- Abbott Laboratories was hit by two separate cyberattacks
- ShinyHunters claims to have exfiltrated 22 million doctor‑patient notes, among other things
- No data has yet been leaked
US healthcare and medical technology giant Abbott Laboratories has been struck by what appears to be two separate cyberattacks, just days apart - one by the infamous ShinyHunters threat actors, and another by The ShadowByt3$, with at least one of the groups currently negotiating a ransom payment.
Abbott, which is one of the largest healthcare companies globally with more than 100,000 employees, said it was investigating an incident in which someone accessed IT systems in its Cancer Di
agnostics department.
Latest Videos From
A day later, ShinyHunters added Abbott to its list of victims, saying it would release the stolen files on July 18 2026 unless the company pays the ransom. This date was later moved to July 21, suggesting that Abbott indeed kicked off the negotiations.
The ShadowByt3$ takes a bite of Abbot
Speaking to BleepingComputer, ShinyHunters operatives said they gained access to a corporate Microsoft Entra SSO account after a successful vishing attack on one of the employees.
The attackers said they stole internal documents, contracts, customer information, more than 22 million doctor-patient notes containing conversations, over 20 million medical orders, customer agreements, and NDAs.
Among the files are customer names, emails, phone numbers, postal addresses, and more than a million Social Security numbers.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
In the meantime, The ShadowByt3$ hacking collective also reached out to the publication to say they accessed Abbott’s LabCentral portal, a customer portal for core laboratory diagnostics.
While in this attack no customer data was stolen, the group said they pulled “sensitive technical documentation related to Abbott's laboratory diagnostic systems, including manufacturing certificates, operation manuals, technical specifications, and regulatory documents”.
No data has yet been leaked.
ShinyHunters is one of the most active threat actors these days, known for running ransomware attacks without deploying encryptors. By focusing solely on data exfiltration, the group achieved the same results, while cutting down on costs for developing and maintaining an encryptor.
It is also known for targeting healthcare organizations - in late April this year, one of the biggest medical device manufacturers in the world - Medtronic - confirmed suffering a cyberattack at the hands of ShinyHunters.
The best antivirus for all budgets
Our top picks, based on real-world testing and comparisons
Follow TechRadar on Google News andadd us as a preferred source to get our expert news, reviews, and opinion in your feeds.