It feels like there’s a new major data breach making the news every week, and unfortunately, many involve organizations entrusted with some of our most sensitive personal information. In this second edition of our In the News security series, we’re taking a look at three more recent breaches that made headlines and exploring why they matter. If you missed Volume 1, check it out!
#1. DentaQuest
Millions of Americans trust DentaQuest to manage sensitive dental and vision benefits information, making this breach particularly concerning. In May 2026, the company disclosed that cybercriminals gained access to its computer network, stealing approximately 234GB of data, impacting more than 15 million individuals. The attackers reportedly had access to company systems for several days before the breach was discovered and contained.
Why It Matters (Severity: Critical)
What makes this incident especially serious is the type of information involved. According to DentaQuest, the exposed data may include names, addresses, Social Security numbers, Medicare and Medicaid identifiers, member ID numbers, and dental and vision treatment information. When criminals obtain both personal identifiers and healthcare information, victims face a greater risk of identity theft and targeted scams. Unlike a password that can be changed, personal and medical information often remains valuable to attackers for years! This is why healthcare information is such a hot commodity to cybercriminals.
#2. Washington Department of Social and Health Services (DSHS)
Not every data breach is caused by an outside hacker. Sometimes the threat comes from within an organization, a risk known as an insider threat. A recent incident involving Washington DSHS highlights this danger. The agency reported that approximately 8,600 individuals may have had personal information improperly accessed by a DSHS employee who accessed an internal client data system without a legitimate business reason. This case serves as a reminder that insider threats, whether intentional or accidental, can expose sensitive data and pose significant risks to organizations and the people they serve.
Why It Matters (Severity: High)
The information involved included names, dates of birth, Social Security numbers, and DSHS client identification numbers. While the investigation found no evidence that detailed medical information were accessed, the exposure of sensitive personal identifiers is still significant. Insider incidents can be difficult to detect because authorized employees already have access to internal systems. However, just because an employee can access information, does not mean it can be viewed or used without a legitimate business need. DSHS stated that the employee was terminated and that affected individuals are being notified.
#3. Unlimited Technology Solutions (UTS)
Unlimited Technology Solutions (UTS), a healthcare software development company, recently confirmed that a 2025 cyberattack affected nearly 3.8 million individuals. Although the incident occurred in October 2025, the full scope of the breach was not known until a lengthy review of the compromised data was completed this year.
Why It Matters (Severity: Critical)
The investigation revealed that a wide range of personal and healthcare-related information may have been exposed, including names, addresses, email addresses, phone numbers, Social Security numbers, dates of birth, health insurance details, patient balances, and limited medical information. Some scanned identification documents, including driver’s licenses and government-issued IDs may also have been affected. While UTS stated that complete medical records, medical images, and financial account information were not involved, the combination of personal identifiers and healthcare data still creates substantial risks. Criminals frequently use this type of information for identity theft and highly convincing phishing attacks.
Data breaches aren’t going away anytime soon, so staying alert and informed about current threats can go a long way. Thanks for reading and keep an eye out for Volume 3 of In the News for more cybersecurity data breach updates!
Stay safe, stay Securus!



