
Abbott Laboratories is dealing with a cybersecurity incident that resulted in the exposure of personal and personal health information from its Cancer Diagnostics business.
The incident, which occurred after attackers gained access through a compromised Microsoft Entra single sign-on account, has since escalated after the ShinyHunters extortion group leaked data it claimed to have stolen from Abbott, following an apparent failure to reach an agreement with the company.
Have I Been Pwned has also added the leaked dataset to its database, listing 10.9 million unique email addresses among the exposed information, with it reportedly containing names, addresses, phone numbers, dates of birth, genders and health information.
However, Abbott said the incident remains limited to a number of internal systems in its Cancer Diagnostics business and did not affect manufacturing, laboratory operations, product availability or its ability to serve patients. And the company has also brought in outside cybersecurity experts and law enforcement as it continues its investigation.
How The Attackers Got In
According to ShinyHunters, the attack began with a voice phishing campaign targeting several Abbott employees in mid-June.
The group told BleepingComputer that the campaign resulted in the compromise of a corporate Microsoft Entra single sign-on account, which was then used to access internal applications connected to it, including ServiceNow, SharePoint, Databricks and Coupa.
Microsoft Entra is widely used by organizations to manage employee identities and access to cloud applications. A compromised account can therefore become a useful entry point when it has access to multiple services.
The reported method matters because there was no publicly reported exploitation of a highly technical software flaw at the start of the intrusion. The attackers reportedly persuaded employees to give up access, then used the compromised identity to move into connected systems.
The Stolen Data Was Eventually Leaked
The situation changed after Abbott apparently declined to pay the ransom demanded by ShinyHunters. The group subsequently leaked the data it claimed to have stolen, moving the incident beyond an extortion threat.
Have I Been Pwned has since added the leaked dataset to its database and lists 10.9 million unique email addresses among the exposed information. The dataset also reportedly contains names, addresses, phone numbers, dates of birth, genders and health information.
While Abbott has acknowledged that some of the files accessed during the incident contained personal information and personal health information, it has not publicly confirmed every detail of the dataset or the specific number of affected individuals that were reported by Have I Been Pwned.
Abbott Says Its Wider Operations Were Not Affected
Abbott has stressed that the incident was contained within its Cancer Diagnostics business, saying the legacy Exact Sciences systems involved are separate from its other Abbott systems and that there was no impact on other businesses, sites, or systems.
The company also said it does not expect the incident to have a material impact on its business or financial results.
The breach still highlights a security challenge facing large organizations. Companies can invest heavily in cybersecurity tools and still face serious exposure when an employee identity becomes the route into several connected systems.
For Abbott, the investigation will now determine exactly how far that compromised account reached and what information, if any, was actually taken.
The incident is another example of why identity security remains a critical part of enterprise cybersecurity, especially for the nature of the business involved. Cancer Diagnostics deals with information connected to one of the most sensitive areas of healthcare, where records can reveal a person’s health status, medical history and treatment-related information.
While Abbott said the incident did not affect laboratory operations or product availability, the exposure of personal health information still raises significant privacy and security concerns for the people whose information was involved.
