Abbott Laboratories Investigates Two Major Cybersecurity Breaches Linked to ShinyHunters and ShadowByt3$

Abbott Laboratories Investigates Two Major Cybersecurity Breaches Linked to ShinyHunters and ShadowByt3$

Abbott Laboratories is currently addressing two significant cybersecurity incidents that have impacted its Cancer Diagnostics and Core Laboratory diagnostics divisions. The first incident involves unauthorized access to legacy Exact Sciences systems, attributed to the ShinyHunters extortion group. This group claims to have exfiltrated sensitive data and has threatened public disclosure unless negotiations are initiated. The second incident involves a claim from the threat actor ShadowByt3$, alleging a breach of the LabCentral customer portal. Abbott asserts that this portal contains only public, non-sensitive documents. As of now, the company reports no disruption to business operations or patient services and has engaged cybersecurity experts and law enforcement. The full extent of data exposure is still under investigation, with no public indicators of compromise (IOCs) released.

Technical Overview of the Incidents

The first incident specifically targeted Abbott’s Cancer Diagnostics business, focusing on legacy Exact Sciences systems. According to Abbott, the attack was initiated through a vishing campaign linked to the ShinyHunters group. Vishing, or voice phishing, is a social engineering tactic where attackers impersonate trusted parties over the phone to trick employees into revealing credentials or multi-factor authentication (MFA) codes. The attackers reportedly compromised a Microsoft Entra (formerly Azure Active Directory) single sign-on (SSO) account, which allowed them access to internal systems and connected software-as-a-service (SaaS) applications.

Once initial access was gained, the attackers allegedly moved laterally within the environment, targeting various SaaS platforms such as Salesforce, Microsoft 365, Google Workspace, and SAP. They claimed to have exfiltrated large volumes of data, including personally identifiable information (PII), internal documents, and customer information. The extortion group has threatened to leak this data unless Abbott engages in negotiations, using their data leak site as leverage.

Details of the LabCentral Breach

The second incident pertains to the LabCentral customer portal, which serves Abbott’s Core Laboratory diagnostics business. The threat actor ShadowByt3$ claimed to have gained access using compromised customer credentials, exploiting a “weak point” in the externally facing environment. They stated that access was obtained on July 4, 2026, and that files were exfiltrated by targeting API endpoints. Allegedly stolen data includes CE manufacturing certificates, operation manuals, and regulatory documentation. However, Abbott maintains that the portal only contains publicly available technical reference documents and does not store proprietary or sensitive customer information.

Threat Activity and Attribution

The ShinyHunters group has a documented history of targeting organizations for financial gain through data theft and extortion. Their tactics include social engineering, SSO and MFA abuse, and SaaS data theft. Previous campaigns have targeted various sectors, including healthcare, with notable incidents involving companies such as Medtronic and Stryker. Attribution to ShinyHunters is assessed with high confidence based on direct extortion claims and consistent tactics.

In contrast, the ShadowByt3$ group is less well-documented but is known for opportunistic breaches of exposed or weakly protected portals and APIs. Attribution to ShadowByt3$ is assessed with medium confidence due to self-attribution and circumstantial evidence, lacking independent technical verification.

Mitigation Strategies

Organizations are advised to conduct an immediate review and hardening of SSO and MFA configurations, particularly for Microsoft Entra, Okta, and Google SSO accounts. Robust employee training should be implemented to help staff recognize and report vishing and other social engineering attempts. Regular audits of SaaS integrations and third-party portals are essential to identify and remediate misconfigurations or weak authentication controls. Monitoring for abnormal access patterns, especially involving API endpoints, is also recommended.

High-priority actions include enforcing strong password policies, enabling phishing-resistant MFA (such as FIDO2 security keys), and restricting access to sensitive systems based on least privilege principles. Medium-priority actions involve reviewing and updating incident response plans and conducting tabletop exercises. Low-priority actions include maintaining up-to-date documentation of all SaaS and third-party integrations.

No public indicators of compromise (IOCs) were available at the time of writing, and organizations should validate any future indicators before enforcement.

For further details, refer to the report by cyberwarriorsmiddleeast.com.

Explore the latest digital editions of FAME Delivered in the Magazine section.

Published on 2026-07-20 16:49:00 • By FAME Delivered News Desk

Abbott Laboratories Investigates Two Major Cybersecurity Breaches Linked to ShinyHunters and ShadowByt3$

Abbott Laboratories Investigates Two Major Cybersecurity Breaches Linked to ShinyHunters and ShadowByt3$

Abbott Laboratories is currently addressing two significant cybersecurity incidents that have impacted its Cancer Diagnostics and Core Laboratory diagnostics divisions. The first incident involves unauthorized access to legacy Exact Sciences systems, attributed to the ShinyHunters extortion group. This group claims to have exfiltrated sensitive data and has threatened public disclosure unless negotiations are initiated. The second incident involves a claim from the threat actor ShadowByt3$, alleging a breach of the LabCentral customer portal. Abbott asserts that this portal contains only public, non-sensitive documents. As of now, the company reports no disruption to business operations or patient services and has engaged cybersecurity experts and law enforcement. The full extent of data exposure is still under investigation, with no public indicators of compromise (IOCs) released.

Technical Overview of the Incidents

The first incident specifically targeted Abbott’s Cancer Diagnostics business, focusing on legacy Exact Sciences systems. According to Abbott, the attack was initiated through a vishing campaign linked to the ShinyHunters group. Vishing, or voice phishing, is a social engineering tactic where attackers impersonate trusted parties over the phone to trick employees into revealing credentials or multi-factor authentication (MFA) codes. The attackers reportedly compromised a Microsoft Entra (formerly Azure Active Directory) single sign-on (SSO) account, which allowed them access to internal systems and connected software-as-a-service (SaaS) applications.

Once initial access was gained, the attackers allegedly moved laterally within the environment, targeting various SaaS platforms such as Salesforce, Microsoft 365, Google Workspace, and SAP. They claimed to have exfiltrated large volumes of data, including personally identifiable information (PII), internal documents, and customer information. The extortion group has threatened to leak this data unless Abbott engages in negotiations, using their data leak site as leverage.

Details of the LabCentral Breach

The second incident pertains to the LabCentral customer portal, which serves Abbott’s Core Laboratory diagnostics business. The threat actor ShadowByt3$ claimed to have gained access using compromised customer credentials, exploiting a “weak point” in the externally facing environment. They stated that access was obtained on July 4, 2026, and that files were exfiltrated by targeting API endpoints. Allegedly stolen data includes CE manufacturing certificates, operation manuals, and regulatory documentation. However, Abbott maintains that the portal only contains publicly available technical reference documents and does not store proprietary or sensitive customer information.

Threat Activity and Attribution

The ShinyHunters group has a documented history of targeting organizations for financial gain through data theft and extortion. Their tactics include social engineering, SSO and MFA abuse, and SaaS data theft. Previous campaigns have targeted various sectors, including healthcare, with notable incidents involving companies such as Medtronic and Stryker. Attribution to ShinyHunters is assessed with high confidence based on direct extortion claims and consistent tactics.

In contrast, the ShadowByt3$ group is less well-documented but is known for opportunistic breaches of exposed or weakly protected portals and APIs. Attribution to ShadowByt3$ is assessed with medium confidence due to self-attribution and circumstantial evidence, lacking independent technical verification.

Mitigation Strategies

Organizations are advised to conduct an immediate review and hardening of SSO and MFA configurations, particularly for Microsoft Entra, Okta, and Google SSO accounts. Robust employee training should be implemented to help staff recognize and report vishing and other social engineering attempts. Regular audits of SaaS integrations and third-party portals are essential to identify and remediate misconfigurations or weak authentication controls. Monitoring for abnormal access patterns, especially involving API endpoints, is also recommended.

High-priority actions include enforcing strong password policies, enabling phishing-resistant MFA (such as FIDO2 security keys), and restricting access to sensitive systems based on least privilege principles. Medium-priority actions involve reviewing and updating incident response plans and conducting tabletop exercises. Low-priority actions include maintaining up-to-date documentation of all SaaS and third-party integrations.

No public indicators of compromise (IOCs) were available at the time of writing, and organizations should validate any future indicators before enforcement.

For further details, refer to the report by cyberwarriorsmiddleeast.com.

Explore the latest digital editions of FAME Delivered in the Magazine section.

Published on 2026-07-20 16:49:00 • By FAME Delivered News Desk

Latest Posts

Latest Posts

Don't Miss

Subscribe

To be updated with all the latest news, offers and special announcements.