US National WireUS NATIONAL WIRE
Tech

Vishing Attack Leads to Massive Data Leak at Abbott Cancer Diagnostics Unit

Portrait of Grace Delaney
Grace Delaneyhealth tech & biotechAug 10AI
Vishing Attack Leads to Massive Data Leak at Abbott Cancer Diagnostics Unit

AI-generated image · US National Wire

The ShinyHunters extortion crew has released millions of records after Abbott reportedly declined to pay a ransom following a social engineering breach.

A security breach at Abbott's cancer diagnostics business has resulted in the public release of personal and health data, as first reported by The Register. The data was leaked by the ShinyHunters extortion crew after the healthcare company apparently refused to pay a ransom.

Abbott, which acquired the cancer diagnostics company Exact Sciences earlier this year, first reported the intrusion on July 16. In an update provided on August 5, the company confirmed that the breach began with a "vishing" attack—a form of voice phishing where attackers trick employees over the phone—though it noted the event did not involve encryption malware. Abbott stated that the intrusion affected only a limited number of internal systems and did not disrupt laboratory operations, patient services, manufacturing, or products.

While Abbott is still analyzing the data to determine which individuals require notification, the stolen information has already surfaced online. On Friday, August 7, the breach involving Exact Sciences was added to the database of the service Have I Been Pwned. This specific leak includes 10.9 million unique email addresses, along with physical addresses, phone numbers, genders, names, dates of birth, and personal health information of patients, customers, and healthcare providers.

ShinyHunters has made more expansive claims regarding the volume of stolen data on its dark web leak site. The group asserts it seized over 30 million rows of customer data, which includes more than one million Social Security numbers and 7.5 million dates of birth. Furthermore, the crew claims to have stolen over 20 million medical-order records—including refill information, order dates, prescription types, and patient IDs—and more than 22 million rows of confidential doctor-patient health information and client notes.

Additional claims from ShinyHunters include the theft of 130,000 SharePoint files, 89,000 Coupa contracts, and over 425 million rows of data from Databricks, though The Register notes these specific figures have not been independently verified.

On its leak site, ShinyHunters stated that Abbott "should've paid the ransom" and alleged the company failed to reach an agreement despite multiple opportunities. Abbott has not disclosed the specifics of how the vishing attack granted the hackers access, the duration of the intruders' system access, or whether an official extortion demand was received. The company maintains that its investigation is ongoing.

Sources

More from Grace Delaney