Skip to content
>_ITDITDWeb Security Platform

Security Guides

A one-time code can be handed over — what the DentaQuest breach teaches about MFA, and what members should do

DentaQuest disclosed a May 2026 breach affecting more than 27.4 million people, including SSNs and Medicaid/Medicare numbers. Based on its notice and state filings: what members should do now, and why code-based MFA was not enough.

Published 2026-09-30 Updated 2026-09-30 Last verified 2026-09-30 15 min read

For: DentaQuest members, former members and parents of child members in the US, and anyone who runs sign-in, MFA or a help desk for an organization. This article is based on DentaQuest's own notice and letters, its filings with US state attorneys general, and US government guidance (FTC, IRS, Medicare, CISA). It does not cover attack techniques.

What affected members should do today

1

Confirm you are affected — use only the number in your letter

DentaQuest began mailing letters on July 17, 2026. Separate versions were filed for adults, minors and deceased individuals. The company also posted the same information on its website for people it could not reach. If you have questions, the dedicated call center is (844) 959-7163, Monday to Friday, 8:00 a.m. to 5:30 p.m. Central Time. Because the data includes phone numbers and addresses, do not trust a call or text that says it is from DentaQuest and asks you to "confirm" your SSN or member ID; call the number printed on your letter instead (see What is phishing?).

2

Enroll in the free identity monitoring before your deadline

The letter offers 24 months of identity monitoring at no cost, covering credit monitoring, fraud consultation and identity theft restoration. It says you have 90 days from the date the letter was mailed to enroll, using the activation code in the letter. Monitoring tells you after something happens; the next step is what stops it.

3

Freeze your credit at Equifax, Experian and TransUnion

The FTC says that while a credit freeze is in place, nobody can open a new credit account in your name. It is free, does not affect your credit score, and lasts until you lift it. You must contact all three bureaus separately. When you need credit, you can lift it temporarily at the bureau the lender uses. A fraud alert is a lighter option that asks lenders to verify your identity first; an initial alert lasts one year.

4

Get an IRS Identity Protection PIN

An IP PIN is a six-digit number that, according to the IRS, prevents someone else from filing a tax return using your SSN. Anyone with an SSN or ITIN who can verify their identity can enroll, even if they do not have to file. The fastest route is your IRS online account. Parents and guardians can also request one for dependents.

5

Read your Explanation of Benefits and watch your Medicaid or Medicare number

The FTC describes medical identity theft as someone using your name, SSN, health insurance number or Medicare number to get care or submit claims. Warning signs include a bill or Explanation of Benefits for care you did not receive, or a debt collector calling about medical debt you do not owe. If you think someone is using your Medicare number, Medicare says to call 1-800-MEDICARE (1-800-633-4227), and it will never call you uninvited to ask for personal information. For a Medicaid number, the FTC's advice applies: contact the health plan and the providers where your information may have been used and ask for the records. Fraud in Medicare and Medicaid can also be reported to the HHS Office of Inspector General hotline (1-800-HHS-TIPS).

6

Parents: freeze your child's credit too

DentaQuest filed a separate letter for minors, so children are among the people being notified. The FTC says that if your child is under 16, you can request a free credit freeze in the child's name; it stays in place until you ask the bureaus to remove it, and each bureau has its own process for minors. For an IP PIN for a child under 18, the IRS says you must use one of its alternative enrollment options.

7

If something is misused, make a recovery plan at IdentityTheft.gov

If you find an account, tax return or medical claim you did not make, report it at IdentityTheft.gov. The FTC site asks what happened and builds a personal recovery plan. DentaQuest's letter also advises contacting your local police if you suspect identity theft.

SSN + name + date of birth

↓

New credit, fake tax returns

→ Credit freeze at all three bureaus + IRS IP PIN

Medicaid / Medicare / member number

↓

Care or claims in your name

→ Read every Explanation of Benefits; call 1-800-MEDICARE or your plan

Name + address + provider and diagnosis

↓

Convincing calls and letters

→ Hang up; call the number on your letter or card

Which step answers which leaked item. None of these items can be changed the way a password can, so each needs a lock or a watch (steps drawn from FTC, IRS and Medicare guidance).

What happened (from DentaQuest's notice and state filings)

Everything below is as stated by DentaQuest in its public notice, its letters to individuals, and its letters to the Washington State Attorney General, or as listed by state regulators.

  1. May 17, 2026

    The incident began, according to the company.
  2. May 19

    According to the Washington filing, all activity by the unauthorized party ended. (The public notice says the incident ended "by May 20".)
  3. May 20

    DentaQuest became aware of an unauthorized third party claiming to have its data, and put containment measures in place. An outside forensic firm was engaged through outside counsel.
  4. May 21

    The company informed the FBI.
  5. May 26

    DentaQuest first published its notice of data breach on its website.
  6. May 29

    The company learned that the data had been posted on the dark web.
  7. July 16–17

    Filings with state attorneys general citing more than 15 million people; the company says it also notified the HHS Office for Civil Rights. Letters mailed from July 17.
  8. August 3

    Updated filing to the Washington AG: more than 27.4 million people nationwide; the review is ongoing.
27.4M+
People nationwide, per the company's August 3, 2026 update (first filing: 15M+)
3 days
Window of access (May 17–20, 2026)
1 employee
Tricked into giving credentials and an MFA code, per the filing
24 months
Free identity monitoring offered in the letters
What the company has disclosed
Who
DentaQuest LLC, which works with health plans to provide dental and vision benefits. Affected people include members, providers and others connected to DentaQuest, and people whose plan used to work with it
Data involved
Name, address, date of birth, Social Security number, member ID number, health plan number, Medicaid and Medicare numbers, and dental or vision health information (provider name, diagnosis, treatment, billing). Varies by person
How access happened (Washington filing)
A social engineering attack tricked a single employee into providing credentials and a multifactor authentication code. Data was taken from a network file share
What the investigation did not find
No evidence of other compromised accounts, malware or ransomware, privilege escalation or persistence; operating systems were not affected, according to the filing
Posted online
The letters say the individual's information was "accessed and posted on the internet"
Company measures
Enhanced security and monitoring controls, additional employee training, outside cybersecurity experts
Contact
(844) 959-7163, Mon–Fri 8:00 a.m.–5:30 p.m. Central Time

How to read the numbers

The count has grown as the review continued: more than 15 million in the July 16 filings, more than 27.4 million in the August 3 update, and the company says the review is ongoing. Other figures circulating online come from outside analyses or from the party that took the data; this article uses only the company's own filings. If you are a member and have not received a letter, that alone does not prove you were not included.

Why a code was not enough — and what does close the gap

The filing does not say which kind of MFA DentaQuest used, and this article does not guess. What it does say is enough for a general lesson: the second factor was something a person could give away.

Factors a person can hand over

  • Password (typed, can be read out)
  • SMS or app one-time code (six digits, can be read out or typed into the wrong page)
  • Push approval (one tap, can be approved for someone else)

Factors bound to the real site

  • Passkey (FIDO/WebAuthn, on a phone or computer)
  • FIDO2 security key (a physical key)
  • PKI smart card (certificate-based)

CISA's guidance ranks MFA from strongest to weakest and calls phishing-resistant MFA "the gold standard". It says the only widely available phishing-resistant form is FIDO/WebAuthn authentication, and it lists one-time-password apps as vulnerable to phishing. The difference is structural: a passkey or security key checks which website is asking before it answers, so there is no code for a person to read out and nothing to relay. How the options compare for your own accounts is covered in Choosing multi-factor authentication and What is a passkey?.

This site's view: the help desk is part of your MFA

Organizations often roll out passkeys and then leave a side door open: the process for resetting them. If someone who calls the help desk saying "I lost my phone" can get a new factor registered after answering questions whose answers are in a leaked file (name, date of birth, employee ID), the strong factor was never the real barrier. Treat the reset process as a login:

1. Verify outside the call. Hang up and call back on the number in the HR directory, or confirm through the employee's manager on a separate channel.
2. Never accept "knowledge" as proof. Anything in an HR or member file can leak. Use an in-person check, a video check against the badge photo, or an existing registered device.
3. Slow down high-risk resets. A new factor on an admin, finance or help-desk account triggers a notice to the user's other devices and their manager, plus a short hold before it becomes usable.
4. Start with the people who hold keys. Put phishing-resistant MFA on administrators, help-desk staff and anyone who can reach bulk data (such as a shared file store) first; CISA urges administrators and other high-value targets to move first.

For organizations that hold member or patient data

The filing says data was taken from a network file share. That detail is worth checking in your own environment, because file shares tend to collect exports and reports that nobody owns.

1

Find the bulk exports on shared drives

Search file shares and shared cloud folders for spreadsheets and exports that contain SSNs, member IDs or diagnosis codes. For each, ask: who needs this file, and could the same work be done inside the system of record, where access is logged and limited?

2

Alert on volume, not just on logins

A stolen login that passed MFA looks like a normal login. What stands out is how much one account reads. Set an alert on your file server or cloud storage audit log for one account reading far more files than its usual daily volume, and route it to someone who can suspend the account that day.

3

Plan the notification before you need it

DentaQuest mailed separate letters for adults, minors and deceased individuals, and its count grew as the data review went on. Decide in advance how you would identify people from a pile of files, and how you would reach people whose contact details are out of date. The broader baseline is in The minimum security baseline for organizations.

For another case where the way in was an employee being deceived, see the Carnival Corporation breach, which also involved passport numbers; for identity-document numbers leaking in Europe, see the Odido breach.

Sources (public record)

The facts in this article come from the public sources below. Figures and claims from the party that took the data, and outside estimates, are not used.

Update history

2026-09-30: First version, based on DentaQuest's notice (updated July 16, 2026), its filings with the Washington, California and Oregon regulators (including the August 3, 2026 update of more than 27.4 million people), and FTC, IRS, Medicare, HHS-OIG and CISA guidance. The company says its data review is ongoing; this article will be updated if the count changes.

FAQ

QWhat happened in the DentaQuest data breach?
A

DentaQuest says it discovered on May 20, 2026 that unauthorized individuals had accessed data on its computer network, and that the incident began on May 17 and ended by May 20, 2026. In its July 16, 2026 filing with the Washington State Attorney General, the company says the access resulted from a social engineering attack that tricked a single employee into providing credentials and a multifactor authentication code, and that data was taken from a network file share. The letters to affected people say their information was accessed and posted on the internet.

QHow many people were affected?
A

In its first filings on July 16, 2026, DentaQuest said it was aware of more than 15 million people nationwide (the Oregon Department of Justice lists 15,000,000). In an updated letter to the Washington State Attorney General dated August 3, 2026, the company said it was aware of more than 27.4 million people nationwide and that its review was ongoing. Higher or lower figures from other sources are not company figures.

QWhat information was exposed?
A

According to DentaQuest's notice and its state filing, the data varies by person and includes name, address, date of birth, Social Security number, member identification number, health plan number, Medicaid and Medicare numbers, and dental or vision health information such as provider name, diagnosis, treatment and billing information.

QWhat should I do if I got a DentaQuest letter?
A

Enroll in the free 24-month identity monitoring offered in the letter (the letter says you have 90 days from the mailing date), place a free credit freeze with Equifax, Experian and TransUnion, request an IRS Identity Protection PIN, and check your Explanation of Benefits statements for care you did not receive. If someone uses your Medicare number, call 1-800-MEDICARE; report other identity theft at IdentityTheft.gov.

QCan children be affected, and what can parents do?
A

DentaQuest filed separate notification letters for adults, minors and deceased individuals with the California Attorney General. The FTC says parents can request a free credit freeze for a child under 16, and the IRS says parents and guardians can request an IP PIN for dependents (children under 18 must use one of the alternative enrollment options).

QDidn't DentaQuest use multifactor authentication?
A

The company's filing says the employee was tricked into providing credentials and a multifactor authentication code. It does not say which kind of MFA was in use. The general lesson, reflected in CISA's guidance, is that one-time codes are vulnerable to phishing, while FIDO/WebAuthn authentication (passkeys and security keys) is the widely available phishing-resistant option.

QHow do I contact DentaQuest about the breach?
A

DentaQuest's dedicated call center is (844) 959-7163, Monday through Friday, 8:00 a.m. to 5:30 p.m. Central Time, excluding major US holidays. Only use the number printed in your letter or on DentaQuest's own website, not one given in an unexpected call or text.