Desk live·
ForensicPost
Breaches/Healthcare/File 26-0612

DentaQuest Data Published After Extortion Demand Refused

DentaQuest declined to meet an extortion demand and the data was published — around 234 GB, with 2.6 million unique email addresses verified. The file documents what the other branch of that decision looks like.

Constructed geometry · not a chart of case data
TargetDentaQuest
ActorShinyHunters
S. Rosler10 min readConfidence: medium2 sources reviewed

DentaQuest, a dental benefits administrator, was compromised in a campaign beginning around May 2026. When extortion did not succeed, roughly 234 GB was published, with about 2.6 million unique email addresses subsequently verified within it.

We filed the opposite outcome in 26-0501, where a payment was made and deletion logs supplied. Setting the two side by side is the closest this desk gets to a controlled comparison, and it is worth being careful about what it shows.

What Refusal Actually Costs

Publication is the outcome the organisation was trying to avoid, and it is permanent in a way the alternative is not: once an archive is public it is mirrored, indexed and traded, and no subsequent decision reverses it.

It also produces something payment does not — a verifiable record. Independent parties were able to establish 2.6 million unique addresses in the published data. In the paid case, nobody outside the negotiation knows what was taken or whether it was destroyed.

The Comparison Does Not Yield A Recommendation

It would be convenient to conclude that refusing is right because it produces honesty, or that paying is right because it prevents publication. Neither follows. The organisations faced different data, different regulators and different obligations.

What the pair does establish is narrower and, we think, more useful: the affected people learn substantially more when the organisation refuses. Payment buys the possibility of suppression and guarantees that nobody outside the room ever finds out what was in the archive.

Graded medium. The volume and verified address count are consistently reported; the intrusion route has not been established.

How we reported this

Compiled from public reporting, listed below. We did not access the published data; the verified address count is as reported by the researchers who examined it. We do not describe the contents of leaked archives. Corrections: corrections@forensicpost.com.

Sources
  1. List of recent data breaches in 2026Bright Defense
  2. Data breach news — recent data breaches in 2026Breachsense
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary