{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-abbott-investigates-shinyhunters-claim-after-mid-june-vishing-on-employe"},"incident":{"slug":"2026-abbott-investigates-shinyhunters-claim-after-mid-june-vishing-on-employe","title":"Abbott investigates ShinyHunters claim after mid-June vishing on employees","date":"2026-06","date_precision":"month","year":2026,"victim_org":"Abbott Laboratories (legacy Exact Sciences systems)","sector":"Healthcare","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters","summary":"ShinyHunters conducted vishing attacks against Abbott Laboratories employees in mid-June 2026 and compromised a Microsoft Entra single sign-on account that opened certain internal systems, according to reporting on the company's investigation. The group claimed 30 million rows of customer data including names, contact details, dates of birth and one million Social Security numbers, with a publication deadline of 21 July 2026. The affected systems were legacy Exact Sciences infrastructure acquired by Abbott in late 2025.","how_it_worked":"Callers impersonating internal IT reached Abbott staff and steered them into an Entra sign-in they did not control, capturing the credential and the multi-factor response in the same call. The single compromised SSO identity federated into internal systems inherited from the Exact Sciences acquisition, an environment less likely to have been fully folded into Abbott's identity and monitoring controls. A separate actor using the handle ShadowByt3$ claimed access to Abbott's LabCentral portal on 4 July using compromised customer credentials; Abbott said that portal holds only non-sensitive technical documents.","lessons":"Acquired estates need identity consolidation onto phishing-resistant MFA before the integration backlog is worked through, since attackers target exactly the tenant that has not been migrated yet.","confidence":"Reported","sources":[{"title":"Abbott Investigating Cyberattack Claims From Two Threat Actors","url":"https://www.hipaajournal.com/abbott-investigating-cyberattack-claims/","publisher":"HIPAA Journal"},{"title":"Abbott investigates after ShinyHunters claims massive data theft","url":"https://www.paubox.com/blog/abbott-investigates-after-shinyhunters-claims-massive-data-theft","publisher":"Paubox"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-abbott-investigates-shinyhunters-claim-after-mid-june-vishing-on-employe"}}