Medical giant Abbott probes dual cyber incidents as ShinyHunters claims to possess 22 million patient notes
- Marijan Hassan - Tech Journalist
- 2 days ago
- 2 min read
Healthcare titan Abbott Laboratories is investigating two separate, unrelated cybersecurity incidents that hit its diagnostic infrastructure simultaneously. The twin disclosures arrived within days of each other, highlighted by an aggressive extortion threat from the prolific hacking collective ShinyHunters, which claims to have stolen millions of highly sensitive medical files and personal records from an internal company database.

The dual security alerts target entirely distinct layers of Abbott's business. While ShinyHunters is attempting to squeeze the corporation over an intrusion inside its Cancer Diagnostics segment, a completely separate hacking group known as ShadowByt3$ has claimed a parallel breach of Abbott’s LabCentral portal, an externally facing platform used by its core laboratory diagnostics division.
The Cancer Diagnostics Vishing Raid
The most severe threat stemming from the dual incidents involves Abbott's Cancer Diagnostics business unit. According to forensic details shared by the attackers, the compromise began in mid-June through a sophisticated voice phishing (vishing) campaign. Cybercriminals phoned several Abbott employees, masquerading as internal corporate IT support to trick the workers into surrendering their corporate credentials.
This social engineering maneuver allowed the group to successfully hijack a high-privilege Microsoft Entra single sign-on (SSO) account. Once inside, the threat actors moved laterally into a legacy system originally built by Exact Sciences, which Abbott inherited through a prior business acquisition.
ShinyHunters has posted Abbott to its dark web leak site, threatening to publish a massive 11-gigabyte data cache by July 21 unless the corporation pays a hefty ransom. The extortion group claims the stolen data encompasses a staggering treasure trove of protected health information, including:
Over 22 million doctor-patient medical notes and recorded clinical conversations.
More than 20 million official medical orders, customer agreements, and corporate NDAs.
Detailed identity dossiers on roughly one million individuals containing full names, physical addresses, dates of birth, and verified Social Security numbers.
Public Reference Versus Technical Secrets
As Abbott scrambled to contain the ShinyHunters intrusion, the ShadowByt3$ hacking syndicate launched a second, separate assault against the firm's LabCentral customer portal. The attackers claimed to have exploited a weak security configuration on July 4 using stolen customer credentials, subsequently exfiltrating a deep cache of proprietary technical documentation and internal manufacturing certificates.
Abbott has moved aggressively to downplay the severity of the LabCentral incident. While acknowledging the unauthorized entry, the medical giant clarified that the public-facing portal is exclusively used to host non-sensitive product reference material, troubleshooting checklists, and basic operating manuals.
The company reiterated that the portal contains zero proprietary code, trade secrets, or patient data.
Zero Operational Fallout
In a formal statement addressing the overlapping incidents, Abbott emphasized that neither breach has impacted its live manufacturing plants, laboratory workflows, or patient care systems. Because the compromised cancer diagnostic infrastructure is entirely isolated from Abbott’s primary corporate network, the firm does not expect the extortion event to cause any material impact on its financial results or core business operations.
The company has activated its incident response protocols, deployed external cybersecurity defense experts to harden its cloud environments, and is actively working with federal law enforcement to track the exfiltrated files.












