GoFirm
Back to Blog
Case Studies·4 min read

One vishing call opened Abbott Laboratories' Entra login in mid-June. A second gang walked in through the back door days later.

By GoFirm

Abbott Laboratories, the Illinois-based healthcare and diagnostics group that sits at 107th on the Fortune 500 with more than $44.3 billion in annual revenue, confirmed on 16 July 2026 that it was investigating unauthorised access to a limited number of internal systems within its Cancer Diagnostics business. Those systems are legacy infrastructure from Exact Sciences, the diagnostics company Abbott folded into that business unit, and Abbott says they sit apart from its own core network. ShinyHunters added Abbott to its dark web leak site on the same day, threatening to publish the stolen data unless the company negotiated, then pushed its own deadline back to 21 July. According to the group, the vishing call in mid-June was enough to compromise the Entra account and reach every connected application behind it.

The claimed haul is specific and substantial: contracts, internal documents, customer agreements, non-disclosure agreements, more than 20 million medical orders, and over 22 million client notes recording doctor-patient conversations, alongside a dataset of names, email addresses, phone numbers, physical addresses, dates of birth and upwards of a million Social Security numbers. Abbott has not verified those figures and says it does not expect the incident to have a material impact on its business or financial results. Separately, ShadowByt3$ told researchers it gained access to LabCentral, the externally hosted portal Abbott's core laboratory diagnostics business uses for customer documentation, on 4 July, exploiting a weak point in the environment with a set of stolen customer credentials and quietly pulling files out through the portal's API endpoints over the following days. The group claims to have taken manufacturing certificates, operation manuals, calibrator value assignments, assay files and other technical documentation. Abbott disputes the significance of that data, describing LabCentral as a repository of publicly available reference material.

Neither incident happened in isolation. ShinyHunters has spent the past year running the same vishing-to-SSO playbook against medtech and healthcare targets specifically, including Medtronic, OneMedical, AdaptHealth and iRhythm, and it reportedly went after Stryker in the immediate aftermath of a destructive Iranian data-wiping attack on that company. A single technique, repeated against one sector until it stops working, is now hitting a third and fourth medical device and diagnostics giant in the same year.

The defences that failed here were not weak by conventional standards. Abbott activated incident response procedures, engaged outside cybersecurity experts and notified law enforcement as soon as it learned of the Cancer Diagnostics incident. None of that changes what happened at the moment that mattered: a caller convinced one employee that a routine support request was genuine, and the Entra session that followed carried the same authority as if the real employee had approved it herself. On the LabCentral side, a stolen customer password was, on its own, sufficient to start pulling files through an API for days without anyone confirming the person on the other end was who the credential said they were.

Both of those moments are execution events, and both would have hit a different wall under GoFirm. Before a flagged or newly authenticated Entra session can reach connected applications like ServiceNow, SharePoint or Databricks, a confirmation request goes to the named account holder's registered device, requiring biometric confirmation before the session is allowed to proceed. Before a bulk document export executes against a customer portal like LabCentral, the same real-time check applies to the account of record. No confirmation, no execution, regardless of how the credential was obtained or how convincing the caller sounded on the phone.

A vishing call, however convincing, cannot produce that confirmation on the real employee's registered device. Nor can a stolen customer password produce it on the real customer's. The execution boundary holds regardless of how credible the impersonation appears, or how legitimate the credential looks on paper.

GoFirm is The Authority Platform. Stop unauthorised action. Every time.

In association with Osinto.ai, the collective intelligence platform for Security, Resilience & Defence.
Osinto's AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in seconds, not days.

References

1. Abrams, L. 2026. Abbott Laboratories probes two cyber incidents amid extortion claims. BleepingComputer, 17 July 2026.
2. Zhadan, A. 2026. Medical giant Abbott investigates two cyber incidents as ShinyHunters claims breach. Cybernews, 18 July 2026.
3. Abbott Laboratories. 2026. Abbott statement on cyber incident in Cancer Diagnostics business. Abbott Newsroom, 16 July 2026.

Share this article