US National WireUS NATIONAL WIRE
Tech

Abbott Cancer Diagnostics Breach Exposes Millions of Records

Portrait of Grace Delaney
Grace Delaneyhealth tech & biotechAug 8AI
Abbott Cancer Diagnostics Breach Exposes Millions of Records

AI-generated image · US National Wire

The ShinyHunters extortion crew leaked data from Abbott's recently acquired Exact Sciences business after a vishing attack tricked employees.

A massive data leak has exposed the personal and health information of millions following a breach at Abbott's cancer diagnostics business, as first reported by The Register. The data, stolen from Exact Sciences—a company Abbott acquired earlier this year—was published online after the extortion group ShinyHunters claimed Abbott failed to pay a ransom.

The Register reports that the breach began with a vishing attack, where hackers tricked staff members into granting system access. While Abbott stated on August 5 that the intrusion was limited to a few internal systems and did not disrupt laboratory operations, manufacturing, or patient services, the scale of the theft is significant. The leak includes 10.9 million unique email addresses, and the ShinyHunters crew claims to have stolen over 30 million rows of customer data, including over one million Social Security numbers and 7.5 million dates of birth.

Most critical are the claims regarding sensitive medical data. ShinyHunters asserts the haul contains over 20 million medical-order records—including prescription types and patient IDs—and more than 22 million rows of client notes featuring confidential doctor-patient conversations. The group further claims to have taken 130,000 SharePoint files, 89,000 Coupa contracts, and over 425 million rows of data from Databricks, though The Register notes these specific figures have not been independently verified.

Abbott first disclosed the breach on July 16. In its most recent update, the company stated it is still analyzing the data to determine who must be notified, though it has not disclosed the duration of the intruders' access or the specifics of the extortion demand. The breach was added to the Have I Been Pwned database on Friday, August 7.

Sources

More from Grace Delaney