The extortion group published 10.9 million email addresses alongside health information, weeks before the company finished working out whom to notify.
What happened
Data stolen from Abbott's cancer diagnostics business has been published online after the company apparently refused to pay, The Register reported on August 7, 2026. The breach notification service Have I Been Pwned added the Exact Sciences dataset the same day, recording 10.9 million unique email addresses alongside names, physical addresses, phone numbers, dates of birth, genders, and personal health information belonging to customers, patients, and healthcare providers. Abbott acquired Exact Sciences earlier this year. The company first disclosed the intrusion on July 16.
Going deeper
The attackers reached the network by telephone rather than through software. Abbott confirmed in an August 5 update that the intrusion began with a vishing attack, meaning voice phishing, where a caller impersonates someone the target has reason to trust and talks their way into access. The company stated that some of the accessed files contained personal information or personal health information, that the investigation was continuing, and that it had not yet determined who required notification. Abbott also said the incident was not an encryption malware event, that a limited number of internal systems within the cancer diagnostics business were affected, and that products, manufacturing, laboratory operations, and patient services continued without disruption. Several questions remain unanswered publicly, including how the call led to data theft, how long the intruders held access, and whether an extortion demand was received.
What was said
ShinyHunters gave a different account on its leak site, telling Abbott it "should've paid the ransom" and claiming the company was given multiple chances to reach an agreement, according to The Register, which reviewed the post. Abbott's own statement describes an ongoing investigation and commits to notifying affected individuals where required, without addressing the group's claims about negotiations.
In the know
Reading the attackers' inventory requires care, since none of it has been independently verified. ShinyHunters claims to hold more than 30 million rows of customer information including over a million Social Security numbers and 7.5 million dates of birth, more than 22 million rows of client notes containing doctor-patient conversations, and over 20 million medical order records carrying patient identifiers, prescription types, order dates, and refill details. It further claims more than 425 million rows taken from a data analytics platform, 130,000 SharePoint files, and 89,000 contract documents. Row counts inflate easily, since a single patient can generate many rows across appointments, orders, and refills, so those figures describe records rather than people. What has been confirmed by the 10.9 million email addresses in the published set is substantial on its own, and it establishes a floor rather than a total.
The big picture
Notification exists so people can act before their information circulates, and this sequence reverses that. The Breach Notification Rule allows up to 60 days from discovery, with the review period covering the work of identifying each affected individual and the specific data elements involved. Abbott disclosed the incident on July 16 and had not settled the notification list by August 5, which is within the rule and behind the attackers, who published on August 7. Anyone whose cancer diagnostic records sit in that dataset now learns of it from news coverage or a breach-checking service rather than a letter. The entry method deserves separate attention from healthcare security teams, since a data breach that starts with a phone call bypasses every email control an organization has configured, and social engineering against help desks and support staff has become a documented route into health sector organizations rather than an unusual one.
FAQs
Does publication of stolen data change an organization's notification obligations?
Not the deadline, which runs from discovery. Publication does affect the risk assessment, since an entity can no longer argue a low probability of compromise on the basis that data was not further disclosed. Organizations generally treat public leak-site posting as settling that question.
Why do attacker row counts differ so much from victim headcounts?
Databases store one row per transaction, order, note, or appointment, so a single patient with a multi-year treatment history can appear hundreds of times. Deduplicating to individuals requires access to the underlying data, which is why confirmed figures typically arrive months after attacker claims.
What makes vishing harder to defend against than email phishing?
No filter sits in the path of a phone call, no attachment gets sandboxed, and no link gets rewritten. Defense depends entirely on verification procedures that staff follow under pressure, which is why callbacks to numbers held on record and supervisor approval for access changes matter more than any technical control.
Are cancer diagnostic records more sensitive than other health data?
They carry particular consequences, since a record indicating cancer screening, diagnosis, or treatment can affect insurance underwriting in some contexts, employment situations, and personal relationships in ways a routine lab result does not. The data also has permanent value to fraudsters, unlike a payment card.
What should patients do when a company has not yet sent notifications?
Check breach notification services against their email addresses, place a credit freeze with the three bureaus at no cost, and review explanation-of-benefits statements for services they did not receive. Waiting for a letter delays protective steps that cost nothing to take early.
