Cybersecurity Girl Weekly Drop
Cyber news, tools & one smart career path.
5 min read

Quick Reality Check
DentaQuest, a major dental benefits administrator, is notifying nearly 15 million people after hackers broke into its systems and stole sensitive health and personal data
What happened:
DentaQuest, a subsidiary of Sun Life, manages dental benefits for about 32 million Americans on Medicaid and CHIP. In May, hackers broke into their systems over three days and walked out with 234 gigabytes of data.
That includes names, dates of birth, gender, email and physical addresses, phone numbers, Social Security numbers, government‑issued IDs, dental and vision insurance details such as member IDs and provider names, diagnoses, treatments, billing information, plus Medicaid and Medicare numbers. At least 15 million people are affected.
DentaQuest began mailing breach notices on July 17, separately addressing adults and parents of impacted minors. While the company says around 15 million people are affected, an independent researcher analyzing the leaked data estimated the number could rise above 23.4 million, with about 1.7 million unique Social Security numbers, most of them appearing to belong to children, and some records dating back to 2009.
Why it matters:
This is basically a complete identity kit. Names, dates of birth, Social Security numbers, government-issued IDs, physical addresses, phone numbers, emails. A criminal doesn't need all of these to destroy someone's financial life. They need maybe three or four. This breach hands them everything on a silver platter.
The health data makes it uniquely dangerous. Dental and vision insurance info, member IDs, diagnoses, treatments, billing records, Medicaid and Medicare numbers. That's not just fuel for identity theft. That's medical identity theft, where someone uses your information to get treatments, prescriptions, or file fake insurance claims in your name. Cleaning up medical identity theft is significantly harder than financial fraud because health records are fragmented across providers and insurers.
Children's records dating back to 2009 mean some of these kids are now teenagers or young adults who may have never checked their credit. Their clean SSNs could have been used for years without anyone noticing.
Read more here
60-Second Protection Fix
Here is what you can do:
-
Freeze your credit: Go to annualcreditreport.com on your phone or computer and click through to the three major bureaus (Equifax, Experian, and TransUnion). It is completely free by federal law and takes about 10 minutes total. A freeze blocks anyone from opening new credit cards or loans in your name, even if they have your Social Security number. Save the PINs they give you in case you need to lift the freeze later
-
Watch your physical mail: DentaQuest is mailing notification letters to affected individuals (or to parents/guardians if the patient was a minor). When it arrives, do not ignore it. Open it and follow the instructions to enroll in the 24 months of free identity monitoring they are providing.
-
Watch for phishing attacks. After a breach like this, scammers will send emails and texts pretending to be the dental company, an insurer, or even a government agency. They'll create urgency, like "verify your account immediately." Take a deep breath before clicking anything. Ask yourself: is this urgent? What's my gut saying?
-
If you have kids affected: Do the same steps for them. Watch their credit like a hawk. You can place a credit freeze on a minor's account too.
How many alerts did you ignore today?
Every tool claims they can handle the volume. But when put to the test, most just suppress what they can't keep up with. TENEX.ai is built differently: it triages at scale and investigates every alert in under a minute. This is what Fully-Agentic, Human-Led SecOps looks like.
*Sponsored by TENEX AI
What You Missed This Week
What I do as a cybersecurity influencer…
12 things I no longer do as a cybersecurity expert
Check all 12 here
OpenAI broke into a real company last week, and nobody told it to…
Here I explain to you what happened
Let’s keep building together!
Stay protected,
Cybersecurity Girl
Know someone who’d enjoy this? Pass it along and have them sign-up here! And if you have thoughts or feedback, just hit reply, I’d love to hear from you.




Responses