Last updated 1 month ago
DentaQuest, a U.S. dental benefits administrator owned by Sun Life, suffered a data breach after threat group ShinyHunters leaked exfiltrated data. The breach exposed approximately 2.6 million accounts, including names and email addresses. The disclosure was made publicly on or around June 8, 2026, as part of Check Point's weekly threat intelligence report.
The attack was carried out by the threat actor ShinyHunters, who exfiltrated data from DentaQuest's systems. The specific initial access vector and exploitation technique were not detailed in the report, but the breach involved unauthorized access leading to data theft. The compromised data types included names and email addresses of affected individuals.
No further post-incident details were provided in the article, such as regulatory actions, litigation, ransom payments, or containment measures.
Data exfiltration by threat group ShinyHunters
DentaQuest's breach, exposing 2.6 million records including names and emails, indicates a failure in access controls and data exfiltration prevention. The involvement of ShinyHunters suggests that the organization lacked adequate monitoring and response mechanisms to detect and block unauthorized data access in a timely manner. This incident underscores the need for robust network segmentation, anomaly detection, and data loss prevention controls to protect sensitive customer information.
Sign in to join the discussion.
Company
Industry
Location
Disclosed
Records Affected
Attack Vector
Threat Actor
Continent
Country
Industry
Attack Vector
Threat Actor