Summary
- Environment: Not publicly identified
- Operational impact: No outage or recovery duration quantified
- Financial impact: No public cost estimate
- Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.
What happened
A vishing attack caused unauthorized access to a limited number of legacy Exact Sciences systems in Abbott’s Cancer Diagnostics business. [2]
Impact
Impacted files contained personal or personal health information and a separately quantified corpus in the Have I Been Pwned breach record. [1][2]
Documented data types include:
- Names [1][2]
- Clinical information — Abbott confirmed personal health information in some impacted files; HIBP lists personal health data. [1][2]
- Contact information — Email, phone, and physical-address fields listed by HIBP. [1][2]
- Dates of birth — HIBP DataClass for the verified corpus. [1][2]
- Gender information [1][2]
A cited record reports 10,869,543 records (Unique email addresses in the verified HIBP corpus; not an Abbott-confirmed number of patients, customers, providers, files, or affected individuals; as of 2026-08-07). [1][2]
Timeline
Documented event
The Have I Been Pwned breach record lists this BreachDate; Abbott did not establish it as the exact initial-access or detection date.
[1]Public disclosure
Date of Abbott’s initial statement; the reviewed page was updated August 5.
[2]Briefing updated
This briefing was last reviewed and updated on August 9, 2026.
Threat Group & Attack Vector
Abbott identified the incident as a vishing attack and explicitly said it was not an encryption-malware event. [2]
Unauthorized access affected a limited number of legacy Exact Sciences internal systems; Abbott said those systems were separate and no other Abbott business, site, or system was affected. [2]
Actors
- No threat actor group has been identified in the reviewed public evidence.
TTPs
Response
Abbott said it would provide more information after review and make any required notifications to affected individuals. Abbott said the incident did not affect operations, products or availability, manufacturing, lab operations, or patient service. Abbott took immediate response steps and engaged third-party cybersecurity experts and law enforcement. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [2]
