top of page
Untitled design (1).png

Two Attackers, One Cancer Diagnostics Business: The Abbott Breach Explained

  • Writer: Syed Adnaan
    Syed Adnaan
  • Aug 13
  • 2 min read

On July 16, 2026, healthcare giant Abbott Laboratories confirmed it was investigating unauthorized access to legacy systems belonging to Exact Sciences — the cancer-diagnostics company behind Cologuard, which Abbott acquired for $20.6 billion in March 2026, just twelve weeks before the intrusion began.


How attackers got in

Abbott traced the breach to a vishing (voice phishing) attack against Abbott and Exact Sciences employees in mid-June 2026. In a now-familiar pattern, ShinyHunters gang members called employees while posing as internal IT support, telling targets their MFA settings needed updating. Employees who complied handed over their Microsoft Entra single sign-on credentials and MFA codes directly to the attackers. Microsoft’s own security research, published July 13, 2026, documented ShinyHunters’ custom phishing infrastructure — modular landing pages that adapt in real time depending on whether a victim uses Google, Microsoft, or another SSO provider.


What was allegedly taken

ShinyHunters claims to have exfiltrated data from Microsoft Entra, ServiceNow, SharePoint, Databricks, and Coupa, including:


  • Over 30 million rows of customer personal data (names, emails, phone numbers, addresses, dates of birth)

  • More than 1 million U.S. Social Security numbers

  • Over 22 million doctor-patient conversation notes

  • More than 20 million medical orders

  • Internal contracts and NDAs


Abbott has confirmed unauthorized access to a limited number of internal systems within its Cancer Diagnostics business but has disputed some of the framing and has not independently verified the attacker’s specific figures. ShinyHunters initially threatened to leak the data after July 18, then extended the deadline to July 21. When Abbott reportedly declined to pay, the group published a batch of the data — Have I Been Pwned logged 10.9 million unique email addresses from the leak, alongside health and personal information.


A second, unrelated attacker

Complicating matters, a separate threat actor calling itself ShadowByt3$ claimed a second, unrelated breach of Abbott’s Core Laboratory business via its LabCentral customer portal, allegedly using compromised customer credentials starting July 4, 2026. Abbott maintains that portal only holds publicly available technical documentation — operating manuals and product specifications — not sensitive data.


Why it matters

This incident is a clean case study in acquisition risk: the compromised systems weren’t Abbott’s own infrastructure — they were legacy Exact Sciences systems inherited through a deal closed less than three months earlier. Newly acquired environments are frequently under-integrated into a parent company’s security stack, and that gap is exactly what attackers look for.


Key takeaways for healthcare and M&A teams: - Treat newly acquired IT environments as high-risk until they’re fully integrated into your identity and monitoring stack — not after. - Vishing continues to bypass standard MFA. Verification protocols that don’t rely on a phone call being trustworthy are essential for privileged accounts. - Medical and health data carries permanent identifiers that can’t be reissued the way a credit card number can — treat health record exposure as a higher-severity event than typical PII loss.


Sources: BleepingComputer, HIPAA Journal, The Register, and Abbott’s public statements.




 
 
 

Recent Posts

See All

Comments


bottom of page