Abbott Investigates Two Cyber Attacks Linked to Extortion Threats

0
36

Key Takeaways

  • Abbott Laboratories confirmed unauthorized access to internal systems in its Cancer Diagnostics business and investigated a separate incident affecting the externally hosted LabCentral portal.
  • The company states there is no impact on manufacturing, laboratory operations, product availability, or patient care, and it has found no evidence that sensitive customer or business information was exposed.
  • Cybercriminal groups ShinyHunters and ShadowByt3$ claim to have stolen large volumes of data—including millions of doctor‑patient notes, medical orders, Social Security numbers, and technical documentation—but have not yet released verifiable proof.
  • Both groups have placed Abbott on their extortion sites and set deadlines for response, though the claims remain unverified at this time.
  • Customers are advised to follow Abbott’s guidance, change passwords, enable multi‑factor authentication, watch for impersonation scams, and consider identity‑monitoring services to mitigate potential risk.

Overview of the Reported Incidents
Abbott Laboratories, a global leader in healthcare and medical devices, disclosed on July 16 that it is investigating two cyber incidents. One incident involved unauthorized access to a limited number of internal systems within its Cancer Diagnostics business. The second incident concerns the LabCentral customer portal, which Abbott describes as an externally hosted platform used for core laboratory diagnostics. The company emphasized that, to date, there is no indication that manufacturing, lab operations, product availability, or patient care have been affected by either breach.

Abbott’s Official Statement on the Cancer Diagnostics Breach
In its public statement, Abbott said: “Abbott is investigating a cyber incident in which there was unauthorized access to a limited number of internal systems in our Cancer Diagnostics business only. This does not impact any business operations, product or product availability, manufacturing or lab operations, or our ability to serve patients.” The firm added that it has activated incident‑response procedures, engaged law‑enforcement authorities, and is conducting a thorough forensic review to determine the scope and origin of the intrusion.

ShinyHunters’ Allegations and Extortion Timeline
The hacking group ShinyHunters told BleepingComputer that it had exfiltrated a substantial cache of data from Abbott, including internal documents, contracts, customer information, more than 22 million doctor‑patient notes, over 20 million medical orders, and upwards of one million U.S. Social Security numbers. The group also claimed to have taken personally identifiable information such as names, addresses, dates of birth, email addresses, and phone numbers. On July 18, ShinyHunters issued a final warning, giving Abbott until July 21, 2026 to respond before leaking the alleged data and causing “several annoying (digital) problems.” The group referenced its past tactics, such as defacing school login pages during the Canvas attacks, to underline the seriousness of its threat.

ShadowByt3$ Claims Regarding the LabCentral Portal
Separately, ShadowByt3$ asserted that it gained access to the LabCentral portal on July 4 by leveraging compromised customer credentials and exploiting a “weak point” in the environment. The group said it exfiltrated technical documentation, manufacturing certificates, operating manuals, technical specifications, and regulatory files related to Abbott’s laboratory systems. ShadowByt3$ posted these claims on its extortion site and shared details with media narrative, although, like ShinyHunters, it has not yet published any verifiable samples of the purported data.

Assessment of the Claims and Abbott’s Position
While the attackers’ allegations are detailed and have been echoed across multiple media outlets, no concrete evidence—such as leaked files or screenshots—has been made public to substantiate the scale of the data theft. Abbott’s acknowledgment of unauthorized access in the Cancer Diagnostics systems indicates a genuine compromise, yet the company maintains that its investigations have uncovered no exposure of sensitive customer or business information from either incident. The lack of leaked proof leaves the claims in the realm of unverified extortion attempts, though the groups’ history of follow‑through on threats warrants vigilance.

Recommended Actions for Abbott Customers and Partners
If you use Abbott’s diagnostic systems or the LabCentral portal, consider the following precautionary steps:

  • Check Vendor Guidance – Review any communications from Abbott regarding the incidents and follow the specific advice they provide.
  • Change Passwords – Replace existing passwords with strong, unique credentials; a password manager can help generate and store them securely.
  • Enable Two‑Factor Authentication (2FA) – Wherever possible, use a FIDO2‑compliant hardware key or authenticator app; avoid SMS‑based 2FA if feasible, as it is more susceptible to phishing.
  • Watch for Impersonation Scams – Verify the legitimacy of any unsolicited contact claiming to be from Abbott by checking official channels and using a separate communication method to confirm.
  • Avoid Storing Card Details – Refrain from saving payment information on websites unless absolutely necessary, and monitor account statements for unauthorized activity.
  • Set Up Identity Monitoring – Services that alert you when personal data appears on illicit markets can help you react quickly if your information is compromised.

How to Check Whether Your Data Has Been Exposed
You can run a free Digital Footprint scan using tools such as Malwarebytes to see if your email address, phone number, or other personal identifiers appear in known breach databases. While such scans cannot guarantee detection of every possible exposure, they provide a useful first step in assessing your risk and deciding whether additional protective measures—like credit freezes or fraud alerts—are warranted.

By staying informed, strengthening authentication practices, and monitoring for misuse of personal data, customers can mitigate potential fallout from these incidents while awaiting further clarification from Abbott and law‑enforcement investigations.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here