ever is.
What is actually worth doing this week
Activate the monitoring. It is free but it is opt-in, and most people never enroll. Unused coverage protects nobody.
Freeze your credit at all three bureaus. It is free, it takes about fifteen minutes, and it blocks new-account fraud outright rather than reporting it after the fact — strictly stronger than monitoring.
Watch the medical side too. Read your Explanation of Benefits statements for treatment you never received, which is the earliest visible sign of medical identity theft.
Keep the letter. If a settlement does arrive years from now, the notification letter is the cleanest proof of class membership — and the single most common reason people miss out is that they cannot show they were affected.
The Data Behind This Story
- Reported to Maine AG
- 2,643,348
- Individuals being notified
- 15 million+
- Unconfirmed researcher estimate
- 23.4 million+
- Breach window
- May 17–20, 2026
- Notifications began
- July 17, 2026
- Settlement fund
- None — no settlement exists
- Free monitoring offered
- 24 months
- Source: DentaQuest breach notification filed with the Maine Attorney General (2,643,348 individuals)
- Source: DentaQuest notification letters filed with the California Attorney General (data categories, monitoring offer)
- Source: HIPAA Journal reporting on the DentaQuest notification program (15 million+); Have I Been Pwned dataset analysis (unconfirmed 23.4 million estimate)
- Source: King v. DentaQuest Group, Inc. and related actions, U.S. District Court for the District of Massachusetts (first filed June 1, 2026)
- Source: Settlement Insight tracker: settlementinsight.com/dentaquest-data-breach-settlement
Journalists: these figures are free to cite with attribution to Settlement Insight. Custom data pulls: press@settlementinsight.com.