ShinyHunters called cancer diagnostics biz and tricked staffers into giving them access. Now they've dumped 10.9M email addresses
Cancer diagnostics breach spills personal and health info as extortion crew says healthcare giant ‘should’ve paid the ransom’
Hackers, identified as ShinyHunters, infiltrated Abbott's cancer diagnostics business and subsequently released sensitive data. The theft encompassed 10.9 million unique email addresses, along with personal and health details of customers, patients, and healthcare professionals. Abbott first notified the public on July 16, and Aug.
5 disclosed that some accessed files contained personal or health information. The intrusion began with a vishing tactic, and the company emphasized that no disruption to products, manufacturing, lab operations, or patient services occurred.
ShinyHunters presented a contrasting perspective, stating on their dark web leak site that the company should have paid the ransom and claimed to have obtained over 30 million records, including more than 1 million Social Security numbers and 7.5 million dates of birth. They also allege the theft of 22 million client notes containing confidential doctor-patient communications and health information, as well as over 20 million medical-order records.
These details, including patient IDs, prescription types, order dates, and refill information, were also claimed to have been obtained.
While Abbott has not disclosed the specifics of the vishing attack, the duration of the intruders' access to their systems, or whether they received an extortion demand, the company has stated that the investigation is ongoing. Affected individuals will be notified as required. However, the significant portion of stolen data is already circulating online, raising concerns about potential misuse.
Written by urgent.news from The Register's reporting — not their text. Machine-written; read the original for the full account.


