NG Solution Team
Cybersecurity

Did Abbott Laboratories face two separate cyber incidents involving ShinyHunters and ShadowByt3$?

Abbott Laboratories is investigating two cybersecurity incidents affecting its Diagnostics operations — one tied to unauthorized access of legacy Exact Sciences systems claimed by extortion group ShinyHunters, and another involving an alleged intrusion of the LabCentral customer portal attributed to the collective ShadowByt3$. The company says it has, so far, observed no impact to product availability or patient services.

## Key facts
At the core of the matter: access obtained via social-engineering techniques and exploitation of SSO accounts, according to information released by Abbott and external reports. ShinyHunters claims to have exfiltrated large volumes of data from Exact Sciences’ legacy systems and has issued extortion demands. Separately, ShadowByt3$ says it accessed the LabCentral portal using compromised customer credentials and extracted technical and regulatory documents. Abbott disputes the sensitivity of those documents, stating the portal primarily contains publicly available materials.

## Observed attack methods and vectors
At this stage, neither incident appears to involve destructive malware. The first incident is reported to have resulted from a vishing (voice-phishing) campaign that enabled attackers to obtain MFA codes or SSO access to Microsoft Entra (formerly Azure AD). The adversaries then allegedly used valid accounts to move laterally and target a range of SaaS services (Microsoft 365, Google Workspace, Salesforce, Slack, Dropbox, ServiceNow, SharePoint, Databricks, Coupa, SAP, Adobe, Atlassian, Zendesk). The second incident highlights the exploitation of customer accounts and the querying of exposed APIs to exfiltrate files.

These techniques map to recognized categories (voice phishing, valid-account misuse, abuse of OAuth/MFA tokens, exfiltration via web services) and align with documented tactics used by groups such as ShinyHunters.

## Timeline and known scope
The compromise of Exact Sciences’ legacy systems reportedly occurred in mid‑June 2026, with public disclosures and extortion demands surfacing in July 2026. The LabCentral portal access is, according to the attacker, dated 4 July 2026; Abbott says it became aware of the incident shortly thereafter. As of 17 July 2026, neither ShinyHunters nor ShadowByt3$ had published the alleged stolen data, and no public indicators of compromise (IOCs) had been released.

Abbott asserts that no other business units, manufacturing operations, or patient services were affected. The company has activated its incident response procedures, engaged external cybersecurity specialists, and notified law enforcement.

## Attribution and credibility of the claims
Attribution to ShinyHunters is being evaluated as…

Related posts

Is Anthropic’s Claude Code a security risk due to a backdoor?

Michael Johnson

Has Novo Nordisk Fallen Victim to a Major Cybersecurity Breach?

Emily Brown

Are 100 universities at risk due to a PeopleSoft vulnerability?

David Jones

This website uses cookies to improve your experience. We assume you agree, but you can opt out if you wish. Accept More Info

Privacy & Cookies Policy