Skip to content
The Cybersecurity Focus
The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

  • Home
  • Home
The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

  • Home
  • Home
BreachHackIncident

Abbott Laboratories Double Cyber Incident: ShinyHunters Claims PII Records Stolen in Vishing Attack

By ogwatermelon
July 20, 2026 5 Min Read
0
July 19, 2026

Abbott Laboratories, one of the world’s largest medical technology companies, is investigating two separate cybersecurity incidents disclosed this week. One involves the ShinyHunters extortion gang, which claims to have stolen more than 30 million rows of customer personally identifiable information. The second involves a separate threat actor who allegedly breached Abbott’s LabCentral customer portal.

What Happened: Abbott Laboratories Hit by Two Cyber Incidents in One Week

On July 17, 2026, Abbott confirmed unauthorized access to internal legacy Exact Sciences systems within its Cancer Diagnostics business. This disclosure followed pressure from the ShinyHunters extortion group, which added Abbott to its data leak site and threatened to publish stolen data unless the company negotiated.

Separately, a threat actor known as ShadowByt3$ contacted journalists claiming to have breached Abbott’s Core Laboratory diagnostics business through its LabCentral customer portal. Abbott has acknowledged this second incident as a “potential” breach but disputes the severity of the data involved.

ShinyHunters told BleepingComputer that it gained initial access through a vishing attack targeting several Abbott employees in mid-June. Furthermore, the group claimed it compromised a Microsoft Entra single sign-on account, which opened access to a broad swath of internal systems and cloud applications.

Technical Details of the Abbott Cancer Diagnostics Breach

The ShinyHunters attack leveraged social engineering at its entry point. The threat actor used voice phishing to trick Abbott employees into surrendering credentials. Once inside, the group exploited a Microsoft Entra SSO account to move laterally across cloud-connected services.

ShinyHunters has refined this playbook over the past year. The group routinely targets employees’ SSO accounts at Microsoft Entra, Okta, and Google. After gaining access, it steals data from connected SaaS applications. This tactic has proven effective against medtech firms, including Medtronic, OneMedical, AdaptHealth, and iRhythm.

The group claims to have exfiltrated data from multiple platforms connected to Abbott’s Cancer Diagnostics environment:

  • Microsoft Entra – SSO identity and access data
  • ServiceNow – Internal IT and service records
  • SharePoint – Document repositories and contracts
  • Databricks – Analytics and data processing platforms
  • Coupa – Procurement and vendor management data

ShinyHunters alleges the stolen data includes internal documents, contracts, and customer information. The group further claims more than 30 million rows of customer PII, including names, email addresses, phone numbers, physical addresses, dates of birth, and over one million Social Security numbers. Additionally, the group says it stole more than 22 million client notes containing doctor-patient conversations, over 20 million medical orders, and customer agreements.

It is important to note that BleepingComputer has not independently verified the threat actor’s claims regarding the scope of stolen data.

Technical Details of the LabCentral Portal Incident

The second incident involves a separate threat actor, ShadowByt3$, who claims to have breached Abbott’s LabCentral customer portal on July 4, 2026. The attacker says it used compromised customer credentials after identifying what it described as a “weak point” in the environment.

According to ShadowByt3$, the group slowly exfiltrated files by targeting API endpoints over time. The stolen data allegedly includes CE manufacturing certificates, operation manuals, technical specifications, regulatory documentation, product requirement archives, calibrator value assignments, assay files, and other product documentation related to Abbott’s laboratory diagnostic systems.

However, Abbott disputes the severity of this incident. A spokesperson told BleepingComputer that LabCentral is an externally facing third-party hosted portal. The company stated that all data stored in the environment is publicly available technical product reference material, including operating manuals and troubleshooting checklists. Abbott emphasized that the portal does not contain proprietary, sensitive customer, or business information.

Business and Operational Impact

The Abbott incidents carry significant implications for the healthcare and medical technology sectors. The alleged scale of the ShinyHunters breach, if verified, would rank among the largest healthcare data exposures of 2026.

Immediate business impacts include:

  • Patient trust erosion: Healthcare data breaches directly undermine patient confidence in providers and vendors.
  • Regulatory scrutiny: Abbott faces potential HIPAA and FDA oversight investigations, especially if protected health information was exposed.
  • Financial exposure: The company said it does not expect material financial impact, but legal costs and potential settlements could mount.
  • Operational continuity: Abbott stated the Cancer Diagnostics incident does not impact manufacturing, lab operations, or product availability.
  • Vendor risk questions: The LabCentral incident raises concerns about third-party portal security and credential management.

The ShinyHunters extortion deadline was initially set for July 18, then extended to July 21. At the time of publication, neither group has publicly released data.

Mitigation and Recommendations

Organizations in healthcare and medtech should treat the Abbott incidents as a wake-up call. Threat actors are increasingly targeting SSO accounts and SaaS applications with social engineering at the entry point.

Immediate Actions for Defenders

  1. Strengthen SSO protections: Enforce phishing-resistant MFA on all identity providers, especially Microsoft Entra, Okta, and Google Workspace.
  2. Review SaaS app permissions: Audit connected third-party applications and revoke unnecessary OAuth grants and API permissions.
  3. Monitor for vishing indicators: Train employees to verify unexpected calls requesting credentials or MFA codes.
  4. Restrict lateral movement: Segment cloud environments so a single compromised SSO account cannot access every system.
  5. Hunt for suspicious API access: Look for anomalous API endpoint access patterns, especially from unfamiliar IP ranges or at unusual hours.

Long-Term Strategic Recommendations

Furthermore, organizations should invest in continuous SaaS security posture management. ShadowByt3$ claims it found a “weak point” in the LabCentral environment, which suggests basic security hygiene gaps. Regular third-party risk assessments, credential monitoring, and API security testing can close these gaps before attackers exploit them.

For healthcare entities specifically, compliance with HIPAA Security Rule requirements around access controls, audit logs, and risk analysis is not optional. These controls are the frontline defense against the exact tactics ShinyHunters employed.

Bottom line: Threat actors are bypassing perimeter defenses by targeting the humans who hold the keys. A single vishing call can cascade into a multi-system breach. Train your people, harden your identity stack, and monitor your SaaS connections like they are your network perimeter. Because to attackers, they are.

Incident Summary

Incident: Abbott Laboratories Double Cyber Incident
Threat Actor(s): ShinyHunters (Cancer Diagnostics); ShadowByt3$ (LabCentral)
Target: Abbott Laboratories Cancer Diagnostics and Core Laboratory businesses
Attack Vector: Vishing / SSO compromise (ShinyHunters); Compromised customer credentials (ShadowByt3$)
Disclosure Date: July 17, 2026
Claimed Data Exposed: 30M+ PII rows, 22M+ client notes, 20M+ medical orders, business documents
Patch Status: N/A – Incident response and law enforcement engaged
Verified by Victim: Cancer Diagnostics breach confirmed; LabCentral incident under investigation

References

  1. Lawrence Abrams, BleepingComputer, “Abbott probes two cyber incidents amid extortion claims,” July 17, 2026, https://www.bleepingcomputer.com/news/security/abbott-laboratories-probes-two-cyber-incidents-amid-extortion-claims/ (accessed July 19, 2026).
  2. Microsoft Security Blog, “ACR Stealer: Two observed intrusion chains amid increased threat activity,” July 16, 2026, https://www.microsoft.com/en-us/security/blog/2026/07/16/acr-stealer-two-observed-intrusion-chains-amid-increased-threat-activity/ (accessed July 19, 2026).
  3. Abbott Laboratories, “Abbott Statement on Cyber Incident in Cancer Diagnostics Business,” July 2026, https://www.abbott.com/en-us/corpnewsroom/diagnostics-testing/abbott-statement-on-cyber-incident-in-cancer-diagnostics-business (accessed July 19, 2026).

Tags:

BreachExploitHack
Author

ogwatermelon

Follow Me
Other Articles
Previous

wp2shell WordPress Core RCE: CVEs Enable Unauthenticated Code Execution

Next

HelloNet APT Campaign Abuses ViPNet Update System

AI Botnet Breach CVE Exploit Hack Incident Linux Malware Network Ransomware supply chain Vulnerability Windows World Zero Day

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

Archives

  • July 2026
  • June 2026
  • May 2026

Categories

  • AI
  • BotNet
  • Breach
  • CVE
  • exploit
  • Hack
  • Incident
  • Linux
  • Malware
  • Phishing
  • Ransomware
  • supply-chain
  • Uncategorized
  • Vulnerability
  • Windows
  • World
  • Zero Day
Copyright 2026 — The Cybersecurity Focus. All rights reserved.