Abbott Laboratories, one of the world's largest healthcare and medical device makers, is investigating two apparently separate cyber incidents after confirming that intruders reached internal systems. Two extortion crews, ShinyHunters and ShadowByt3$, say the breaches were far larger than Abbott has acknowledged, but neither has published any stolen data and their claims remain unverified.
According to the Malwarebytes Data Breaches team, the incidents involve Abbott's Cancer Diagnostics business and its LabCentral customer portal for core laboratory diagnostics. Abbott said unauthorized access was "limited to internal systems of the Cancer Diagnostics business only," with no impact on manufacturing, lab operations, product availability, or patient care. It described LabCentral as an externally hosted portal with "no known exposure of sensitive customer or business information."
What the attackers claim
The two groups tell a very different story. ShinyHunters claims it stole internal documents, contracts, and customer information, along with more than 22 million doctor-patient notes, over 20 million medical orders, and more than one million US Social Security numbers, plus names, addresses, dates of birth, emails, and phone numbers. On July 18 the group gave Abbott until July 21 to respond before leaking the data, warning the company not to "be the next headline."
Separately, ShadowByt3$ says it accessed the LabCentral portal on July 4 using compromised customer credentials and a "weak point" in the environment, allegedly taking technical documentation, manufacturing certificates, operating manuals, and regulatory paperwork for Abbott lab systems.
Why it matters
If the claims hold up, the fallout could reach hospitals and labs that rely on Abbott's diagnostic systems, and expose sensitive patient and healthcare data. For now, that is a big "if": Abbott says it has found no evidence that sensitive customer or business information was exposed through LabCentral, and neither gang has released samples to back up its numbers. What is not in dispute is that a genuine compromise touched Cancer Diagnostics systems, that Abbott has engaged incident response and law enforcement, and that both groups have listed the company on their extortion sites with specific narrative details rather than generic name-dropping.
ShinyHunters has a long track record of high-pressure extortion. IntelFusions has tracked the group's breach of universities through an Oracle PeopleSoft zero-day and its leak-site claims against Fluke and Ingram Content. The threat of "digital problems" echoes earlier campaigns in which the crew defaced victim login pages to amplify pressure.
What Abbott customers can do
- Watch for updates from Abbott and follow any guidance it issues to affected customers.
- Reset passwords for any Abbott-linked portal accounts and avoid reusing them elsewhere.
- Turn on phishing-resistant two-factor authentication, ideally a FIDO2 hardware key, wherever it is offered.
- Treat unexpected calls or emails referencing the incident as possible impersonation, and verify through a separate channel before acting.
IntelFusions assesses the core compromise as real but the full scope of stolen data as unconfirmed pending any actual leak. We will update as the July 21 deadline passes.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.