Executive Summary
Abbott Laboratories is currently investigating two separate cybersecurity incidents involving its Cancer Diagnostics and Core Laboratory diagnostics businesses. The first incident, confirmed by Abbott, involved unauthorized access to internal legacy Exact Sciences systems within the Cancer Diagnostics business. This breach was linked to the ShinyHunters extortion group, which claims to have exfiltrated sensitive data and threatened public disclosure unless negotiations occurred. The second incident centers on a claim by the threat actor ShadowByt3$, who alleges a breach of the LabCentral customer portal, resulting in the exfiltration of technical and regulatory documentation. Abbott asserts that the LabCentral portal only contains public, non-sensitive documents and that no proprietary or customer data was compromised. At this time, Abbott reports no impact to business operations, product availability, or patient services, and has engaged cybersecurity experts and law enforcement. No public indicators of compromise (IOCs) have been released, and the full extent of data exposure remains under investigation.
Technical Information
The first incident targeted the Cancer Diagnostics business of Abbott Laboratories, specifically legacy Exact Sciences systems. According to statements from Abbott and reporting by BleepingComputer, the attack was initiated through a vishing (voice phishing) campaign attributed to the ShinyHunters extortion group. Vishing is a form of social engineering where attackers impersonate trusted parties over the phone to trick employees into revealing credentials or multi-factor authentication (MFA) codes. In this case, the attackers reportedly compromised a Microsoft Entra (formerly Azure Active Directory) single sign-on (SSO) account, which provided access to internal systems and connected SaaS (Software-as-a-Service) applications.
Once initial access was achieved, the attackers allegedly moved laterally within the environment, targeting SaaS platforms such as Salesforce, Microsoft 365, Google Workspace, SAP, Slack, Adobe, Atlassian, Zendesk, and Dropbox. The attackers claimed to have exfiltrated large volumes of data, including personally identifiable information (PII), internal documents, contracts, and customer information from platforms like Microsoft Entra, ServiceNow, SharePoint, Databricks, and Coupa. The extortion group threatened to leak the data unless Abbott engaged in negotiations, using their data leak site as leverage.
The second incident involves the LabCentral customer portal, which serves the Core Laboratory diagnostics business. The threat actor ShadowByt3$ claimed to have gained access using compromised customer credentials, exploiting what was described as a "weak point" in the externally facing environment. The attacker stated that access was obtained on July 4, 2026, and that files were exfiltrated by targeting API endpoints. The data allegedly stolen includes CE manufacturing certificates, operation manuals, technical specifications, regulatory documentation, product requirement archives, calibrator value assignments, assay files, and other product documentation. Abbott, however, maintains that the portal only contains publicly available technical reference documents and does not store proprietary or sensitive customer or business information.
No specific malware was reported in either incident. The primary attack vectors were social engineering (vishing), credential harvesting, and abuse of legitimate SSO/OAuth tokens. The ShinyHunters group is known for using victim-branded credential harvesting sites, registering new MFA devices for persistence, abusing OAuth and refresh tokens, and scanning for SaaS misconfigurations. No ransomware or destructive malware was confirmed in these incidents.
The attack methods align with several MITRE ATT&CK techniques, including phishing (T1566.002), vishing (T1598.004), valid accounts (T1078), multi-factor authentication interception (T1111), data from information repositories (T1213), and exfiltration over web service (T1567.002). The incidents highlight the ongoing risks to healthcare sector supply chains, third-party portals, and cloud identity providers.
Affected Versions & Timeline
The first incident affected legacy Exact Sciences systems within the Cancer Diagnostics business of Abbott Laboratories. The compromise reportedly occurred in mid-June 2026, with public disclosure and extortion threats emerging in July 2026. The second incident targeted the LabCentral customer portal, with the threat actor claiming initial access on July 4, 2026. Abbott confirmed awareness of the potential incident shortly thereafter. As of July 17, 2026, neither group has publicly released any stolen data.
Abbott has stated that the incidents have not impacted other business units, product availability, manufacturing, or patient services. The company activated its incident response procedures, engaged third-party cybersecurity experts, and notified law enforcement upon discovery of the incidents.
Threat Activity
The ShinyHunters group has a documented history of targeting organizations for financial gain through data theft and extortion. Their tactics include social engineering (vishing), SSO and MFA abuse, SaaS data theft, OAuth token abuse, and extortion via data leak sites. Previous campaigns have targeted technology, finance, education, and healthcare sectors, with notable incidents involving Medtronic, OneMedical, AdaptHealth, iRhythm, and Stryker. The group is known for leveraging stolen credentials to access cloud and SaaS environments, exfiltrating large datasets, and threatening public disclosure to pressure victims into negotiations.
The ShadowByt3$ group is less well-documented but is known for opportunistic breaches of exposed or weakly protected portals and APIs. In the Abbott incident, the group claimed to have used compromised customer credentials to access the LabCentral portal and exfiltrate technical documentation. Abbott disputes the sensitivity of the data involved, stating that all information stored in the portal is public.
Attribution to ShinyHunters is assessed with high confidence based on direct extortion claims, consistent tactics, techniques, and procedures (TTPs), and historical pattern matching. Attribution to ShadowByt3$ is assessed with medium confidence due to self-attribution and circumstantial evidence, but lacking independent technical verification.
Mitigation & Workarounds
Critical recommendations include immediate review and hardening of SSO and MFA configurations, particularly for Microsoft Entra, Okta, and Google SSO accounts. Organizations should implement robust employee training to recognize and report vishing and other social engineering attempts. Regular audits of SaaS integrations and third-party portals are essential to identify and remediate misconfigurations or weak authentication controls. Monitoring for abnormal access patterns, especially involving API endpoints and externally facing portals, is recommended. Engaging with third-party cybersecurity experts and promptly notifying law enforcement in the event of a suspected breach are also critical steps.
High-priority actions include enforcing strong password policies, enabling phishing-resistant MFA (such as FIDO2 security keys), and restricting access to sensitive systems based on least privilege principles. Medium-priority actions involve reviewing and updating incident response plans, conducting tabletop exercises, and ensuring that all externally facing portals are regularly tested for vulnerabilities. Low-priority actions include maintaining up-to-date documentation of all SaaS and third-party integrations and ensuring that public-facing documentation does not inadvertently expose sensitive information.
Indicators of Compromise
No public indicators of compromise (IOCs) were available at the time of writing. Organizations should validate any future indicators before enforcement.
References
BleepingComputer: https://www.bleepingcomputer.com/news/security/abbott-laboratories-probes-two-cyber-incidents-amid-extortion-claims/amp/
Abbott Statement: https://www.abbott.com/en-us/corpnewsroom/diagnostics-testing/abbott-statement-on-cyber-incident-in-cancer-diagnostics-business
Huntress ShinyHunters Profile: https://www.huntress.com/threat-library/threat-actors/shinyhunters
About Rescana
Rescana provides a third-party risk management (TPRM) platform designed to help organizations identify, assess, and monitor cybersecurity risks across their supply chain and vendor ecosystem. Our platform enables continuous monitoring of third-party portals, SaaS integrations, and identity providers, supporting rapid detection and response to credential abuse, misconfigurations, and social engineering threats. For more information or to discuss your organization’s risk posture, contact us at info@rescana.com.



