```html ```
top of page

Two Different Crews Breached Abbott the Same Week — a Cancer-Diagnostics Unit and a Lab Portal. In March We Said Medical-Device Makers Were the Ones Getting Breached. Abbott Is the Receipt.

  • Writer: Patrick Duggan
    Patrick Duggan
  • 4 hours ago
  • 5 min read

Abbott Laboratories is dealing with two cyberattacks at once, from two unrelated crews, hitting two different parts of the company in the same window. That is unusual enough to note on its own. What makes it worth a full write-up is that we called this category — out loud, in March — and Abbott is the receipt.



Two breaches, two actors, one building


The first intrusion hit Abbott's Cancer Diagnostics business, specifically legacy systems from Exact Sciences, a company Abbott absorbed. The extortion gang ShinyHunters — tracked in the industry as UNC6040 — added Abbott to its leak site and set a deadline, first July 18, then extended to July 21. Their reported way in is the crew's signature move: a vishing call to an employee, used to compromise a Microsoft Entra single-sign-on account. Not a zero-day, not a firewall bug. A phone call and a login. This is the same playbook that drove the Salesforce and Drift OAuth wave we covered earlier this year, and it keeps working because it targets the person, not the perimeter.


The second intrusion is a different actor entirely, calling itself ShadowByt3$, and it hit Abbott's Core Laboratory diagnostics unit through its LabCentral customer portal. The method was quieter and, for a device maker, more alarming: compromised customer credentials, a "weak point" in the portal, access gained on July 4, and then a slow drip of files out through API endpoints. What they say they took is not marketing data. It is CE manufacturing certificates, assay files, calibrator value assignments, operation manuals, technical specifications, and regulatory documentation — the engineering and compliance core of a diagnostics business.


Abbott's position is that manufacturing, laboratory operations, and patient care were not affected. The two crews claim the damage is broader. Both things can be partly true; that gap is normal this early, and the forensics will settle it. What is not in dispute is that two independent attackers found two independent doors into the same medical-device giant in the same week.



Why the ShadowByt3$ haul is the part that should worry the industry


Ransomware headlines train you to look for encrypted servers and halted production. Neither happened here, and that makes this easy to under-rate. Look again at what ShadowByt3$ says it walked out with.


Calibrator value assignments and assay files are the numbers that make a diagnostic test read correctly. CE certificates and regulatory documentation are the paperwork that lets a device be sold in a regulated market. Operation manuals and technical specifications are the blueprint of how the machine works. That is not data you leak for embarrassment — it is data with value to a competitor, a counterfeiter, or anyone trying to understand or undermine how a medical test produces its result. A device maker's design-and-compliance archive is a different class of loss than a customer email list, and it is exactly the class of asset that does not show up as "downtime" on an incident summary. The quiet exfiltration of a diagnostics company's engineering files can be the most expensive breach on this list precisely because nothing broke.



The receipt: we named this category in March


Here is the comparator, and we hold ourselves to stating it with dates.


In March 2026 we published a thesis with a blunt title: medical-device makers are the ones getting breached. We backed it with receipts as they landed — we wrote "We Predicted Medtronic" with the timeline attached, we covered Stryker getting hit, and we argued that the device companies with the weakest visibility were the ones walking into it. That was four months ago. Abbott is the newest entry in exactly the category we flagged.


We will also be precise about what we did and did not do, because the honest version is the only one worth publishing. We did not predict the Abbott breach. What we can show is that Abbott was already inside our medical-device work before this happened: the company was in our vertical audit set, scored on March 15, 2026, four months before these disclosures. That tells you Abbott was on our radar as part of the category — it does not tell you we saw this coming, and we are not going to dress up a perception metric as a crystal ball. The defensible claim is the category one: we said the sector was the soft target, we said it in March, and the sector keeps proving it.


And one of the two actors here is one we already track. ShinyHunters / UNC6040 is in our adversary index, and the vishing-to-Entra-SSO technique it used on Abbott is the same one we have documented before. That is not a coincidence you discover after the fact — it is a known crew running a known play against a target profile we named.



What to actually do — especially if you're smaller than Abbott


The lesson generalizes down, which is the part we care about most. Abbott has a security budget; the mid-size diagnostics and device shops that run the same kind of infrastructure often do not, and they are the ones this pattern is quietly aimed at.


Two doors got Abbott, and both are common. The first is help-desk and SSO social engineering — the vishing-to-Entra path. Assume your identity provider is a target of phone calls, not just passwords: enforce phishing-resistant MFA, put hard verification on help-desk credential resets, and watch for single-sign-on grants that appear right after a support call. The second is a customer or partner portal with credential-based access to real data — the LabCentral path. Treat every external portal as an exfiltration surface: rate-limit and monitor the API endpoints behind it, alert on a single account pulling documents at machine pace, and remember that "compromised customer credentials" is not your customer's problem when the files that leave are yours.


And if you acquired another company, inventory what you inherited. The Cancer Diagnostics intrusion rode in through legacy Exact Sciences systems — the acquired estate, the part that is easy to forget is now your attack surface. M&A does not just add revenue; it adds somebody else's unpatched decisions to your perimeter.


We hold this at 95 percent, as always — the incident specifics and the attribution are Abbott's disclosure and the reporting around it, not our own capture. What is ours is the category call, dated to March, and the actor we already track. The device makers are the ones getting breached. We said it in the spring. Abbott is the summer receipt.




Sources: Abbott's disclosure and reporting via BleepingComputer, SC Media, and Malwarebytes. Our prior coverage of the medical-device breach thesis (March 2026) and ShinyHunters / UNC6040 tracking are at dugganusa.com. Abbott is a victim; no indicators were ingested from this disclosure.




Every indicator in this post is in the feed. Free.

1.58M+ IOCs, STIX 2.1 / TAXII, 88% novel vs ThreatFox, exploited-CVE leads ahead of CISA. No credit card — a free API key in 30 seconds, and you can audit every claim above against the live endpoints.


Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page