Abbott Laboratories is currently investigating two significant cybersecurity incidents affecting its Cancer Diagnostics and Core Laboratory diagnostics businesses. The first incident involves unauthorized access to internal legacy Exact Sciences systems, attributed to the ShinyHunters extortion group, which claims to have exfiltrated sensitive data and threatened public disclosure unless negotiations occurred. The second incident involves a claim by the threat actor ShadowByt3$, alleging a breach of the LabCentral customer portal, which Abbott asserts contains only public, non-sensitive documents. As of now, Abbott reports no impact on business operations or patient services and has engaged cybersecurity experts and law enforcement. The full extent of data exposure remains under investigation, with no public indicators of compromise (IOCs) released.
Technical Overview of the Incidents
The first incident targeted Abbott’s Cancer Diagnostics business, specifically legacy Exact Sciences systems. According to Abbott and reporting by BleepingComputer, the attack was initiated through a vishing (voice phishing) campaign linked to the ShinyHunters group. Vishing is a social engineering tactic where attackers impersonate trusted parties over the phone to trick employees into revealing credentials or multi-factor authentication (MFA) codes. The attackers reportedly compromised a Microsoft Entra (formerly Azure Active Directory) single sign-on (SSO) account, gaining access to internal systems and connected SaaS applications.
After gaining initial access, the attackers allegedly moved laterally within the environment, targeting various SaaS platforms, including Salesforce, Microsoft 365, Google Workspace, SAP, and others. They claimed to have exfiltrated large volumes of data, including personally identifiable information (PII), internal documents, and customer information. The extortion group threatened to leak this data unless Abbott engaged in negotiations, leveraging their data leak site as a pressure tactic.
Details of the LabCentral Breach
The second incident involves the LabCentral customer portal, which serves Abbott’s Core Laboratory diagnostics business. The threat actor ShadowByt3$ claimed to have gained access using compromised customer credentials, exploiting a “weak point” in the externally facing environment. They stated that access was obtained on July 4, 2026, and that files were exfiltrated by targeting API endpoints. Allegedly stolen data includes CE manufacturing certificates, operation manuals, and regulatory documentation. However, Abbott maintains that the portal only contains publicly available technical reference documents and does not store proprietary or sensitive customer information.
Threat Activity and Attribution
The ShinyHunters group has a documented history of targeting organizations for financial gain through data theft and extortion. Their tactics include social engineering, SSO and MFA abuse, and SaaS data theft. Previous campaigns have targeted various sectors, including healthcare, with notable incidents involving companies like Medtronic and Stryker. Attribution to ShinyHunters is assessed with high confidence based on direct extortion claims and consistent tactics.
In contrast, the ShadowByt3$ group is less well-documented but is known for opportunistic breaches of exposed or weakly protected portals and APIs. Attribution to ShadowByt3$ is assessed with medium confidence due to self-attribution and circumstantial evidence, lacking independent technical verification.
Mitigation Strategies
Critical recommendations for organizations include an immediate review and hardening of SSO and MFA configurations, particularly for Microsoft Entra, Okta, and Google SSO accounts. Organizations should implement robust employee training to recognize and report vishing and other social engineering attempts. Regular audits of SaaS integrations and third-party portals are essential to identify and remediate misconfigurations or weak authentication controls. Monitoring for abnormal access patterns, especially involving API endpoints, is also recommended.
High-priority actions include enforcing strong password policies, enabling phishing-resistant MFA (such as FIDO2 security keys), and restricting access to sensitive systems based on least privilege principles. Medium-priority actions involve reviewing and updating incident response plans and conducting tabletop exercises. Low-priority actions include maintaining up-to-date documentation of all SaaS and third-party integrations.
No public indicators of compromise (IOCs) were available at the time of writing, and organizations should validate any future indicators before enforcement.
For further details, refer to the report by Rescana.


