If you thought your medical records were safe, think again. The massive Abbott data breach crisis erupted this week after the extortion gang ShinyHunters claimed to steal tens of millions of records from the company’s Cancer Diagnostics business. This incident has drawn immediate attention due to the sheer scale of the theft. A second, completely unrelated hacker group is also claiming they breached Abbott’s LabCentral customer portal.
Abbott has confirmed unauthorized access occurred, but disputes the scale of what attackers claim to have taken, and says the incidents have not disrupted patient care, manufacturing, or business operations.
What ShinyHunters Claims to Have Stolen
ShinyHunters told security outlet BleepingComputer that it broke into Abbott’s systems through a vishing (voice phishing) attack targeting several employees in mid-June. The group claims this let it compromise a corporate Microsoft Entra single sign-on (SSO) account, which in turn gave it access to data across connected platforms including Salesforce, Microsoft 365, Google Workspace, SAP, ServiceNow, SharePoint, Databricks, and Coupa.
According to the group’s claims, the haul includes more than 30 million rows of customer personal data โ names, emails, phone numbers, physical addresses, dates of birth, and over 1 million Social Security numbers. ShinyHunters further claims to have taken more than 22 million client notes containing doctor-patient conversations, over 20 million medical orders, plus internal contracts and NDAs.
Keep one thing in mind: hackers haven’t actually published this data yet. Independent researchers haven’t verified a single row of it. ShinyHunters added Abbott to its dark web extortion site and threatened a July 18 leak, but quickly pushed the deadline to July 21. They might be bluffing to force a faster payout.
Abbott’s Official Response on the Exact Sciences Breach
In an official statement, Abbott confirmed unauthorized access to a limited number of internal systems within its Cancer Diagnostics business specifically. This Abbott Exact Sciences breach involves legacy infrastructure inherited through the company’s March 2026 acquisition of Exact Sciences, maker of the Cologuard and Cancerguard screening tests. Abbott says this legacy environment is separate from its core systems, and that the incident has not impacted product availability, manufacturing, lab operations, or patient care.
Abbott says it activated its incident response plan, engaged outside cybersecurity experts, and notified law enforcement. The company also stated it does not currently expect the incident to have a material impact on its financial results.
A Second, Separate Claim: The LabCentral Portal
A different threat actor, using the name ShadowByt3$, separately claims to have breached Abbott’s Core Laboratory diagnostics business through its LabCentral customer portal, allegedly using compromised customer credentials to exploit what it described as a weak point in the environment starting July 4, 2026.
This group claims to have taken manufacturing certificates, operating manuals, technical specifications, and regulatory documentation โ but says no customer data was involved. Abbott disputes the significance of this claim entirely, stating that LabCentral is an externally hosted portal containing only publicly available reference documents, not sensitive business or customer information.
Why ShinyHunters Keeps Targeting Healthcare Companies
This is far from ShinyHunters’ first attack on the medtech sector. The group has run a sustained campaign since last year specifically targeting employees’ Microsoft Entra, Okta, and Google SSO accounts through social engineering, and has previously been linked to breaches at Medtronic, OneMedical, AdaptHealth, iRhythm, and device maker Stryker โ the latter targeted just after it recovered from a separate destructive attack.
Healthcare and medtech companies remain attractive targets because a single compromised employee SSO login can act as a master key to dozens of connected SaaS platforms holding sensitive patient and business data โ often without triggering the kind of alarms a direct network intrusion would.
How to Stop Vishing-Based SSO Attacks
This attack didn’t happen because of a complex software bug. It happened because someone picked up a phone. Hackers called the IT help desk, impersonated an employee, and sweet-talked the technician into resetting a password. It really is that simple.
To stop this, companies have to rethink basic identity verification. Here is what actually works:
- Kill SMS Authentication: Text messages don’t cut it anymore. Hackers easily intercept them or talk users into reading the code aloud over the phone. Switch to FIDO2 hardware keys (like YubiKey) or Apple Passkeys immediately. A physical key cannot be read out loud to a scammer.
- Require Out-of-Band Help Desk Verification: If an employee calls IT asking for a password reset, the technician cannot just do it. They must send a push notification to the employee’s registered device or require manager approval first. This completely breaks the vishing kill-chain.
- Watch for Anomalous Bulk Exports: A compromised SSO account acts like a master skeleton key. Once hackers log in, they usually start dumping data from Salesforce, SharePoint, or Google Workspace at insane speeds. Security teams must configure anomaly detection to freeze accounts the second a massive data export begins.
- Isolate Legacy Acquisitions: Abbott inherited this vulnerable environment when they bought Exact Sciences. When your company buys another company, you buy their technical debt. Isolate those old servers from your core network on day one.
Frequently Asked Questions (FAQ)
Was I affected by the Abbott data breach?
Did you use a Cologuard test or have contact with Abbott’s Cancer Diagnostics division? If yes, your data might be in the massive pile of records ShinyHunters claims to hold. But remember: independent researchers haven’t seen the data yet. The hackers could be bluffing about the actual size of the theft.
Who is the ShinyHunters hacker group?
They are a notorious extortion gang. They don’t typically break through firewalls with advanced exploits. Instead, they run sustained social engineering campaigns. They call up employees, pretend to be IT support, and steal Microsoft Entra or Okta credentials. The group has previously been linked to breaches at Medtronic, OneMedical, AdaptHealth, iRhythm, and device maker Stryker using these exact tactics.
Has Abbott confirmed the full scope of the breach?
No. Abbott confirmed that hackers accessed a limited number of internal systems inside their Cancer Diagnostics unit as part of this Abbott data breach, but the company actively disputes the hackers’ claim of 30 million stolen records.
Is the separate LabCentral portal breach serious?
A second group named ShadowByt3$ claims they broke into Abbott’s LabCentral portal. Abbott says this portal only holds public manuals and technical specsโno sensitive customer or financial data. If true, this secondary breach poses zero risk to patients.
This Abbott data breach serves as a reminder of how a single compromised SSO account can expose enterprise-wide data across connected platforms.




