Abbott Laboratories Investigates Cybersecurity Incidents Amid Extortion Claims
Abbott Laboratories Investigates Cybersecurity Incidents Amid Extortion Claims 🚨
Abbott Laboratories is currently investigating two separate cybersecurity incidents following unauthorized access to internal legacy Exact Sciences systems in its Cancer Diagnostics business. Additionally, the company is looking into claims that attackers breached its LabCentral portal and stole company data.
The Cancer Diagnostics incident was confirmed after the ShinyHunters extortion gang added Abbott to its data leak site, initially threatening to publish allegedly stolen data after July 18 unless the company negotiated with them. The deadline was later extended to July 21. Abbott stated, “This does not impact any business operations, product or product availability, manufacturing or lab operations, or our ability to serve patients.”
Details of the Incidents 🔍
ShinyHunters claimed to have accessed Abbott’s systems through a vishing attack targeting several employees in mid-June. This attack allowed them to compromise a Microsoft Entra single sign-on (SSO) account, gaining access to internal systems. The group has been conducting social engineering campaigns targeting employees’ SSO accounts, leading to the theft of data from various SaaS applications.
According to ShinyHunters, they exfiltrated over 30 million rows of customer personally identifiable information (PII), including names, email addresses, phone numbers, physical addresses, dates of birth, and more than one million Social Security numbers. They also claimed to have stolen over 22 million client notes containing doctor-patient conversations and more than 20 million medical orders.
The second incident involves a threat actor known as ShadowByt3$, who claimed to have breached Abbott’s Core Laboratory diagnostics business through its LabCentral customer portal using compromised customer credentials. They gained access on July 4, 2026, and allegedly exfiltrated files by targeting API endpoints. Abbott confirmed awareness of this potential cyber incident but disputed the claims regarding the data that was supposedly stolen, stating that all data stored is public and not sensitive.
For more details, you can read the full article here: Read full article