Abbott Laboratories is investigating two separate cybersecurity incidents after the ShinyHunters extortion gang and a second threat actor known as ShadowByt3$ both claimed to have breached the healthcare giant’s systems.
Abbott confirmed unauthorized access to legacy Exact Sciences systems in its Cancer Diagnostics business, stating the incident did not impact operations, manufacturing, or patient care. The legacy systems are separate from Abbott’s core infrastructure.
ShinyHunters told BleepingComputer it gained access through a vishing campaign targeting Abbott employees in mid-June, compromising a Microsoft Entra single sign-on account. The group claims to have exfiltrated 30 million rows of customer data, including one million Social Security numbers, 22 million doctor-patient notes, and 20 million medical orders.
Abbott negotiated with ShinyHunters, which extended its leak deadline to July 21. The second incident involves ShadowByt3$, which claims to have breached Abbott’s LabCentral customer portal using compromised credentials. Abbott said the portal contains only publicly available technical reference documents.
ShinyHunters has increasingly targeted medtech companies, including Medtronic, iRhythm, and AdaptHealth. As of this writing, neither group has publicly released stolen data.
