{"id":63790,"date":"2026-07-17T23:56:42","date_gmt":"2026-07-18T03:56:42","guid":{"rendered":"https:\/\/overcentral.com\/en\/?p=63790"},"modified":"2026-07-17T23:56:42","modified_gmt":"2026-07-18T03:56:42","slug":"abbott-cyber-incidents","status":"publish","type":"post","link":"https:\/\/overcentral.com\/en\/abbott-cyber-incidents\/","title":{"rendered":"Abbott Probes Two Cyber Incidents Amid Extortion Claims"},"content":{"rendered":"<p><a href=\"https:\/\/www.abbott.com\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">Abbott Laboratories<\/a> is currently investigating two separate cybersecurity incidents that have raised concerns about the security of patient data and sensitive business documents. The healthcare technology giant confirmed unauthorized access to internal legacy Exact Sciences systems within its Cancer Diagnostics business, while also probing a separate claim that attackers breached its LabCentral customer portal. The incidents come amid escalating extortion demands from known threat actor groups.<\/p>\n<h2>ShinyHunters Targets Abbott&#8217;s Legacy Exact Sciences Systems<\/h2>\n<p>The first incident came to light after the <a href=\"https:\/\/overcentral.com\/en\/shinyhunters-madison-square-garden-data-breach\/\" title=\"ShinyHunters Leaks Stolen Madison Square Garden Data\" data-iacss-internal=\"1\">ShinyHunters<\/a> extortion gang added Abbott to its data leak site. The group initially threatened to publish allegedly stolen data after July 18 unless the company negotiated, later extending the deadline to July 21. Abbott confirmed that unauthorized access occurred in a limited number of internal systems within its Cancer Diagnostics business only, involving legacy Exact Sciences platforms that are separate from Abbott&#8217;s core infrastructure.<\/p>\n<p>ShinyHunters claimed to have gained access through a vishing attack targeting several Abbott employees in mid-June. According to the threat actor, the social engineering campaign allowed them to compromise a Microsoft Entra single sign-on (SSO) account, which provided entry to internal systems. The group has been conducting similar social engineering campaigns since last year, targeting employees&#8217; Microsoft Entra, Okta, and Google SSO accounts to steal data from connected SaaS applications including Salesforce, <a href=\"https:\/\/overcentral.com\/en\/forg365-phishing-microsoft-365\/\" title=\"Forg365 AI Phishing Platform Targets Microsoft 365 Accounts\" data-iacss-internal=\"1\">Microsoft 365<\/a>, Google Workspace, SAP, Slack, Adobe, Atlassian, Zendesk, and Dropbox.<\/p>\n<p>Abbott stated that the incident does not impact any business operations, product availability, manufacturing, lab operations, or the ability to serve patients. The company activated its incident response procedures, engaged cybersecurity experts, and notified law enforcement. Abbott does not expect the incident to have a material impact on its business or financial results.<\/p>\n<h2>What Data Did ShinyHunters Allegedly Steal From Abbott?<\/h2>\n<p>ShinyHunters claimed to have exfiltrated data from Microsoft Entra, ServiceNow, SharePoint, Databricks, and Coupa, including internal documents, contracts, and customer information. The group further alleged the theft of more than 30 million rows of customer personally identifiable information (PII) containing names, email addresses, phone numbers, physical addresses, and dates of birth, along with more than one million Social Security numbers. Additionally, they claimed to have stolen over 22 million client notes containing doctor-patient conversations, more than 20 million medical orders, and customer agreements and NDAs. These claims have not been independently verified.<\/p>\n<p>The extortion gang has been increasingly targeting medtech companies, including Medtronic, OneMedical, and AdaptHealth, and was also behind the iRhythm <a href=\"https:\/\/overcentral.com\/en\/assuranceamerica-data-breach-exposes-6-9-million-drivers-license-numbers\/\" title=\"AssuranceAmerica Data Breach Exposes 6.9 Million Driver&amp;apos;s License Numbers\" data-iacss-internal=\"1\">data breach<\/a>. ShinyHunters targeted Stryker shortly after that company recovered from a destructive Iranian data-wiping attack.<\/p>\n<h2>Second Incident: LabCentral Portal Breach Alleged by ShadowByt3$<\/h2>\n<p>A separate threat actor operating under the name ShadowByt3$ contacted Abbott claiming to have breached the company&#8217;s Core Laboratory diagnostics business through the LabCentral customer portal. The threat actor said they gained access on July 4, 2026, using compromised customer credentials after identifying a weak point in the environment. They then exfiltrated files by targeting API endpoints.<\/p>\n<p>ShadowByt3$ claims the stolen data includes CE manufacturing certificates, operation manuals, technical specifications, regulatory documentation, product requirement archives, calibrator value assignments, and assay files. The group says no customer data was stolen but asserts that sensitive business documents and intellectual property were obtained. Screenshots and a file listing were provided as purported proof of the intrusion.<\/p>\n<p>Abbott confirmed awareness of the potential cyber incident but disputed the threat actor&#8217;s characterization of the stolen data, stating that all information stored in the LabCentral environment is public and not sensitive. LabCentral is an externally facing third-party hosted portal that houses publicly available technical product reference documents, including operating manuals, troubleshooting checklists, and product specifications. Neither ShinyHunters nor ShadowByt3$ has publicly released data they claim to have stolen from Abbott at this time.<\/p>\n<h2>What Affected Users Should Do Now<\/h2>\n<p>While Abbott has stated that the incidents do not affect business operations or patient care, individuals who have interacted with Abbott&#8217;s diagnostic services should remain vigilant. The alleged theft of Social Security numbers, medical records, and personal information poses a significant risk of identity theft and fraud. Anyone who believes their data may have been involved should monitor financial accounts and credit reports for unusual activity, place a fraud alert or credit freeze with major credit bureaus, and remain cautious of phishing attempts that may reference Abbott or Exact Sciences. Enabling multi-factor authentication on all accounts and using a reputable password manager with end-to-end encryption can help protect against credential-based attacks. For organizations, this incident underscores the critical importance of securing legacy systems, implementing robust SSO monitoring, and conducting regular security awareness training to defend against vishing and social engineering campaigns.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Abbott Laboratories is currently investigating two separate cybersecurity incidents that have raised concerns about the security of patient data and sensitive business documents. The healthcare technology giant confirmed unauthorized access to internal legacy Exact Sciences systems within its Cancer Diagnostics business, while also probing a separate claim that attackers breached its LabCentral customer portal. The [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":84145,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/63790.png","fifu_image_alt":"Abbott Probes Two Cyber Incidents Amid Extortion Claims","footnotes":""},"categories":[349],"tags":[],"class_list":["post-63790","post","type-post","status-publish","format-standard","has-post-thumbnail","category-articles"],"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/63790.png","fifu_image_alt":"Abbott Probes Two Cyber Incidents Amid Extortion Claims","_links":{"self":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/63790","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/comments?post=63790"}],"version-history":[{"count":0,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/63790\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media\/84145"}],"wp:attachment":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media?parent=63790"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/categories?post=63790"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/tags?post=63790"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}