Cybersecurity

Abbott is fighting off two hacking gangs at once

Future Technology ยท 24 July 2026

Healthcare and diagnostics giant Abbott Laboratories is investigating two separate intrusions running in parallel, which is an unusual enough situation that it's worth walking through carefully.

The extortion group ShinyHunters says it got in through a vishing call, a voice phishing attempt where an attacker rings a company help desk or employee and talks their way past identity checks. The gang claims it used this to hijack a Microsoft Entra single sign-on account belonging to an Abbott employee in mid-June, then used that access to reach legacy systems tied to Abbott's Exact Sciences cancer diagnostics business.

ShinyHunters says the haul includes more than 22 million doctor-patient notes, over 20 million medical orders, internal contracts, customer agreements, and more than a million Social Security numbers. It set a leak deadline of 18 July, then pushed it to 21 July, a shift that usually signals ransom negotiations are underway. A second, separate group calling itself ShadowByt3$ is independently claiming access to a different Abbott portal.

As of writing, neither group has published the data they claim to hold, and Abbott has not confirmed the scale of either claim.

Why this matters

The headline number is eye-catching, but the real story is the method. A phone call was reportedly enough to get past the defences of a company with the resources to run a serious security programme. If your organisation's help desk can be talked into resetting multi-factor authentication over the phone without stronger verification, this is the week to fix that, not after it happens to you.

If you've had contact with Abbott's diagnostics or cancer testing services, there's nothing actionable yet since no data has surfaced. Keep an eye on official Abbott communications rather than reacting to the extortion group's claims, which are, by definition, unverified.