Abbott Laboratories is investigating two separate cybersecurity incidents after confirming unauthorized entry to the corporate’s legacy Actual Sciences methods in its most cancers diagnostics enterprise. The corporate can also be investigating one other declare that attackers breached the corporate’s LabCentral portal and stole company knowledge.
After the ShinyHunters extortion group added Abbott to the corporate’s knowledge breach web site, the corporate acknowledged the Most cancers Diagnostics incident and initially threatened to launch the allegedly stolen knowledge after July 18th until the corporate negotiated with the group, however later prolonged that deadline to July twenty first.

Supply: BleepingComputer
When BleepingComputer requested Abbott in regards to the alleged ShinyHunters incident, Abbott directed BleepingComputer to an announcement revealed on its web site.
“Abbott is investigating a cyber incident by which there was unauthorized entry to a restricted variety of inside methods inside its most cancers diagnostics enterprise solely,” the corporate mentioned.
“This doesn’t affect any enterprise operations, merchandise or product availability, manufacturing or testing operations, or our means to serve sufferers.”
Abbott added that the safety incident didn’t affect any of Abbott’s different companies or methods, and famous that the legacy Actual Sciences system is separate from Abbott’s.
The corporate mentioned that after studying of the incident, it initiated incident response procedures, dispatched cybersecurity specialists and notified regulation enforcement.
Mr. Abbott additionally mentioned he doesn’t anticipate the incident to have a cloth affect on the corporate’s operations or monetary outcomes.
ShinyHunters claimed to BleepingComputer that it gained entry via a malicious assault that focused a number of Abbott workers in mid-June. Based on the attackers, the assault compromised Microsoft Entra single sign-on (SSO) accounts and gained entry to inside methods.
Since final yr, extortion teams have been operating social engineering campaigns concentrating on workers’ Microsoft Entra, Okta, and Google SSO accounts.
After getting access to company SSO accounts, risk actors steal knowledge from linked SaaS functions comparable to Salesforce, Microsoft 365, Google Workspace, SAP, Slack, Adobe, Atlassian, Zendesk, and Dropbox.
The extortion group has more and more focused medical expertise firms comparable to Medtronic, One Medical, and AdaptHealth. BleepingComputer has discovered that ShinyHunters was additionally concerned within the iRhythm knowledge breach and focused Stryker shortly after the corporate recovered from Iran’s devastating knowledge erasure assault.
When requested what knowledge was allegedly stolen, ShinyHunters claimed to have stolen inside paperwork, contracts, buyer data, and different knowledge from Microsoft Entra, ServiceNow, SharePoint, Databricks, and Coupa.
Moreover, the attackers claimed to have stolen greater than 30 million traces of buyer personally identifiable data (PII) from a number of datasets, together with names, e mail addresses, cellphone numbers, addresses, dates of delivery, and over 1 million Social Safety numbers.
The group additionally claimed to have stolen greater than 22 million buyer notes, together with doctor-patient conversations, and greater than 20 million medical orders, in addition to buyer contracts and NDAs.
BleepingComputer has not independently verified the attacker’s claims concerning stolen knowledge.
Suspected Compromise in LabCentral Buyer Portal
The second incident concerned a risk actor often known as ShadowByt3$ who contacted BleepingComputer and claimed to have compromised Abbott’s core lab diagnostics enterprise via the LabCentral buyer portal.
The attackers mentioned they used compromised buyer credentials to infiltrate the models through the LabCentral buyer portal after figuring out alleged “weak factors” within the surroundings.
Based on the attackers, they gained entry on July 4, 2026, after which slowly exfiltrated recordsdata by concentrating on API endpoints.
ShadowByt3$ claims that the stolen knowledge contains CE manufacturing certificates, working manuals, technical specs, regulatory paperwork, product necessities archives, calibrator worth assignments, assay recordsdata, and different product documentation associated to Abbott’s laboratory diagnostic methods.
The group says no buyer knowledge was stolen, however that it did get hold of confidential enterprise paperwork and mental property. In addition they offered BleepingComputer with screenshots and an inventory of recordsdata which are mentioned to be proof of the intrusion.
Abbott confirmed to BleepingComputer that the corporate is conscious of a “potential” cyber incident, however disputed the attacker’s characterization of the info the corporate claims was stolen, saying all knowledge saved inside the surroundings is public and never confidential.
“LabCentral is an externally going through third-party hosted portal utilized by Abbott’s core medical laboratory diagnostics enterprise,” an Abbott spokesperson advised BleepingComputer.
“Publicly out there technical product references comparable to working manuals, troubleshooting checklists, and product specs are saved and don’t include delicate buyer or enterprise data.”
At the moment, neither ShinyHunters nor ShadowByt3$ have launched the info they declare to have stolen from Abbott.
Safety groups doc 54% of profitable assaults and challenge a warning on solely 14%. The remainder strikes invisibly via the surroundings.
Picus’ whitepaper reveals learn how to take a look at your SIEM and EDR guidelines in breach and assault simulations to make sure threats go undetected.
Get the white paper
