Abbott Laboratories Investigates Two Major Cybersecurity Breaches Linked to ShinyHunters and ShadowByt3$

Date:

Abbott Laboratories Investigates Two Major Cybersecurity Breaches Linked to ShinyHunters and ShadowByt3$

Abbott Laboratories is currently addressing two serious cybersecurity incidents that have impacted its Cancer Diagnostics and Core Laboratory diagnostics divisions. The first incident involves unauthorized access to legacy Exact Sciences systems, attributed to the ShinyHunters extortion group, which claims to have stolen sensitive data and threatened public disclosure unless negotiations are initiated. The second incident concerns a breach of the LabCentral customer portal, allegedly executed by the threat actor ShadowByt3$, who asserts that they accessed the portal using compromised customer credentials. Abbott maintains that the LabCentral portal contains only public, non-sensitive documents. As of now, the company reports no disruption to business operations or patient services and has enlisted cybersecurity experts and law enforcement to investigate further. The full extent of data exposure is still being assessed, with no public indicators of compromise (IOCs) released.

Technical Overview of the Incidents

The first incident specifically targeted Abbott’s Cancer Diagnostics business, particularly the legacy Exact Sciences systems. According to Abbott, the attack was initiated through a vishing campaign linked to the ShinyHunters group. Vishing, or voice phishing, is a social engineering tactic where attackers impersonate trusted individuals over the phone to deceive employees into disclosing credentials or multi-factor authentication (MFA) codes. The attackers reportedly compromised a Microsoft Entra (formerly Azure Active Directory) single sign-on (SSO) account, which allowed them access to internal systems and connected Software as a Service (SaaS) applications.

Once inside, the attackers allegedly moved laterally within the environment, targeting various SaaS platforms, including Salesforce, Microsoft 365, Google Workspace, and SAP. They claimed to have exfiltrated substantial volumes of data, including personally identifiable information (PII), internal documents, and customer information. The extortion group has threatened to leak this data unless Abbott engages in negotiations, using their data leak site as leverage.

Details of the LabCentral Breach

The second incident revolves around the LabCentral customer portal, which supports Abbott’s Core Laboratory diagnostics business. The threat actor ShadowByt3$ claims to have gained access by exploiting a “weak point” in the externally facing environment using compromised customer credentials. They stated that access was obtained on July 4, 2026, and that files were exfiltrated by targeting API endpoints. Allegedly stolen data includes CE manufacturing certificates, operational manuals, and regulatory documentation. However, Abbott asserts that the LabCentral portal only contains publicly available technical reference documents and does not hold proprietary or sensitive customer information.

Threat Activity and Attribution

The ShinyHunters group has a documented history of targeting organizations for financial gain through data theft and extortion. Their tactics include social engineering, SSO and MFA abuse, and SaaS data theft. Previous campaigns have targeted various sectors, including healthcare, with notable incidents involving companies such as Medtronic and Stryker. Attribution to ShinyHunters is assessed with high confidence based on direct extortion claims and consistent operational tactics.

Conversely, the ShadowByt3$ group is less well-documented but is recognized for opportunistic breaches of exposed or weakly protected portals and APIs. Attribution to ShadowByt3$ is assessed with medium confidence due to self-attribution and circumstantial evidence, lacking independent technical verification.

Mitigation Strategies

Organizations are advised to conduct an immediate review and enhancement of SSO and MFA configurations, particularly for Microsoft Entra, Okta, and Google SSO accounts. Implementing robust employee training to recognize and report vishing and other social engineering attempts is crucial. Regular audits of SaaS integrations and third-party portals are essential to identify and rectify misconfigurations or weak authentication controls. Monitoring for abnormal access patterns, especially involving API endpoints, is also recommended.

High-priority actions include enforcing strong password policies, enabling phishing-resistant MFA (such as FIDO2 security keys), and restricting access to sensitive systems based on least privilege principles. Medium-priority actions involve reviewing and updating incident response plans and conducting tabletop exercises. Low-priority actions include maintaining up-to-date documentation of all SaaS and third-party integrations.

As of this report, no public indicators of compromise (IOCs) have been made available, and organizations are encouraged to validate any future indicators before enforcement.

For further details, refer to the report by cyberwarriorsmiddleeast.com.

For ongoing coverage and breaking updates, visit our Latest News section.

Published on 2026-07-20 16:49:00 • By the Editorial Desk

Share post:

Subscribe

Popular

More like this
Related

1Password Strengthens Secure Credential Management for AI Agents with Claude Integration

1Password Strengthens Secure Credential Management for AI Agents with...

Sophos Launches Sophos Fusion: A Comprehensive AI-Native Cybersecurity Defense System for Modern Threats

Sophos Launches Sophos Fusion: A Comprehensive AI-Native Cybersecurity Defense...

Legacy Systems, Real-World Risks: Navigating the Critical Challenges of OT Security

Legacy Systems, Real-World Risks: Navigating the Critical Challenges of...