Aug 7, 2026
Policy

Abbott Exact Sciences data breach reportedly exposes 10.9 million email addresses

A reported ShinyHunters leak includes 10.9 million email addresses, while Abbott says its review of the vishing incident continues.

Dominic Okoye

By Dominic Okoye · Staff Writer

· 3 min read

Abbott Exact Sciences data breach reportedly exposes 10.9 million email addresses
Photo: The Register

The Abbott Exact Sciences data breach has reportedly resulted in a public dataset containing 10.9 million unique email addresses, according to The Register, which said the material was published by the extortion group ShinyHunters and added to Have I Been Pwned’s breach database. Abbott has confirmed unauthorized access to a limited number of internal systems in its Cancer Diagnostics business, but it has not confirmed the reported dataset’s size, contents, publication, or an extortion demand.

In its most recent public update, dated Aug. 5, Abbott said some files affected in the incident contained personal information and/or personal health information. The company said it was still reviewing the material and would provide further information, including notifications to affected people where required. It has not disclosed a nationwide number of people affected.

What has Abbott confirmed about the Exact Sciences data breach?

Abbott first disclosed the incident on July 16, saying an unauthorized party had accessed a limited number of internal systems within its Cancer Diagnostics business. On Aug. 5, it said the intrusion was a vishing attack and not an encryption-malware event. Abbott did not describe how the attack led to access, how long the intruders were in its systems, or which information was taken.

The company said the event did not disrupt business operations, product availability, manufacturing, laboratory operations, or patient services. It also said no other Abbott businesses, sites, or systems were affected. Abbott has engaged third-party cybersecurity specialists and law enforcement, according to its statement.

What is reported about the published data?

The Register reported that the published material included names, email and physical addresses, phone numbers, dates of birth, gender, and personal health information associated with customers, patients, and healthcare providers. That report, rather than Abbott’s disclosure, is the basis for the 10.9 million-email figure and the itemized description of the records.

An email-address total should not be read as Abbott’s count of affected individuals. A person may have more than one address in a dataset, and Abbott has not yet established publicly which records require notification.

ShinyHunters has separately claimed it took more than 30 million customer-information rows, including more than one million Social Security numbers and 7.5 million dates of birth. The group also alleged that it obtained patient notes, medical-order records, Databricks data, SharePoint files, and Coupa contracts. Those assertions are claims by the criminal group and have not been independently verified.

What happens next?

Abbott’s review remains the main unresolved part of the incident. The company has not said whether it received or rejected a ransom demand, and it has not released a field-by-field accounting of the information accessed. Its required notifications, if any, will determine the confirmed scope for people whose personal information or personal health information was involved.

This story draws on original reporting from The Register.

More from Policy

All Policy →