{"id":596030,"date":"2026-07-21T02:16:15","date_gmt":"2026-07-21T02:16:15","guid":{"rendered":"https:\/\/www.europesays.com\/ie\/596030\/"},"modified":"2026-07-21T02:16:15","modified_gmt":"2026-07-21T02:16:15","slug":"healthcare-giant-abbott-probes-two-cyber-incidents-amid-extortion-claims","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ie\/596030\/","title":{"rendered":"Healthcare giant Abbott probes two cyber incidents amid extortion claims"},"content":{"rendered":"<p class=\"wp-block-paragraph\">Abbott Laboratories, one of the world\u2019s largest healthcare and medical device companies, is investigating two apparently unrelated cyber incidents after confirming unauthorized access to internal systems. While Abbott says there has been no impact on manufacturing, laboratory operations, or patient care, cybercriminal groups ShinyHunters and ShadowByt3$ claim the breaches were far more extensive. Those claims remain unverified at the time of writing and, so far, unsupported by publicly leaked data.<\/p>\n<p class=\"wp-block-paragraph\">The incidents <a href=\"https:\/\/cybernews.com\/news\/abbott-laboratories-breach-shinyhunters\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">reportedly<\/a> involve Abbott\u2019s Cancer Diagnostics business and its LabCentral customer portal for core laboratory diagnostics.<\/p>\n<p class=\"wp-block-paragraph\">According to a <a href=\"https:\/\/www.abbott.com\/en-us\/corpnewsroom\/diagnostics-testing\/abbott-statement-on-cyber-incident-in-cancer-diagnostics-business\" rel=\"nofollow noopener\" target=\"_blank\">statement released by Abbott on July 16<\/a>:<\/p>\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">\u201cAbbott is investigating a cyber incident in which there was unauthorized access to a limited number of internal systems in our Cancer Diagnostics business only. This does not impact any business operations, product or product availability, manufacturing or lab operations, or our ability to serve patients.\u201d<\/p>\n<\/blockquote>\n<p class=\"wp-block-paragraph\">Regarding LabCentral, Abbott told <a href=\"https:\/\/www.reuters.com\/business\/abbott-investigates-two-separate-cyber-incidents-says-no-operations-affected-2026-07-17\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">reporters<\/a> that it is an externally hosted portal and that there has been \u201cno known exposure of sensitive customer or business information.\u201d<\/p>\n<p class=\"wp-block-paragraph\">ShinyHunters told <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/abbott-laboratories-probes-two-cyber-incidents-amid-extortion-claims\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">BleepingComputer<\/a> it stole internal documents, contracts, customer information, more than 22 million doctor\u2011patient notes, over 20 million medical orders, and more than one million US Social Security numbers, along with personally identifiable information (PII) such as names, addresses, dates of birth, emails, and phone numbers.<\/p>\n<p class=\"wp-block-paragraph\">On July 18, ShinyHunters gave Abbott until July 21 to respond before leaking the alleged data:<\/p>\n<p><img fetchpriority=\"high\" decoding=\"async\" width=\"301\" height=\"442\" src=\"https:\/\/www.europesays.com\/ie\/wp-content\/uploads\/2026\/07\/ShinyH_complete.png\" alt=\"Extended deadline\" class=\"wp-image-439142\"  \/>Extended deadline<\/p>\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">\u201cThis is a final warning to reach out by 21 July 2026 before we leak along with several annoying (digital) problems that\u2019ll come your way. Make the right decision, don\u2019t be the next headline\u201d<\/p>\n<\/blockquote>\n<p class=\"wp-block-paragraph\">The  threat of \u201cdigital problems\u201d is a familiar one from ShinyHunters. During the <a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2026\/05\/shinyhunters-escalates-canvas-attacks-with-school-login-defacements\" rel=\"nofollow noopener\" target=\"_blank\">Canvas attacks<\/a>, the group defaced school login pages and the Canvas app with an on\u2011screen ransom message.<\/p>\n<p class=\"wp-block-paragraph\">Separately, ShadowByt3$ claims it accessed the LabCentral portal on July 4, using compromised customer credentials plus a \u201cweak point\u201d in the environment, allegedly exfiltrating technical documentation, manufacturing certificates, operating manuals, technical specs, and regulatory docs for Abbott lab systems.<\/p>\n<p class=\"wp-block-paragraph\">If the attackers\u2019 claims prove accurate, the breach could affect healthcare providers that use Abbott\u2019s diagnostic systems and potentially expose sensitive patient and healthcare data. Abbott, however, says it has found no evidence that sensitive customer or business information was exposed through the LabCentral incident and has not confirmed any patient data was compromised.<\/p>\n<p>What we can reasonably assume to be true<\/p>\n<ul class=\"wp-block-list\">\n<li>There was a genuine compromise affecting Cancer Diagnostics systems. Abbott has publicly acknowledged unauthorized access and engaged incident response and law enforcement. This doesn\u2019t appear to be a purely \u201cfake\u201d extortion attempt. <\/li>\n<li>There was also a separate cyber incident involving the LabCentral portal. Abbott says the portal primarily hosts public reference material and that it has found no evidence that sensitive customer or business information was exposed.<\/li>\n<li>Both ShinyHunters and ShadowByt3$ have listed Abbott on their extortion sites and have provided narrative details to media outlets, so this is not just generic name\u2011dropping.<\/li>\n<li>As of the latest reporting, neither group has publicly released samples of the data they claim to have stolen.<\/li>\n<\/ul>\n<p>What Abbott customers can do<\/p>\n<p class=\"wp-block-paragraph\">There are some actions you can take if you are, or suspect you may have been, the\u00a0<a href=\"https:\/\/www.malwarebytes.com\/blog\/personal\/2023\/09\/involved-in-a-data-breach-heres-what-you-need-to-know\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">victim of a data breach<\/a>.<\/p>\n<ul class=\"wp-block-list\">\n<li><strong>Check the vendor\u2019s advice.<\/strong>\u00a0Every breach is different, so check with the vendor to find out what\u2019s happened and follow any specific advice they offer.<\/li>\n<li><strong>Change your password.<\/strong>\u00a0You can make a stolen password useless to thieves by changing it. Choose a\u00a0<a href=\"https:\/\/www.malwarebytes.com\/computer\/how-to-create-a-strong-password\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">strong password<\/a>\u00a0that you don\u2019t use for anything else. Better yet, let a\u00a0<a href=\"https:\/\/www.malwarebytes.com\/what-is-password-manager\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">password manager<\/a>\u00a0choose and store one for you.<\/li>\n<li><strong>Enable two-factor authentication (2FA).<\/strong>\u00a0If you can, use a FIDO2-compliant hardware key, laptop, or phone as your second factor. Some forms of\u00a0<a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2023\/10\/multi-factor-authentication-has-proven-it-works-so-what-are-we-waiting-for\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">2FA<\/a>\u00a0can be phished just as easily as a password. 2FA that relies on a FIDO2 device can\u2019t be phished.<\/li>\n<li><strong>Watch out for impersonation scams.<\/strong>\u00a0Criminals may contact you pretending to be the company. Check the company\u2019s website to see how it is contacting affected customers, and verify anyone who contacts you\u00a0using a different communication channel.<\/li>\n<li><strong>Take your time.<\/strong>\u00a0Phishing attacks often impersonate people or brands you know, and create a false sense of urgency with messages about missed deliveries, suspended accounts, or security alerts.<\/li>\n<li><strong>Consider not storing your card details<\/strong>. It\u2019s definitely more convenient to get sites to remember your card details for you, but we highly recommend not storing that information on websites.<\/li>\n<li><strong>Set up identity monitoring.<\/strong>\u00a0<a href=\"https:\/\/go.cyrus.app\/MN4j\/fkkekmw9\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Identity monitoring<\/a>\u00a0alerts you if your personal information is found being traded illegally online and helps you recover if your identity is stolen.<\/li>\n<\/ul>\n<p class=\"wp-block-paragraph\"><strong>What do cybercriminals know about you?<\/strong><\/p>\n<p class=\"wp-block-paragraph\"> Use Malwarebytes\u2019 free <strong>Digital Footprint scan <\/strong>to see whether your personal information has been exposed online.<\/p>\n","protected":false},"excerpt":{"rendered":"Abbott Laboratories, one of the world\u2019s largest healthcare and medical device companies, is investigating two apparently unrelated cyber&hellip;\n","protected":false},"author":2,"featured_media":596031,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_share_on_mastodon":"0"},"categories":[275],"tags":[77782,18,135,475,474,19,17,252367,151129],"class_list":["post-596030","post","type-post","status-publish","format-standard","has-post-thumbnail","category-healthcare","tag-abbott","tag-eire","tag-health","tag-health-care","tag-healthcare","tag-ie","tag-ireland","tag-shadowbyt3","tag-shinyhunters"],"share_on_mastodon":{"url":"https:\/\/pubeurope.com\/@ie\/116955565184921191","error":""},"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/posts\/596030","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/comments?post=596030"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/posts\/596030\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/media\/596031"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/media?parent=596030"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/categories?post=596030"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/tags?post=596030"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}