Abbott Laboratories is investigating two potentially unrelated cybersecurity incidents. One concerns the internal systems of the Cancer Diagnostics division, and the other concerns the LabCentral portal, which is used by customers of the company’s laboratory solutions.
On 16 July, Abbott confirmed that unauthorised individuals had gained access to a limited number of systems within its Cancer Diagnostics division. According to the company, the attack did not disrupt production, laboratory operations, product availability or patient care. Abbott’s other units and systems are reported to be operating normally. The company has engaged external experts and law enforcement agencies and does not currently expect the incident to have a material impact on its financial results.
The ShinyHunters group has claimed responsibility for the attack. Its representatives claim that in mid-June they carried out a vishing campaign, i.e. phishing via telephone calls. In this way, they allegedly gained access to employees’ accounts and to the company’s Microsoft Entra login system and its associated applications.
According to the group, the stolen data includes internal documents, contracts, customer information, over 22 million notes containing conversations between doctors and patients, and more than 20 million medical orders. The dataset is also said to contain names, addresses, dates of birth and over a million US Social Security numbers. However, these figures come solely from the criminals and have not been independently verified. The announced date for the publication of the data has been postponed to 21 July.
The second incident concerns LabCentral. The ShadowByt3$ group claims that on 4 July it gained access to the portal using compromised customer login credentials and downloaded technical documentation, including manuals, certificates and device specifications.
Abbott, however, disputes the value of this material. The company explains that LabCentral is an externally maintained platform containing publicly available reference documents and does not store confidential information about customers or the company. As of 20 July, neither group had published any data that would corroborate their claims.
The threat to large healthcare organisations lies not only in technical vulnerabilities but also in the hijacking of staff and customer accounts. In the case of health data, however, a definitive assessment of the scale of the incident will only be possible once the investigation has been completed.
