Vulnerabilities

Abbott Laboratories Probes Cyber Incidents Amid Extortion Claims

July 19, 2026 04:04 · 10 min read
Abbott Laboratories Probes Cyber Incidents Amid Extortion Claims

Abbott Laboratories, a leading healthcare company, is investigating two separate cybersecurity incidents after confirming unauthorized access to internal legacy Exact Sciences systems in its Cancer Diagnostics business. Additionally, the company is investigating a separate claim that attackers breached its LabCentral portal and stole company data.

Incident Response and Investigation

Abbott confirmed the Cancer Diagnostics incident after the ShinyHunters extortion gang added Abbott to its data leak site, initially threatening to publish allegedly stolen data after July 18 unless the company negotiated with the group. The deadline was later extended to July 21.

When asked about the alleged ShinyHunters incident, Abbott directed BleepingComputer to a statement published on its website. The company stated that it is investigating a cyber incident in which there was unauthorized access to a limited number of internal systems in its Cancer Diagnostics business only.

Impact and Response

Abbott added that the security incident has not impacted any other Abbott businesses or systems, and said the legacy Exact Sciences systems are separate from Abbott's. The company activated its incident response procedures after it learned of the incident, engaged cybersecurity experts, and notified law enforcement.

Abbott also stated that it does not expect the incident to have a material impact on its business or financial results. ShinyHunters claimed to BleepingComputer that it gained access through a vishing attack targeting several Abbott employees in mid-June.

ShinyHunters' Tactics and Targets

According to the threat actor, the attack allowed it to compromise a Microsoft Entra single sign-on (SSO) account and gain access to internal systems. Since last year, the extortion group has been conducting social engineering campaigns that target employees' Microsoft Entra, Okta, and Google SSO accounts.

After gaining access to a corporate SSO account, the threat actors steal data from connected SaaS applications such as Salesforce, Microsoft 365, Google Workspace, SAP, Slack, Adobe, Atlassian, Zendesk, Dropbox, and many others.

Alleged Data Stolen

ShinyHunters claimed to have exfiltrated data from Microsoft Entra, ServiceNow, SharePoint, Databricks, and Coupa, including internal documents, contracts, and customer information. The threat actor further claimed to have stolen more than 30 million rows of customer personally identifiable information (PII) from multiple datasets containing names, email addresses, phone numbers, physical addresses, dates of birth, and more than one million Social Security numbers.

The group also claimed to have stolen over 22 million client notes containing doctor-patient conversations, more than 20 million medical orders, and customer agreements and NDAs. BleepingComputer has not independently verified the threat actor's claims regarding the stolen data.

Alleged Breach at LabCentral Customer Portal

The second incident involves a threat actor known as ShadowByt3$, who contacted BleepingComputer claiming to have breached Abbott's Core Laboratory diagnostics business through its LabCentral customer portal. The threat actor said it breached the unit via its LabCentral customer portal using compromised customer credentials after identifying what it described as a 'weak point' in the environment.

According to the threat actor, they gained access on July 4, 2026, after which they slowly exfiltrated files by targeting API endpoints. ShadowByt3$ claims the stolen data includes CE manufacturing certificates, operation manuals, technical specifications, regulatory documentation, product requirement archives, calibrator value assignments, assay files, and other product documentation related to Abbott's laboratory diagnostic systems.

Abbott's Response to the Alleged Breach

Abbott confirmed to BleepingComputer that it is aware of the 'potential' cyber incident but disputed the threat actor's characterization of the data it claims to have stolen, stating that all data stored in the environment is public and not sensitive.

At this time, neither ShinyHunters nor ShadowByt3$ has publicly released data they claim to have stolen from Abbott.

As cybersecurity threats continue to evolve, it is essential for companies to prioritize their security measures and incident response plans to protect against such attacks.


Source: BleepingComputer

Source: BleepingComputer

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free