ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Abbott Investigates Cybersecurity Incidents After Hackers Claim Data Breach

Abbott Laboratories, the US-based medical devices and healthcare company, said it is investigating two cybersecurity incidents after hacker groups alleged they had breached its internal network and stolen confidential information.

 

Abbott Laboratories is an American multinational healthcare and medical devices company headquartered in Abbott Park, Illinois. It specialises in diagnostics, diabetes care, cardiovascular devices, nutrition products, and branded generic pharmaceuticals, with operations in more than 160 countries.

 

The ShinyHunters extortion group recently claimed it breached Abbott Laboratories’ internal network by using voice phishing to compromise an employee and gain access to the company’s Microsoft Entra single sign-on (SSO) environment. The group alleges it exfiltrated confidential data from multiple connected SaaS platforms, including more than 30 million records containing personal information, over one million Social Security numbers, medical orders, and doctor-patient notes.

 

Acknowledging the claims of the hacker group, in a data security incidents notice published on its website, Abbott Laboratories said it is investigating a data security incident that affected “limited number of internal systems in our Cancer Diagnostics business.”

 

“This does not impact any business operations, product or product availability, manufacturing or lab operations, or our ability to serve patients. There is no impact to any other Abbott businesses, sites or systems. The legacy Exact Sciences systems are separate from Abbott’s,” the company said.

 

Abbott Laboratories said it has involved external cybersecurity experts to help with the investigation and has notified relevant law enforcement authorities about the incident.

 

Around the same time, another threat actor operating under the moniker "ShadowByt3S" claimed to have breached Abbott Laboratories and exfiltrated approximately 690 MB of data. The stolen information included E-certificates, manufacturing compliance documents, laboratory automation operation manuals, technical specifications and product documentation, regulatory and reference materials, standard operating procedures (SOPs), troubleshooting guides, and product requirement documentation. According to the threat actor, the data was obtained through unauthorised API access, although these claims have not been independently verified.

 

The threat actor also claims to possess supporting evidence, including emails, screenshots, and file listings, and has threatened to publish the allegedly stolen data unless Abbott responds within 48 hours.

 

Acknowledging the claims of the threat actor, in a statement shared with BleepingComputer, Abbott said it is aware of the “potential” cyber incident.

 

“LabCentral is an externally facing third-party hosted portal used by Abbott’s core laboratory diagnostics business.

 

“It houses publicly available technical product reference documents, including operating manuals, troubleshooting checklists and product specifications, and does not contain proprietary/sensitive customer or business information,” an Abbott spokesperson added.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543