ShinyHunters hit medial giant Abbott, disrupting cancer drug research and more
US healthcare and medical technology giant Abbott Laboratories has been struck by what appears to be two separate cyberattacks, just days apart - one by the infamous ShinyHunters threat actors, and another by The ShadowByt3$, with at least one of the groups currently negotiating a ransom payment.
Abbott, which is one of the largest healthcare companies globally with more than 100,000 employees, said it was investigating an incident in which someone accessed IT systems in its Cancer Di
A day later, ShinyHunters added Abbott to its list of victims, saying it would release the stolen files on July 18 2026 unless the company pays the ransom. This date was later moved to July 21, suggesting that Abbott indeed kicked off the negotiations.
Speaking to BleepingComputer, ShinyHunters operatives said they gained access to a corporate Microsoft Entra SSO account after a successful vishing attack on one of the employees.
The attackers said they stole internal documents, contracts, customer information, more than 22 million doctor-patient notes containing conversations, over 20 million medical orders, customer agreements, and NDAs.
Among the files are customer names, emails, phone numbers, postal addresses, and more than a million Social Security numbers.
In the meantime, The ShadowByt3$ hacking collective also reached out to the publication to say they accessed Abbott’s LabCentral portal, a customer portal for core laboratory diagnostics.
While in this attack no customer data was stolen, the group said they pulled “sensitive technical documentation related to Abbott's laboratory diagnostic systems, including manufacturing certificates, operation manuals, technical specifications, and regulatory documents”.
ShinyHunters is one of the most active threat actors these days, known for running ransomware attacks without deploying encryptors. By focusing solely on data exfiltration, the group achieved the same results, while cutting down on costs for developing and maintaining an encryptor.
It is also known for targeting healthcare organizations - in late April this year, one of the biggest medical device manufacturers in the world - Medtronic - confirmed suffering a cyberattack at the hands of ShinyHunters.
➡️ Read our full guide to the best antivirus
1. Best overall:
Bitdefender Total Security
2. Best for families:
Norton 360 with LifeLock
3. Best for mobile:
McAfee Mobile Security
Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.
Please logout and then login again, you will then be prompted to enter your display name.
