Abbott Laboratories is currently investigating two separate cybersecurity incidents involving unauthorized access to its legacy Exact Sciences systems within the cancer diagnostics division. Additionally, the company is looking into claims regarding an attack on the LabCentral portal that resulted in the theft of corporate data.
After the ShinyHunters extortion group listed Abbott on their data breach site, the company acknowledged the Cancer Diagnostics incident and initially warned that the purportedly stolen data would be released after July 18 unless a negotiation occurred. This deadline was later extended to July 21.

Source: BleepingComputer
When asked about the ShinyHunters incident, Abbott directed inquiries to a statement available on their website.
“Abbott is investigating a cyber incident involving unauthorized access to a limited number of internal systems within our cancer diagnostics division only,” the company stated.
“This incident does not impact any ongoing business operations, products, or our ability to serve patients.”
Abbott emphasized that the security breach did not affect any of its other business sectors and noted that the legacy Exact Sciences system remains separate.
Upon discovering the incident, Abbott executed its incident response procedures, activated cybersecurity specialists, and notified law enforcement.
Mr. Abbott further indicated that he does not foresee any material impact on the company’s operations or financial results.
ShinyHunters claimed to BleepingComputer that they gained access through a targeted attack against several Abbott employees in mid-June. The attackers asserted that they compromised Microsoft Entra single sign-on (SSO) accounts, thereby gaining access to internal systems.
Since last year, various extortion groups have been executing social engineering tactics aimed at undermining employees’ Microsoft Entra, Okta, and Google SSO accounts.
After breaching corporate SSO accounts, threat actors typically extract data from connected SaaS platforms like Salesforce, Microsoft 365, Google Workspace, SAP, Slack, Adobe, Atlassian, Zendesk, and Dropbox.
The extortion group has increasingly targeted medical tech companies, including Medtronic, One Medical, and AdaptHealth. BleepingComputer also learned that ShinyHunters was involved in the iRhythm data breach and recently targeted Stryker after the company recovered from data erasure attacks originating from Iran.
When asked about the data allegedly stolen, ShinyHunters claimed to have obtained internal documents, contracts, customer data, and information from Microsoft Entra, ServiceNow, SharePoint, Databricks, and Coupa.
The attackers also claimed to have stolen over 30 million lines of customer personally identifiable information (PII), which includes names, email addresses, phone numbers, addresses, dates of birth, and over 1 million Social Security numbers.
The group further asserted that they secured more than 22 million customer notes, 20 million medical orders, along with various customer contracts and NDAs.
BleepingComputer has yet to independently verify the attackers’ claims regarding the stolen data.
Potential Compromise of LabCentral Customer Portal
The second incident involves a threat actor identified as ShadowByt3$, who reached out to BleepingComputer claiming to have infiltrated Abbott’s core lab diagnostics business via the LabCentral customer portal.
These attackers asserted that they utilized compromised customer credentials to breach the units through the LabCentral portal after identifying alleged vulnerabilities.
According to their claims, access was gained on July 4, 2026, with data being slowly exfiltrated through targeted API endpoints.
ShadowByt3$ stated that the stolen data includes CE manufacturing certificates, operational manuals, technical specifications, regulatory documents, product requirements archives, calibrator value assignments, assay files, and various product documentation related to Abbott’s laboratory diagnostic systems.
While the group claims no customer data was stolen, they did acquire confidential business documents and intellectual property. They also provided BleepingComputer with screenshots and a file list considered evidence of the intrusion.
Abbott acknowledged to BleepingComputer rumors of a “potential” cybersecurity incident but contested the attackers’ characterization of the stolen data, declaring that all data held in the environment is public and not confidential.
“LabCentral is a third-party hosted portal utilized by Abbott’s core clinical laboratory diagnostics business,” an Abbott spokesperson conveyed to BleepingComputer.
“The data stored includes publicly available technical product references such as operational manuals, troubleshooting checklists, and product specifications which do not contain sensitive customer or business information.”
As of now, neither ShinyHunters nor ShadowByt3$ has released the data they claim to have pilfered from Abbott.
Security teams document 54% of successful attacks yet only issue warnings in 14%. Most threats move unnoticed throughout systems.
Picus’ whitepaper outlines methods to test your SIEM and EDR rules using breach and attack simulations to expose overlooked threats.
Source: www.bleepingcomputer.com




