Abbott Laboratories Data Breach Investigation
Chimicles Schwartz Kriner & Donaldson-Smith is investigating potential class action claims against Abbott Laboratories and its subsidiary Exact Sciences Corporation on behalf of patients, customers, employees, and other individuals whose personal information may have been compromised in a recently disclosed data security incident affecting Abbott’s Cancer Diagnostics business.
What Happened?
On July 17, 2026, Abbott publicly confirmed that it is investigating a cyber incident involving unauthorized access to a limited number of internal systems within its Cancer Diagnostics business, which operates on legacy Exact Sciences infrastructure that remains separate from Abbott’s broader enterprise systems. Abbott stated that it activated its incident response procedures, engaged outside cybersecurity experts, and notified law enforcement.
Abbott’s disclosure followed the appearance of Exact Sciences on the data leak site of the ShinyHunters extortion group, which threatened to publish allegedly stolen data absent negotiation. ShinyHunters has claimed that it gained access through a voice phishing (vishing) campaign in mid-June 2026 that compromised a Microsoft Entra single sign-on account, allowing the group to reach connected enterprise applications including ServiceNow, SharePoint, Databricks, and Coupa.
Separately, a threat actor identifying itself as ShadowByt3$ has claimed to have accessed Abbott’s LabCentral customer portal on or around July 4, 2026, using compromised customer credentials. Abbott has represented that LabCentral houses publicly available technical product reference materials and does not contain proprietary or sensitive customer or business information.
What Information May Have Been Compromised?
Based on public reporting and threat actor disclosures concerning the Cancer Diagnostics/legacy Exact Sciences incident, the exposed data may include:
- Names
- Email addresses
- Telephone numbers
- Physical addresses
- Dates of birth
- Social Security numbers
- Doctor-patient communications and clinical notes
- Medical order information
- Customer agreements and other internal business documents
Abbott’s investigation into what information was actually accessed remains ongoing, and the full scope and identity of affected individuals has not yet been publicly confirmed.
Why Is This Important?
The combination of Social Security numbers, dates of birth, contact information, and sensitive health-related data such as doctor-patient notes and medical orders is precisely the bundle of identifiers most commonly exploited for identity theft, synthetic identity fraud, tax-refund fraud, medical identity theft, insurance fraud, and targeted phishing schemes. Exposure of clinical communications and medical order data also raises heightened privacy concerns under state and federal medical privacy laws.
What Should You Do?
If you have received a data breach notification from Abbott or Exact Sciences, or if you have used Exact Sciences products or services (including Cologuard, Oncotype DX, or related oncology diagnostics), you may have been affected by this incident. Please contact our data breach attorneys by completing the form below to learn more about your potential legal rights and our ongoing investigation.
(*) Indicates required field: When communicating with us through this site or otherwise in connection with a matter for which we do not already represent you, your communication may not be treated as privileged or confidential, and does not create an attorney-client relationship between you and our Firm.



