HACK/PROJECT Daily Threat Intelligence
Threat feed live Updated — 28.07.2026 10:32 CET 51 dossiers MITRE ATT&CK mapping

ShinyHunters and ShadowByt3$ — data-theft extortion; unverified claimshigh

Abbott, two incidents and two groups: what the company confirms and what the attackers claim

Abbott Laboratories is investigating two separate cyber incidents. The first, the company confirms: unauthorized access to a limited number of internal legacy Exact Sciences systems, in the Cancer Diagnostics business only; the extortion group ShinyHunters listed Abbott on its leak site and claims the theft of more than 30 million rows of personal data, including over one million US Social Security numbers — the group's figures, not confirmed. The second incident involves the LabCentral portal and an actor called ShadowByt3$; Abbott is aware of it but disputes the description of the data. A case that matters above all for method: separating what the company states from what the attackers assert.

The ransom without encryption

For years "ransomware" meant one precise thing: files get encrypted, and to get them back you pay. Today a growing share of extortion skips the encryption and goes straight to the point: steal the data and threaten to publish it. That is ShinyHunters' model, the group that added Abbott Laboratories to its leak site. There is no halted plant, no red screen: there is a countdown and the threat to release what was carried off. We place the case in this section for exactly that reason — it is the face of modern extortion — but with one rule up front: keep the facts Abbott confirms separate from the group's claims.

What Abbott confirms

On 17 July 2026 Abbott published an official statement, to which the company pointed when asked. The wording is measured. Abbott says it is investigating a cyber incident with unauthorized access to a limited number of internal systems in the Cancer Diagnostics business only. It adds that the incident does not impact operations, products, availability, manufacturing or lab activity, nor its ability to serve patients; that it has not touched any other Abbott business or system; and that the Exact Sciences legacy systems involved are separate from Abbott's own. The company activated its response procedures, engaged security experts and notified law enforcement, and does not expect a material impact on its financial results.

  1. 01
    Vishing on several employees
    phone calls, not a technical exploit (claimed)
  2. 02
    Microsoft Entra SSO account compromised
    the way into connected applications (claimed)
  3. 03
    Data theft and threat to publish
    the extortion countdown

What the group claims — and it is not confirmed

Here the register changes, and it must be flagged. According to what ShinyHunters told BleepingComputer, access reportedly began in mid-June from a vishing attack — voice phishing, phone calls — against several Abbott employees, which allegedly let it compromise a Microsoft Entra single sign-on account and reach internal systems. The group claims it stole data from Entra, ServiceNow, SharePoint, Databricks and Coupa: more than 30 million rows of personal data (names, emails, phone numbers, addresses, dates of birth) and over one million US Social Security numbers, plus 22 million clinical notes with doctor-patient conversations and 20 million medical orders. These are the group's figures. BleepingComputer explicitly writes that it has not independently verified them, and we do the same: we report them as claims, not established facts.

The attacker's profile helps read the case. ShinyHunters, for over a year, has run social-engineering campaigns aimed at corporate SSO accounts — Entra, Okta, Google — then steals data from connected SaaS applications. The group has increasingly targeted the medtech sector, with names such as Medtronic, OneMedical and AdaptHealth among those reported. It is a modus operandi in which the initial link is not a software vulnerability but a person talked into it on the phone.

The second incident, and the disagreement

Then there is a second actor, ShadowByt3$, who contacted BleepingComputer claiming to have breached Abbott's Core Laboratory business through the LabCentral customer portal, using compromised customer credentials, with access on 4 July and slow exfiltration via API endpoints. The group claims CE manufacturing certificates, operating manuals, technical specifications and regulatory documentation. Abbott confirms it is aware of a "potential" incident but disputes the description of the data: it says LabCentral is an externally facing, third-party hosted portal with publicly available technical product documentation — manuals, checklists, specifications — and no proprietary or sensitive customer or business information.

2
separate incidents
two different actors, ShinyHunters and ShadowByt3$
30M+
rows of data claimed
the group's figures, unverified
0
data published so far
neither has released what it claims

Why the method is the story

As we write, neither ShinyHunters nor ShadowByt3$ has published the data they say they hold. That leaves two parallel truths standing: the company confirms a limited, contained access, the group claims an enormous haul. Both can coexist for mundane reasons — extortion works better when the number is large — and the gap between them closes only with proof that, today, does not exist.

The MITRE IDs at the head of this dossier — vishing, valid accounts, exfiltration over a web service — are our reasoned mapping of the modus operandi as reported, not IDs copied from an official advisory: there is no agency bulletin here, there is the company's confirmation and a specialist outlet's account. The value of the case, for the reader, is not the record count: it is the reminder that the most effective way in is still a well-made phone call, and that defence starts there — from verifying who is calling and from phishing-resistant second factors, not from one more firewall.

More dossiers