Start with Identity
← Blog
News

Abbott investigates two incidents, one starting with a vished Entra account

Abbott confirmed unauthorized access to legacy Exact Sciences systems after a mid-June vishing attack compromised a Microsoft Entra single sign-on account. ShinyHunters claims a large data theft, unverified. A second, smaller incident used stolen customer credentials on a portal.

By SWI Community TeamJul 18, 2026Updated Jul 27, 2026

Abbott Laboratories confirmed unauthorized access to internal legacy Exact Sciences systems in its Cancer Diagnostics business. The reported entry point is the part worth noting: a mid-June vishing attack against Abbott employees that compromised a Microsoft Entra single sign-on account.

ShinyHunters claims to have taken customer personal data running to tens of millions of rows, client notes covering doctor-patient conversations, medical orders, and data pulled from Entra, ServiceNow, SharePoint, Databricks, and Coupa. Abbott has confirmed the unauthorized access; the volume and content claims are the attacker's and remain unverified. Treat the numbers as an extortion posture until someone independent confirms them.

A second, separate incident involved the LabCentral customer portal, entered with compromised customer credentials by an actor calling itself ShadowByt3$. Abbott disputes its significance, saying the portal holds only publicly available technical reference documents.

Why it matters

One phone call to one employee, one SSO account, and the reach extends across five SaaS platforms. That is single sign-on working exactly as designed, in the wrong hands: the same property that makes it worth deploying makes one compromised identity a cross-platform incident.

ShinyHunters sits in The Com, the same loose collective behind the Entra passkey-enrollment vishing campaign, and this is now their signature: skip the malware, call the helpdesk or the user. Our Scattered Spider teardown covers the pattern in detail. The uncomfortable question it poses is not whether your MFA is strong, but what your helpdesk does when someone calls sounding stressed and senior. Note also that the compromised systems were legacy and acquired, which is where identity governance usually thins out.

Source: BleepingComputer

Last reviewed By SWI Community TeamSuggest a correctionHow we research
Independent analysis. No vendor sponsorship.