← Back to Tech & Science

Abbott Laboratories Investigates Two Cybersecurity Incidents Involving Extortion Claims

Tech & ScienceAI-Generated & Algorithmically Scored·

AI-generated from multiple sources. Verify before acting on this reporting.

CHICAGO — Abbott Laboratories announced on July 17, 2026, that it is investigating two separate cybersecurity incidents involving unauthorized access to internal systems and potential data breaches. The global healthcare company stated the intrusions targeted legacy Exact Sciences systems within its Cancer Diagnostics business unit and potentially compromised its LabCentral portal.

The first incident involved a threat actor known as ShadowByt3$, who claimed unauthorized access to Abbott's internal legacy infrastructure formerly belonging to Exact Sciences, which Abbott acquired in 2019. The second incident involves the ShinyHunters extortion gang, which has publicly asserted that it breached the company's networks and is demanding payment to prevent further data exposure.

Abbott confirmed that an investigation is underway to determine the full scope of both events. The company noted that while unauthorized access was detected in specific legacy environments, there is currently no evidence indicating a compromise of patient records or personally identifiable information beyond what has been publicly disclosed by the threat actors themselves. However, the potential breach of the LabCentral portal remains under active review.

The ShinyHunters group released statements claiming possession of sensitive data and issued an extortion demand against Abbott Laboratories. The gang's communications suggested that failure to meet their demands would result in the public release of stolen information. Simultaneously, ShadowByt3$ has been linked to unauthorized access attempts within the Cancer Diagnostics division, though specific details regarding the volume or type of accessed files have not been fully disclosed by either party.

Abbott Laboratories emphasized that it is working with cybersecurity experts and law enforcement agencies to contain the incidents. The company stated its priority remains protecting patient safety and maintaining the integrity of its diagnostic services. No service disruptions were reported at the time of the announcement, but Abbott advised customers utilizing the LabCentral portal to remain vigilant.

The exact timeline of when the initial intrusions occurred has not been specified by Abbott or the threat actors. While ShinyHunters claims a recent breach date, ShadowByt3$ activity may have spanned an earlier period involving legacy systems that were integrated into Abbott's network following previous acquisitions.

Questions remain regarding whether any patient data was exfiltrated during either incident and if other business units beyond Cancer Diagnostics are affected. As the investigation continues, Abbott has not confirmed whether it will engage in negotiations with either group or pay any ransom demands. The company expects to provide further updates as more information becomes available.

Discussion

0 / 2000