The healthcare industry continues to be hit hard by cybercriminals, with the spring hacking of DentaQuest exposing the private data of 15 million people—the largest health data breach reported to federal regulators so far in 2026.
The U.S.-based dental benefits administrator has approximately 32 million beneficiaries enrolled in its dental and vision plans. The company discovered in May that hackers, reportedly linked to the cyber threat group ShinyHunters, had gained access to its data.
Hacking has been the leading cause of healthcare data breaches reported to federal regulators since 2017. One of the latest breaches involves Baylor Genetics, where a cyberattack may have affected 2.8 million people by exposing lab results, medical conditions, Social Security numbers and other sensitive information.
DentaQuest engaged financial and risk advisory firm Kroll to conduct an analysis of the impacted data. According to the review, beneficiaries’ personal, sensitive and medical information could have been exposed, including Social Security numbers, Medicaid and Medicare IDs, diagnosis, treatment and billing information.
The Health Information Sharing and Analysis Center (H-ISAC), a global organization that facilitates information sharing among healthcare organizations, released a threat bulletin about ShinyHunters in July. The bulletin warned that the group uses social engineering tactics, including phone calls, to trick individuals into sharing information and compromising accounts.
DentaQuest did not respond to a request for comment. However, the company said in July that it had begun notifying affected individuals of the breach, provided additional security training to employees and implemented more stringent security controls.
Healthcare Data Is a High-Value Target
The DentaQuest breach is another reminder that healthcare organizations face a particularly difficult cybersecurity challenge. They hold vast amounts of sensitive information—including financial, medical and personally identifiable information—that can be extremely valuable to cybercriminals.
And as the ShinyHunters activity demonstrates, the threat isn’t limited to sophisticated technical attacks. Social engineering remains a powerful way for attackers to gain access to organizations by targeting the people who interact with their systems every day.
For healthcare organizations, protecting sensitive data requires more than strong passwords and security software. Organizations also need threat intelligence and visibility into where sensitive information is exposed, who has access to it and whether compromised credentials could put patients, employees and customers at risk.
Credential Exposure Can Increase Account Takeover Risk
Stolen credentials are among the most valuable assets for cybercriminals. When usernames, passwords or other identity information are exposed, attackers may use them to attempt account takeover or gain access to additional systems and data.
This makes credential exposure monitoring an important component of a broader cybersecurity strategy. By continuously monitoring for exposed credentials and other sensitive information, organizations can identify potential risks earlier and take steps to protect affected accounts.
For healthcare organizations in particular, early visibility matters. A compromised credential may not immediately result in a breach, but it can create an opening for attackers to move deeper into an organization’s systems.
Dark Web Monitoring and Exposure Intelligence
Sensitive information stolen during a breach can also circulate long after the initial attack. Cybercriminals may share, sell or reuse credentials and other personal information across underground forums and the dark web.
Dark web monitoring can help organizations identify when credentials or other sensitive information associated with their employees, customers or organization appear in these environments.
More broadly, exposure intelligence gives security teams insight into what information may already be available to cybercriminals. Instead of waiting until stolen information is used in an attack, organizations can identify exposed data and take action to reduce their risk.
Turning Breach Awareness Into Action
The DentaQuest breach demonstrates how quickly a cyberattack can affect millions of individuals—and how difficult it can be to regain control once sensitive information has been exposed.
While no organization can eliminate every cyber threat, proactive digital risk intelligence can give security teams greater visibility into compromised credentials and exposed information. Combining this intelligence with employee security training, stronger access controls and an effective data breach response strategy can help organizations reduce the potential impact of an attack.
Enfortra helps organizations identify exposed credentials, sensitive information and other indicators of risk across the digital landscape. Its exposure intelligence and credential exposure monitoring capabilities provide security teams with greater visibility into potential threats, helping them identify risks before exposed information can be used against their organization or its customers.
Want to know what information associated with your organization may already be exposed? Enfortra can help you uncover credential and identity exposure, monitor potential threats and take action before a cyber risk becomes a larger security incident.