AIO APEX

Abbott confirms cyber intrusion as ShinyHunters claims theft of millions of patient records

BleepingComputer
Share:
Abbott confirms cyber intrusion as ShinyHunters claims theft of millions of patient records

Abbott Laboratories has confirmed unauthorized access to internal systems in its Cancer Diagnostics business, after the ShinyHunters extortion gang added the healthcare giant to its data leak site and threatened to publish stolen data. The confirmed intrusion is one of two separate cyber incidents Abbott is now investigating simultaneously.

What Abbott has actually confirmed

Abbott acknowledged unauthorized access to what it described as "a limited number of internal systems in our Cancer Diagnostics business only," specifically legacy systems inherited from its Exact Sciences acquisition. The company stated the incident "does not impact any business operations, product or product availability, manufacturing or lab operations." Separately, Abbott confirmed it is aware of a "potential" incident involving its LabCentral customer portal, but disputed the severity of that claim, saying the portal "does not contain proprietary/sensitive customer or business information."

What ShinyHunters is claiming — and why it matters that it's unverified

ShinyHunters, a financially motivated extortion group with a track record of high-profile enterprise breaches, claims it gained initial access through a vishing (voice phishing) attack targeting Abbott employees in mid-June, ultimately compromising a Microsoft Entra single sign-on account. From there, the group claims it accessed and exfiltrated data from Microsoft Entra, ServiceNow, SharePoint, Databricks, and Coupa — a set of enterprise systems that, if true, would represent broad internal access well beyond a single diagnostics subsidiary.

The scale of the claimed theft is what makes this incident significant: ShinyHunters alleges it stole more than 30 million rows of customer personally identifiable information, over one million Social Security numbers, more than 22 million client notes containing doctor-patient conversations, and more than 20 million medical orders. It's important to note that these figures come entirely from the threat actor's own claims — security outlets covering the incident have explicitly stated they have not independently verified the scope of stolen data, and Abbott has not confirmed these specific figures.

The extortion deadline

ShinyHunters initially set a deadline of July 18 — today — to publish the allegedly stolen data unless Abbott negotiated payment, and has since extended that deadline to July 21. Extending a leak deadline is a common extortion tactic that can indicate ongoing negotiation, uncertainty about the data's leverage value, or simply pressure-testing the victim, and shouldn't be read as confirmation that a deal is close.

A second, separate incident

Compounding the situation, a second threat actor operating under the name ShadowByt3$ separately claims to have breached Abbott's Core Laboratory diagnostics business through its LabCentral customer portal, using compromised customer credentials, with an alleged access date of July 4. Unlike the ShinyHunters claim, ShadowByt3$ says the stolen material consists of manufacturing certificates, technical manuals, specifications, and regulatory documentation — not customer data. Abbott's public statement about LabCentral appears to address this second claim specifically.

Why this matters beyond Abbott

If even a fraction of ShinyHunters' claimed data set is accurate, this would rank among the more serious healthcare data incidents of 2026, given the sensitivity of doctor-patient clinical notes and the volume of Social Security numbers allegedly involved. ShinyHunters has targeted a string of enterprise cloud environments this year using similar social-engineering-to-SSO-compromise tactics, a pattern that underscores how a single compromised identity provider account can cascade into access across an organization's entire SaaS stack.

What to watch next

The July 21 deadline is the next concrete checkpoint — whether ShinyHunters follows through on publishing data, extends again, or goes quiet will say something about how credible its claims actually are. Abbott customers and patients affected by the Exact Sciences systems should watch for official breach notifications, which — under US state and federal breach disclosure law — would be required if Abbott confirms personal or health data was actually exfiltrated, regardless of what the company has said publicly so far.

Originally reported by BleepingComputer. Read the original article for additional details.

View original source
Share: