Wednesday, August 19, 2026 76°F Knoxville
Mon–Fri 9–5 ET Answered by a human
Press Release · August 6, 2026

Limehawk urges families to freeze their children's credit after the DentaQuest breach.

Hackers published Social Security numbers, Medicaid IDs, and dental records of up to 23.4 million people, many of them children on Medicaid plans.

KNOXVILLE, Tenn., Aug. 6, 2026 — Limehawk, LLC, a Knoxville managed IT services provider, today urged families to freeze their own and their children’s credit after the DentaQuest data breach put Social Security numbers and Medicaid records for as many as 23.4 million people on the open internet.

DentaQuest, part of Sun Life U.S., is the largest Medicaid and Children’s Health Insurance Program (CHIP) dental benefits administrator in the country and operates in all 50 states, according to The HIPAA Journal. The company is mailing separate notification letters to parents and guardians of affected children, a signal of how many minors are in the stolen files.

Attackers were inside the DentaQuest network from May 17 to May 20, 2026, when the company discovered the intrusion. The extortion group ShinyHunters claimed the attack and, after ransom negotiations failed, published 234 gigabytes of stolen data, according to reporting by Paubox and SecurityWeek.

The files include names, addresses, Social Security numbers, member identification numbers, Medicaid and Medicare numbers, and dental or vision records: provider names, diagnoses, treatments, and billing details, according to DentaQuest’s own notification letters.

DentaQuest has confirmed that at least 15 million people are affected. Independent researchers who counted unique name and birth-date combinations in the leaked files put the total above 23.4 million. Notification letters began mailing on a rolling basis July 17, with breach filings on record with the attorneys general of California, Texas, Massachusetts, and South Carolina. Plaintiffs’ attorneys are investigating.

“This breach is not abstract for us — it reached my own household,” said Corey Watson, Managing Member of Limehawk. “A child’s Social Security number is especially valuable to identity thieves, because nobody checks a seven-year-old’s credit report. Fraud opened against a child can run undetected for a decade. If your family had dental coverage through a Medicaid or CHIP plan, assume your information is in this leak and act now.”

What should affected families do?

Limehawk recommends these steps for anyone who has received a DentaQuest notice, or whose family had dental or vision coverage administered by DentaQuest:

  • Enroll in the free monitoring. DentaQuest offers two years of free identity monitoring through Kroll: credit monitoring, fraud consultation, and identity theft restoration. Enroll at enroll.krollmonitoring.com/redeem with the Activation Code and Verification ID printed in your notification letter; you have 90 days from the mail date. Questions: info.krollmonitoring.com or 1-844-959-7163 (Monday–Friday, 8 a.m.–5:30 p.m. Central).
  • Freeze your credit at all three bureaus. A freeze is free and does not affect your credit score. Equifax (1-800-685-1111), Experian (1-888-397-3742), and TransUnion (1-800-888-4213).
  • Freeze your children’s credit too. Request a protected consumer freeze for each minor child at the three bureaus listed above. The bureau creates a credit file for the child and then freezes it.
  • Check your credit reports. Pull free reports for every adult in the household at AnnualCreditReport.com or 1-877-322-8228.
  • Watch your benefit statements. Review explanation-of-benefits statements from your dental, vision, and health plans. Report any care you did not receive.
  • Be suspicious of unexpected contact. ShinyHunters is known for follow-on extortion emails and threatening calls to breach victims. Do not click links in unexpected messages that reference your dental coverage.
  • Lock down your tax filings. Request an Identity Protection PIN from the IRS to block fraudulent returns filed under your Social Security number.
  • If you find fraud, report it. Get a recovery plan at IdentityTheft.gov or call the FTC at 1-877-438-4338, and file a report with local law enforcement.

How big is this breach, really?

The breach first surfaced publicly at a fraction of its real size. The leak was added to the Have I Been Pwned notification service on June 3, 2026 as 2.6 million email addresses. DentaQuest’s own investigation later confirmed at least 15 million affected people. Independent researchers counting unique name and date-of-birth combinations in the leaked files estimate more than 23.4 million.

State attorney general filings account for about 4.5 million written notifications so far. One folder in the leak alone contained more than 1.7 million unique Social Security numbers tied to a Texas organization. DentaQuest serves roughly 32 to 35 million people nationwide.

Health-plan enrollment data is a worst-case identity theft package. It pairs government identifiers with names, birth dates, and addresses. And it covers the population least likely to monitor credit reports: Medicaid families and children. That is why Limehawk recommends credit freezes, not just monitoring, for every affected household.

What does this mean for Tennessee?

DentaQuest was TennCare’s statewide dental benefits manager for twelve years. Tennessee awarded DentaQuest the contract in 2013 after competitive bid, and DentaQuest began managing dental benefits for roughly 750,000 children that October. CoverKids awarded DentaQuest its dental contract in 2015. Renaissance Dental replaced DentaQuest as the TennCare and CoverKids dental benefits manager on November 1, 2025, six months before the breach.

Losing the contract did not remove Tennessee records from DentaQuest’s systems. DentaQuest’s own notification letters say they apply to people whose health plan “works with, or used to work with” DentaQuest. In practice, that means virtually every Tennessee family with TennCare or CoverKids dental coverage between 2013 and late 2025 has records that were in DentaQuest’s systems. Whether all of those records appear in the published leak is not confirmed; no state-by-state breakdown has been released. Tennessee families should assume exposure and take the steps above.

Sources

  1. Have I Been Pwned, “DentaQuest Data Breach”, added June 3, 2026.
  2. The HIPAA Journal, “DentaQuest Starts Notifying 15 Million+ Individuals About May 2026 Cyber Incident”.
  3. Paubox, “DentaQuest breach toll passes 23 million as notifications begin”.
  4. SecurityWeek, “DentaQuest Data Breach Potentially Impacts Over 23 Million People”.
  5. ClassAction.org, “DentaQuest Data Breach Reported; Attorneys Investigating”.
  6. DentaQuest, “Notice of Data Breach” — adult notification letter mailed to affected members (form ELN-27527), 2026.
  7. Fierce Healthcare, “DentaQuest Begins Management of TennCare Dental Benefits”, 2013.
  8. State of Tennessee, “CoverKids Awards Dental Benefits Manager Contract to DentaQuest”, 2015.
  9. TennCare, “Dental Benefits Manager” — Renaissance Dental is the statewide dental benefits manager effective November 1, 2025.
Advertisement, ours, permanently
Worried your business data is out there too?

Fifteen minutes with Corey. Bring the breach notice, leave with a plan.