On July 16, 2026, Abbott Laboratories publicly confirmed that it is investigating unauthorized access to legacy computer systems belonging to Exact Sciences, the cancer-diagnostics company behind Cologuard and other at-home cancer screening tests, which Abbott acquired in late 2025. Abbott says the intrusion traces back to a vishing (voice phishing) attack against Abbott and Exact Sciences employees in mid-June 2026, which allowed attackers to compromise a Microsoft Entra single sign-on account and gain access to internal systems.
A cybercriminal group calling itself ShinyHunters has claimed responsibility and told the security news outlet BleepingComputer that it exfiltrated approximately 30 million rows of customer data, including roughly 1 million Social Security numbers, along with names, contact information, and dates of birth, from the legacy Exact Sciences systems. Abbott has not confirmed these figures. The company has acknowledged unauthorized access to the legacy systems but has not yet disclosed the scope or volume of data involved, and has stated it does not expect a material impact on its business or financial results.
Why This Matters
Abbott reportedly engaged with ShinyHunters, and the group’s leak deadline was extended to July 21, 2026. As of the most recent reporting, the claimed data had not yet been published, but that could change at any time, and Abbott has not said whether a payment was made to the attackers.
This breach originated from a vishing attack that specifically targeted Abbott and Exact Sciences employees, tricking staff into giving up credentials that opened the door to internal systems. Because no official breach notification has been sent to individuals and no state regulatory filing has been made yet, Emery | Reddy is currently focused on hearing from current and former Abbott and Exact Sciences employees who believe they may have been affected, whether through the compromised credentials themselves or the broader systems those credentials exposed.
A separate, apparently unrelated claim from a second group (ShadowByt3$) involves Abbott’s LabCentral customer portal. Abbott says that portal holds only non-sensitive public reference materials, and we are not treating it as part of this incident.
What Information Was Exposed?
According to the claims made by the ShinyHunters group, not yet confirmed by Abbott, the exposed data may include:
- Full name
- Contact information
- Full date of birth
- Social Security number (claimed for approximately 1 million individuals)
Treat these figures as an unconfirmed threat-actor claim pending Abbott’s own accounting of the incident.
What Is Abbott Offering Affected Individuals?
This is a pre-notice case: no official breach notification has been sent to individuals, and no state regulatory filing has been made as of this writing. Abbott has not yet announced credit monitoring, identity theft protection, or any other remedy. We will update this post as soon as Abbott issues formal notice.
Your Information Is at Risk
If the claimed data set holds up, the combination of full name, date of birth, and Social Security number is exactly the kind of information used to open fraudulent accounts and commit identity theft. Affected individuals, including current and former employees whose credentials may have been targeted, should:
- Watch for phishing, vishing, or unusual communications referencing Abbott or Exact Sciences
- If you believe your own login credentials may have been part of the compromised SSO access, reset your passwords and enable multi-factor authentication
- Monitor your credit reports and consider a fraud alert or credit freeze
- Save any communication you receive from Abbott about this incident
- Contact Emery | Reddy for a Free Case Review even before a formal notice is issued
Do You Have Legal Options?
Companies that collect and store sensitive personal information, including employee credentials and customer records, have a legal obligation to safeguard it. When that obligation is not met, affected individuals may have legal rights and remedies worth discussing with an attorney.
Contact the Data Breach Attorneys at Emery | Reddy today for a Free Case Review.
Your Personally Identifiable Information (PII) includes information that can be used to identify you, such as your name and other personal details. Organizations that manage healthcare data are legally required to safeguard this information. When PII is exposed in a data breach, it can potentially be used by cybercriminals to commit identity theft, financial fraud, or other misuse.
Much of the information involved in this incident may also qualify as Protected Health Information (PHI). PHI includes medical or healthcare-related data protected under federal and state privacy laws. When PHI is compromised, it can be misused for medical identity theft or insurance fraud.
Residents of California may be entitled to additional protections under the California Consumer Privacy Act (CCPA), which provides enhanced rights regarding the collection, use, and safeguarding of personal information.
FAQ
How many people were affected by the Abbott Laboratories data breach?
Not confirmed by Abbott. The threat actor ShinyHunters claims approximately 1 million Social Security numbers among 30 million rows of exfiltrated data; treat this as an unconfirmed claim pending Abbott’s own accounting.
What information was exposed?
Per the attacker’s claims (not yet Abbott-confirmed): full name, contact information, date of birth, and Social Security number for a subset of individuals.
Has Abbott sent notice letters?
Not yet. Abbott publicly confirmed the incident on July 16, 2026, but has not issued individual notification letters or a state regulatory filing as of this writing; this is a pre-notice case.
Why is Emery | Reddy reaching out to employees specifically?
The breach originated from a vishing attack targeting Abbott and Exact Sciences employee credentials. Since formal notice to the broader customer base hasn’t gone out yet, we’re currently gathering information from current and former employees who believe they may have been affected.
What should I do if I’m a current or former Abbott or Exact Sciences employee?
Contact us for a free case review, and if you believe your own credentials may have been part of the compromised SSO access, reset your passwords and enable multi-factor authentication.