Abbott Laboratories is currently investigating two separate cybersecurity incidents that have raised concerns about unauthorized access to its internal systems and potential data breaches. The company has confirmed that it has been targeted by two different threat actors, who claim to have compromised sensitive information through various means.
One of the incidents involves the ShinyHunters extortion gang, which has a history of conducting social engineering campaigns targeting employees’ single sign-on (SSO) accounts. According to the group, they gained access to Abbott’s internal systems through a vishing attack in mid-June, compromising a Microsoft Entra SSO account and allowing them to exfiltrate data from connected SaaS applications such as Salesforce and Microsoft 365. The stolen data includes internal documents, contracts, customer information, and over 30 million rows of customer personally identifiable information (PII). ShinyHunters has also claimed to have targeted Abbott’s Legacy Exact Sciences systems in its Cancer Diagnostics business.
The company has stated that the incident does not impact any business operations, product availability, manufacturing or lab operations, or its ability to serve patients. However, the investigation is ongoing, and it’s unclear what data was actually stolen by ShinyHunters. The extortion gang has been increasingly targeting medtech companies in recent months, with previous victims including Medtronic, OneMedical, and AdaptHealth.
In a separate incident, Abbott’s LabCentral customer portal was allegedly breached by an individual or group known as ShadowByt3$. According to the threat actor, they identified a “weak point” in the environment and gained access on July 4, 2026. ShadowByt3$ claims that no customer data was stolen, but sensitive business documents and intellectual property were compromised. The stolen data includes CE manufacturing certificates, operation manuals, technical specifications, regulatory documentation, product requirement archives, calibrator value assignments, assay files, and other product documentation related to Abbott’s laboratory diagnostic systems.
The investigation into both incidents is ongoing, with Abbott stating that it has activated its incident response procedures and engaged cybersecurity experts. The company has also notified law enforcement and does not expect the incidents to have a material impact on its business or financial results. However, these incidents highlight the ongoing threat posed by sophisticated cyber attackers who are increasingly targeting healthcare companies.
The practical takeaway for our readers is that even well-established companies like Abbott Laboratories can be targeted by sophisticated cyber attackers. As such, it’s essential for all organizations to prioritize cybersecurity and implement robust measures to protect their internal systems from unauthorized access. This includes regular security audits, employee training on social engineering tactics, and implementing multi-factor authentication to prevent SSO account compromises. By staying vigilant and proactive in our approach to cybersecurity, we can reduce the risk of data breaches and maintain the trust of our customers and stakeholders.
Source: Bleeping Computer — 2026-07-17