25% off all training courses Offer ends July 30, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends July 30, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Abbott Investigating Cyberattack Claims From Two Threat Actors

The healthcare giant Abbott is investigating claims from two threat groups who allege cyberattacks and data theft, one involving legacy Exact Sciences systems of its cancer diagnostics business, and another involving its LabCentral portal.

Abbott acquired Exact Sciences in late 2025, a company specializing in cancer screening and precision oncology diagnostics. The acquisition allowed the company to enter the fast-growing cancer diagnostics market. Abbott has yet to confirm the extent to which patient data has been compromised but has confirmed unauthorized access to certain legacy cancer diagnostics systems. The intrusion did not impact any other Abbott businesses, and had no impact on its business operations, products, product availability, manufacturing/lab operations, or its ability to serve patients. The impacted Exact Sciences systems are separate from Abbott’s systems. In a July 16, 2026, announcement, Abbott said it does not anticipate the incident having any material impact on the business or its financial results.

The ShinyHunters data theft and extortion group claimed responsibility for the attack and threatened to publish the stolen data if payment was not made. Abbott negotiated with the group, and the publication deadline was extended to July 21, 2026. It is currently unclear if payment has been made, and as of July 20, 2026, the stolen data has not been leaked.

ShinyHunters often compromises victims’ systems through voice phishing (vishing) and appears to have used those tactics in this attack. Bleeping Computer reports that it received communications from a ShinyHunters spokesperson stating vishing attacks were conducted on Abbott employees in mid-June, which allowed the group to compromise a Microsoft Entra single sign-on account that provided access to certain internal systems. The group claims to have exfiltrated 30 million rows of customer data, including names, contact information, dates of birth, and one million Social Security numbers.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

An investigation has also been launched into a separate claim from a hacker with the moniker ShadowByt3$. This separate attack, so the hacker claims, involved unauthorized access to the Abbott core business via the LabCentral customer portal. The threat actor claims to have gained access on July 4, 2026, using compromised customer credentials, exfiltrating data over the weekend, although no customer or patient data was compromised. Abbott maintains that the third-party hosted portal does not contain sensitive data, only publicly available, non-sensitive data, such as technical product reference documents including operating manuals, product specifications, and troubleshooting checklists.

Abbott is one of several medtech companies to announce cyberattacks and data breaches in recent months, including Stryker, Medtronic, iRhythm, AdaptHealth, and Intuitive.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist