Medical device giant Abbott Laboratories is investigating two separate cybersecurity incidents after the cybercriminal group ShinyHunters claimed responsibility for breaching the company's systems.

 

What happened

According to Bleeping Computer, Abbott Laboratories is investigating two separate cybersecurity incidents after the ShinyHunters extortion group claimed to have breached the company's systems and stolen a significant amount of sensitive data.

According to Abbott, one incident involved unauthorized access to systems within its Cancer Diagnostics business, while the second affected LabCentral, a third-party-hosted portal used by its Core Laboratory Diagnostics division. The company said both incidents have been contained and that there is no evidence that manufacturing, laboratory operations, patient care, or sensitive customer information were impacted.

ShinyHunters, however, claims the breach was far more extensive. The threat actor alleges it stole more than 30 million rows of customer’s personally identifiable information (PII) from multiple datasets, including names, email addresses, phone numbers, physical addresses, dates of birth, and more than one million Social Security numbers.

The group further claims to have exfiltrated more than 22 million client notes containing doctor-patient conversations, over 20 million medical orders, and customer agreements and non-disclosure agreements (NDAs).

Abbott has not confirmed these claims, and at the time of writing, the company says its investigation remains ongoing.

 

 

Going deeper

Abbott said the first incident, which affected its cancer diagnostics business, involved the attacker gaining unauthorized access to certain internal systems. According to the company, the breach was contained to that business unit and did not impact other Abbott systems or its legacy Exact Sciences infrastructure.

The second incident involved LabCentral’s portal, which primarily stores publicly available technical documentation, such as operating manuals, troubleshooting guides, and product specifications. Their investigation found no evidence that sensitive customer or business information was exposed through the portal.

ShinyHunters, however, claims the attack extended far beyond these systems. According to a report by BleepingComputer, the threat actor told researchers it gained initial access through a voice phishing (vishing) campaign targeting Abbott employees. The group alleges the social engineering attack enabled it to compromise a Microsoft Entra single sign-on (SSO) account, providing access to multiple cloud-based services.

The attackers further claim they exfiltrated data from Microsoft Entra, SharePoint, ServiceNow, Databricks, and Coupa, including internal documents, contracts, and customer information. Abbott has not confirmed these allegations, and no evidence has been publicly released to independently verify the claimed data theft.

Regardless of the ultimate scope of the breach, the incident highlights a growing trend in cyberattacks. Rather than exploiting software vulnerabilities, threat actors are increasingly targeting identity platforms through phishing and vishing campaigns. By compromising a single employee account, attackers can potentially gain access to numerous interconnected cloud applications, making identity security a critical component of modern cybersecurity.

 

 

What was said

In a statement released by the company, they noted that the company is “investigating a cyber incident in which there was unauthorized access to a limited number of internal systems in our Cancer Diagnostics business only.” They reassured their customers, stating that the cyber incidents do “not impact any business operations, product or product availability, manufacturing or lab operations, or our ability to serve patients.”

An Abbott spokesperson told Bleeping Computer that “LabCentral is an externally facing third-party hosted portal used by Abbott's core laboratory diagnostics business… It houses publicly available technical product reference documents, including operating manuals, troubleshooting checklists and product specifications, and does not contain proprietary/sensitive customer or business information.”

 

The bigger picture

The Abbott incident follows a string of cyberattacks targeting healthcare and medical technology companies through identity-based attacks and social engineering rather than traditional ransomware. According to BleepingComputer, “The extortion gang has been increasingly targeting medtech companies, including Medtronic, OneMedical, and AdaptHealth.” The publication also reported that it had learned ShinyHunters was behind the iRhythm data breach and targeted Stryker soon after the company recovered from a destructive Iranian data-wiping attack.

Several of these incidents have also been covered by Paubox. Medtronic recently disclosed that a cyberattack initially claimed by ShinyHunters ultimately affected nearly 370,000 individuals, with attackers gaining access to personal information despite no reported disruption to products or patient care. Similarly, AdaptHealth revealed that a social engineering attack allowed threat actors to compromise employee credentials and access sensitive data, underscoring the growing effectiveness of identity-based attacks against healthcare organizations.

Meanwhile, iRhythm disclosed that attackers stole protected health information (PHI), personal information, and proprietary company data after compromising third-party-hosted business applications. Although the company did not publicly attribute the incident, BleepingComputer reported that ShinyHunters was responsible for the breach.

These incidents point to a sustained campaign against the healthcare sector, with ShinyHunters repeatedly targeting organizations that hold large volumes of sensitive patient and business data. They also reinforce the growing importance of securing identity platforms, strengthening phishing-resistant authentication, and training employees to recognize increasingly sophisticated social engineering attacks.

See also: HIPAA Compliant Email: The Definitive Guide (2026 Update)

 

FAQS

What is ShinyHunters?

ShinyHunters is a cybercriminal and extortion group known for stealing sensitive data from organizations and demanding ransom payments. The group has been linked to attacks against companies across multiple industries, including healthcare and medical technology.

 

Why are healthcare organizations increasingly targeted by cybercriminals?

Healthcare organizations store valuable patient, financial, and operational data. Rather than disrupting operations with ransomware, many attackers now focus on stealing sensitive information that can be used for extortion or sold on cybercriminal marketplaces.

 

What can healthcare organizations do to prevent similar attacks?

Organizations can reduce their risk by implementing phishing-resistant multi-factor authentication (MFA), monitoring identity systems for suspicious activity, limiting user privileges, providing regular security awareness training, and adopting a zero-trust security strategy.