Abbott Data Breach Exposes Social Security Numbers and Personal Information

Healthcare data breach illustration
Breach Discovery: June 2026Breach Notification: July 2026

What Happened in the Abbott Data Breach?

Abbott, the diagnostics and medical device company, is now investigating claims from two separate hacking groups. Both groups say they broke into systems connected to Abbott’s business and stole data. This Abbott data breach investigation covers two distinct incidents that surfaced around the same time.

The first claim comes from the ShinyHunters extortion group. This group says it targeted legacy systems belonging to Exact Sciences, the cancer diagnostics company Abbott acquired in late 2025. According to reports, the attackers used voice phishing calls against Abbott employees in mid-June 2026 to trick someone into giving up access credentials. As a result, the group says it compromised a Microsoft Entra single sign-on account, which then opened the door to internal systems.

Because these were legacy Exact Sciences systems, Abbott says the intrusion did not touch its other business lines. The company also states that manufacturing, lab operations, and its ability to serve patients were not affected. Abbott has confirmed unauthorized access occurred, though it has not yet confirmed the full extent of any patient data compromise.

Meanwhile, a second hacker using the name ShadowByt3$ claims to have separately broken into Abbott’s LabCentral customer portal. This person says they used stolen customer credentials to get in around July 4, 2026, then pulled data out over the following weekend. However, Abbott maintains that this third-party hosted portal only holds publicly available technical documents, not sensitive customer or patient information.

Abbott’s investigation into both claims is ongoing. The company issued a public statement on July 16, 2026, saying it does not expect either incident to have a material financial impact. Even so, the ShinyHunters claim involves far more serious allegations about the type and volume of data taken.

Who was affected?

The population affected by this breach appears to be customers connected to the Exact Sciences cancer diagnostics business that Abbott purchased in 2025. Because Exact Sciences focused on cancer screening and precision oncology testing, some of the exposed individuals could include patients who used those diagnostic services.

Abbott has not publicly disclosed a confirmed number of affected individuals. However, ShinyHunters claims to have exfiltrated 30 million rows of customer data. That claim, if accurate, would represent one of the larger healthcare-related breaches reported this year. The separate LabCentral incident, by contrast, reportedly did not involve customer or patient data at all, according to Abbott’s own assessment.

What Information Was Potentially Exposed?

According to the ShinyHunters group, the stolen data includes several categories of personal information. Abbott has not independently confirmed these claims in full, but the following data types have been alleged as exposed:

  • Full names
  • Contact information such as addresses, phone numbers, or emails
  • Dates of birth
  • Social Security numbers, affecting roughly one million individuals per the group’s claim

This combination of data is particularly concerning because it includes the exact pieces of information identity thieves need most. Names paired with dates of birth and Social Security numbers can be used to open new credit accounts, file fraudulent tax returns, or apply for loans in someone else’s name. For example, a criminal armed with this data could pass many standard identity verification checks used by banks and lenders.

In addition, because the underlying business involves cancer diagnostics, some affected individuals may worry about their health information being linked to this stolen data. Abbott has not confirmed that medical records or diagnostic results were part of the theft. Still, the exposure of Social Security numbers alone creates a long-term risk that does not go away once the news cycle ends. Victims often face fraud attempts for years after a breach like this.

What is the company doing?

Abbott has confirmed that unauthorized access occurred to certain legacy Exact Sciences systems and has launched an investigation into both threat actor claims. The company negotiated with ShinyHunters over the stolen data, and the group agreed to extend its publication deadline to July 21, 2026. As of the most recent update, no stolen data has appeared publicly.

Abbott has stated that the intrusion did not affect its broader operations, products, or manufacturing capabilities. The company is also investigating the separate LabCentral portal claim, though it believes only non-sensitive, publicly available technical documents were involved there. Abbott has not yet announced whether it will offer credit monitoring or identity protection services to affected individuals, since the scope of confirmed data loss is still being determined.

What Should Affected Individuals Do?

Monitor Your Credit Reports Closely

Anyone who may have used Exact Sciences diagnostic services should check their credit reports for unfamiliar activity. You can request free credit reports from each of the three major bureaus and review them for accounts you did not open.

Because Social Security numbers were allegedly stolen, this step matters even more than usual. Identity thieves sometimes wait months before using stolen data, so continued monitoring over the coming year is important, not just a one-time check.

Consider a Credit Freeze or Fraud Alert

Given that Social Security numbers may have been exposed, placing a credit freeze with each bureau is a strong protective step. A freeze blocks most lenders from opening new credit in your name until you lift it.

Alternatively, a fraud alert makes it harder for identity thieves to open accounts, since it requires lenders to verify your identity before extending credit. This option is easier to manage than a freeze but offers a bit less protection. Either way, acting sooner rather than later reduces your risk window.

Watch for Phishing and Vishing Attempts

Since this breach reportedly began with voice phishing calls against employees, affected individuals should be alert for similar tactics. Scammers may call, text, or email pretending to represent Abbott, a bank, or a government agency.

You should never give out personal information to unsolicited callers, even if they seem to know some of your details already. Instead, hang up and contact the organization directly using a verified phone number. This simple habit can prevent a lot of downstream fraud.

Review Medical and Insurance Statements

Because the affected systems relate to a cancer diagnostics business, it makes sense to review any medical bills or insurance explanation-of-benefits statements for services you did not receive. Medical identity theft can be harder to detect than financial fraud.

If you notice unfamiliar charges or claims, contact your health insurer and the provider listed right away. Keeping records of your normal healthcare providers also helps you spot anything unusual more quickly.

Seek Legal Guidance if You Are Affected

If you believe your information was part of this breach, consulting a data breach attorney can help clarify your options. Many attorneys offer free case evaluations to determine whether you qualify for compensation.

Because litigation around healthcare data breaches often develops over the following months, staying informed about deadlines is important. An attorney can also help you understand what documentation to keep in case a class action or settlement becomes available.



More Information

Official data breach notification from California Attorney General

Related Data Breaches