Abbott Laboratories Investigates Dual Cybersecurity Breaches Linked to ShinyHunters and ShadowByt3$

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

Abbott Laboratories is currently investigating two significant cybersecurity incidents affecting its Cancer Diagnostics and Core Laboratory diagnostics businesses. The first incident involves unauthorized access to internal legacy Exact Sciences systems, attributed to the ShinyHunters extortion group, which claims to have exfiltrated sensitive data and threatened public disclosure unless negotiations occurred. The second incident involves a claim by the threat actor ShadowByt3$, alleging a breach of the LabCentral customer portal, which Abbott asserts contains only public, non-sensitive documents. As of now, Abbott reports no impact on business operations or patient services and has engaged cybersecurity experts and law enforcement. The full extent of data exposure remains under investigation, with no public indicators of compromise (IOCs) released.

Technical Overview of the Incidents

The first incident targeted Abbott’s Cancer Diagnostics business, specifically legacy Exact Sciences systems. According to Abbott and reporting by BleepingComputer, the attack was initiated through a vishing (voice phishing) campaign linked to the ShinyHunters group. Vishing is a social engineering tactic where attackers impersonate trusted parties over the phone to trick employees into revealing credentials or multi-factor authentication (MFA) codes. The attackers reportedly compromised a Microsoft Entra (formerly Azure Active Directory) single sign-on (SSO) account, gaining access to internal systems and connected SaaS applications.

After gaining initial access, the attackers allegedly moved laterally within the environment, targeting various SaaS platforms, including Salesforce, Microsoft 365, Google Workspace, SAP, and others. They claimed to have exfiltrated large volumes of data, including personally identifiable information (PII), internal documents, and customer information. The extortion group threatened to leak this data unless Abbott engaged in negotiations, leveraging their data leak site as a pressure tactic.

Details of the LabCentral Breach

The second incident involves the LabCentral customer portal, which serves Abbott’s Core Laboratory diagnostics business. The threat actor ShadowByt3$ claimed to have gained access using compromised customer credentials, exploiting a “weak point” in the externally facing environment. They stated that access was obtained on July 4, 2026, and that files were exfiltrated by targeting API endpoints. Allegedly stolen data includes CE manufacturing certificates, operation manuals, and regulatory documentation. However, Abbott maintains that the portal only contains publicly available technical reference documents and does not store proprietary or sensitive customer information.

Threat Activity and Attribution

The ShinyHunters group has a documented history of targeting organizations for financial gain through data theft and extortion. Their tactics include social engineering, SSO and MFA abuse, and SaaS data theft. Previous campaigns have targeted various sectors, including healthcare, with notable incidents involving companies like Medtronic and Stryker. Attribution to ShinyHunters is assessed with high confidence based on direct extortion claims and consistent tactics.

In contrast, the ShadowByt3$ group is less well-documented but is known for opportunistic breaches of exposed or weakly protected portals and APIs. Attribution to ShadowByt3$ is assessed with medium confidence due to self-attribution and circumstantial evidence, lacking independent technical verification.

Mitigation Strategies

Critical recommendations for organizations include an immediate review and hardening of SSO and MFA configurations, particularly for Microsoft Entra, Okta, and Google SSO accounts. Organizations should implement robust employee training to recognize and report vishing and other social engineering attempts. Regular audits of SaaS integrations and third-party portals are essential to identify and remediate misconfigurations or weak authentication controls. Monitoring for abnormal access patterns, especially involving API endpoints, is also recommended.

High-priority actions include enforcing strong password policies, enabling phishing-resistant MFA (such as FIDO2 security keys), and restricting access to sensitive systems based on least privilege principles. Medium-priority actions involve reviewing and updating incident response plans and conducting tabletop exercises. Low-priority actions include maintaining up-to-date documentation of all SaaS and third-party integrations.

No public indicators of compromise (IOCs) were available at the time of writing, and organizations should validate any future indicators before enforcement.

For further details, refer to the report by Rescana.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

North Korean WaterPlum Cyber Group Targets IT Professionals to Steal Cryptocurrency

Recent investigations by the National Police Agency of Japan (NPA), the US Federal Bureau of Investigation (FBI), and other international cybersecurity agencies have revealed...

Air Force plans to field 100 Massed Modular Aircraft drones by 2029

The United States Air Force is advancing its plans for the Massed Modular Aircraft (MMA) unmanned platform, with intentions to field 100 of these...

Surge in AI-Driven Vulnerabilities Leads to Record Number of CVEs, Straining Cybersecurity Resources

Recent developments in cybersecurity have revealed a significant surge in vulnerabilities driven by artificial intelligence (AI), leading to a record number of Common Vulnerabilities...

North Korean hackers steal over $10.5 million in cryptocurrency through ‘WaterPlum’ campaign targeting job seekers across 100 countries

North Korean hackers have reportedly stolen over $10.5 million in cryptocurrency through a campaign known as "WaterPlum," which targets job seekers across more than...