Abbott probes two cyber incidents amid extortion claims

Abbott Laboratories, a leading healthcare company, is investigating two separate cybersecurity incidents that have raised concerns about data breaches and extortion attempts. The company confirmed that unauthorized access was made to internal systems in its Cancer Diagnostics business, while also probing a second incident involving its LabCentral customer portal.

At the center of the first incident are allegations by the ShinyHunters extortion gang, who claimed to have gained access through a vishing attack targeting Abbott employees. The group has been conducting social engineering campaigns that target corporate single sign-on (SSO) accounts, including those managed by Microsoft Entra, Okta, and Google. Once inside, attackers steal data from connected software-as-a-service (SaaS) applications such as Salesforce and Microsoft 365.

According to ShinyHunters, they compromised a Microsoft Entra SSO account in mid-June, allowing them to access internal systems. The group claims to have stolen sensitive information, including customer personally identifiable information (PII), contracts, and internal documents. While the company has not independently verified these claims, it has acknowledged an unauthorized access incident and activated its incident response procedures.

The second incident involves a threat actor known as ShadowByt3$, who contacted BleepingComputer claiming to have breached Abbott’s LabCentral customer portal using compromised customer credentials. The group says no customer data was stolen but obtained sensitive business documents and intellectual property. They claim to have accessed API endpoints, slowly exfiltrating files over several days.

Both incidents highlight the risks of social engineering attacks and the importance of robust cybersecurity measures. The ShinyHunters gang has been targeting medtech companies, including Medtronic and OneMedical, with similar tactics. Their claims of stealing sensitive information from connected SaaS applications underscore the need for businesses to secure their external-facing services.

The Abbott incidents also demonstrate how attackers can exploit vulnerabilities in single sign-on accounts to gain access to internal systems. This is particularly concerning given the widespread adoption of cloud-based services and the increasing reliance on SSO technology.

While Abbott has stated that it does not expect the incident to have a material impact on its business or financial results, the company’s response highlights the importance of swift action in the face of cybersecurity incidents. By activating its incident response procedures and engaging with law enforcement, Abbott is taking necessary steps to mitigate potential damage.

For businesses facing similar threats, this incident serves as a reminder to prioritize cybersecurity measures, including multi-factor authentication, regular software updates, and employee education on social engineering tactics.


Source: Bleeping Computer — 2026-07-17