Abbott Laboratories is investigating two separate cyber incidents involving its Cancer Diagnostics business and LabCentral portal.
The ShinyHunters hacking group claims it stole medical, customer, and internal business data from Abbott. Meanwhile, another group says it accessed technical documents through the company’s LabCentral portal.
However, Abbott says the two Abbott cyber incidents are unrelated. The healthcare company also reports no disruption to its customers, products, operations, or financial performance.
ShinyHunters Claims Abbott Data Breach
Abbott disclosed unauthorized access to a limited number of internal systems within its Cancer Diagnostics business on July 16.
According to the company, the incident did not affect its other businesses, products, or operations. Furthermore, legacy Exact Sciences systems remained separate from the affected environment.
Abbott inherited those systems when it acquired the Exact Sciences cancer diagnostics business. Therefore, the company says attackers could not access them through the compromised Abbott systems.
ShinyHunters later added Abbott to its data leak site. The group initially threatened to publish the allegedly stolen information on July 18. However, it later moved the deadline to July 21.
No data connected to the alleged breach has been published so far.
Attackers Allegedly Compromised Employee Accounts
ShinyHunters claims it gained access to Abbott through a voice phishing attack in mid-June.
During the alleged attack, the hackers targeted several employees. They reportedly compromised a corporate Microsoft Entra single sign-on account and used it to enter connected applications.
The group claims it stole internal documents, contracts, customer agreements, and nondisclosure agreements. In addition, it says the stolen material includes more than 22 million doctor-patient notes and over 20 million medical orders.
ShinyHunters also claims it obtained customer names, email addresses, telephone numbers, physical addresses, and dates of birth. Moreover, the group alleges that the data contains more than one million Social Security numbers.
Abbott has not confirmed those claims. The company also does not expect the incident to have a material effect on its business or financial results.
Separate Group Targets LabCentral Portal
A second hacking group, known as ShadowByt3$, has claimed responsibility for another incident involving Abbott.
The group says it accessed the company’s LabCentral portal on July 4. LabCentral provides customers with reference materials for Abbott’s core laboratory diagnostic products.
According to the attackers, they entered the portal using compromised customer credentials and a weakness in the environment.
The group claims it downloaded manufacturing certificates, operating manuals, technical specifications, and regulatory documents. It also says the stolen files include confidential business information and intellectual property.
However, ShadowByt3$ says it did not steal customer data during the incident.
Abbott Disputes Claims About Sensitive Documents
Abbott describes LabCentral as an externally accessible portal hosted by a third party.
According to the company, the portal contains publicly available technical reference documents for its products. Abbott says it does not store proprietary business information or sensitive customer data.
As a result, the company disputes the attackers’ claims about the nature of the documents they allegedly obtained.
Abbott also reports no effect on its businesses or customers. Furthermore, neither ShadowByt3$ nor ShinyHunters has released any files connected to the Abbott cyber incidents.
The available information therefore remains based largely on claims made by the hacking groups. Abbott continues to investigate both cases.


0 responses to “Abbott Cyber Incidents Trigger Data Theft Investigation”