All incidents

Abbott Laboratories investigates two cyber incidents affecting Cancer Diagnostics and LabCentral

incidentopenJul 19, 2026 — Jul 20, 2026
Abbott Laboratories investigates two cyber incidents affecting Cancer Diagnostics and LabCentral

ABBOTT Laboratories is investigating two separate cyber incidents affecting its Cancer Diagnostics business and the externally hosted LabCentral portal, after hacker groups ShinyHunters and ShadowByt3$ claimed to have stolen large volumes of sensitive data. The company says it has found no evidence of operational disruption or data exposure, but the attackers have threatened to publish the alleged material unless contacted by 21 July 2026 Abbott's statement.

The Cancer Diagnostics incident involved unauthorised access detected on 16 July, while the LabCentral breach is said to have originated from compromised customer credentials that allowed the ShadowByt3$ gang to exfiltrate technical documents related to Abbott’s diagnostics systems. No CVEs have been associated with these events, and Abbott has not disclosed the specific vulnerability that was exploited.

ShinyHunters is known for large‑scale data theft and extortion campaigns, often demanding payment to prevent the release of stolen information. ShadowByt3$, a newer group, has claimed responsibility for several intrusions targeting healthcare and technology firms, typically leveraging credential stuffing and phishing to gain initial footholds.

Although Abbott maintains that no patient records or personally identifiable information have been confirmed as leaked, the extortion deadline set by the attackers has raised concerns among healthcare providers and partners who rely on the LabCentral portal for test ordering and results distribution. Security researchers note that the timing of the threats coincides with a surge in ransomware‑themed extortion attempts across the medical sector.

Abbott advises its customers to review account activity, enable multi‑factor authentication where available and to rotate passwords for any credentials used with the LabCentral service. Organisations should also monitor for suspicious emails that reference the alleged breach and consider blocking any unauthorised download attempts from unfamiliar domains.

The firm has engaged external forensic experts, notified law enforcement and is working with its internal security team to validate the scope of access and to harden the affected environments against further intrusion. It promises to provide updates as the investigation progresses and to notify any impacted individuals should evidence of data loss emerge.

Intelligence briefing updated Jul 20, 2026

ShinyHunters
Root sourcewww.abbott.com
Timeline Coverage

Swipe to explore timeline