---
title: "Exact Sciences legacy-systems vishing data incident"
description: "Evidence-backed account of Exact Sciences legacy-systems vishing data incident, covering what happened, impact, timeline, attack vector, technical details, and primary sources."
incident_type: "Data incident"
status: "active"
last_modified: "2026-08-09"
canonical_url: "https://www.ally.security/incidents/exact-sciences-legacy-systems-vishing-data-incident-2026"
markdown_url: "https://www.ally.security/incidents/exact-sciences-legacy-systems-vishing-data-incident-2026.md"
stix_url: "https://www.ally.security/incidents/exact-sciences-legacy-systems-vishing-data-incident-2026/stix.json"
---

# Exact Sciences legacy-systems vishing data incident

A vishing attack caused unauthorized access to a limited number of legacy Exact Sciences systems in Abbott's Cancer Diagnostics business. Impacted files containing personal or personal health information and a separately quantified verified HIBP corpus.

Last modified Aug 9, 2026 · 2 sources

## Summary

- **Environment:** Not publicly identified
- **Operational impact:** No outage or recovery duration quantified
- **Financial impact:** No public cost estimate

## What happened

A vishing attack caused unauthorized access to a limited number of legacy [Exact Sciences](https://www.exactsciences.com/) systems in [Abbott](https://www.abbott.com/)'s Cancer Diagnostics business. [2](#source-2)

## Impact

Impacted files contained personal or personal health information and a separately quantified corpus in the [Have I Been Pwned breach record](https://haveibeenpwned.com/api/v3/breach/ExactSciences). [1](#source-1) [2](#source-2)

Documented data types include:

- Names [1](#source-1) [2](#source-2)
- Clinical information — Abbott confirmed personal health information in some impacted files; HIBP lists personal health data. [1](#source-1) [2](#source-2)
- Contact information — Email, phone, and physical-address fields listed by HIBP. [1](#source-1) [2](#source-2)
- Dates of birth — HIBP DataClass for the verified corpus. [1](#source-1) [2](#source-2)
- Gender information [1](#source-1) [2](#source-2)

A cited record reports 10,869,543 records (Unique email addresses in the verified HIBP corpus; not an Abbott-confirmed number of patients, customers, providers, files, or affected individuals; as of 2026-08-07). [1](#source-1) [2](#source-2)

## Timeline

### July 15, 2026 — Documented event

The [Have I Been Pwned breach record](https://haveibeenpwned.com/api/v3/breach/ExactSciences) lists this BreachDate; Abbott did not establish it as the exact initial-access or detection date. [1](#source-1)

### July 16, 2026 — Public disclosure

Date of [Abbott's initial statement](https://www.abbott.com/en-us/corpnewsroom/diagnostics-testing/abbott-statement-on-cyber-incident-in-cancer-diagnostics-business); the reviewed page was updated August 5. [2](#source-2)

### August 9, 2026 — Briefing updated

This briefing was last reviewed and updated on August 9, 2026.

## Threat Group & Attack Vector

Abbott identified the incident as a vishing attack and explicitly said it was not an encryption-malware event. [2](#source-2)

Unauthorized access affected a limited number of legacy Exact Sciences internal systems; Abbott said those systems were separate and no other Abbott business, site, or system was affected. [2](#source-2)

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- [T1566.004 — Phishing: Spearphishing Voice](https://attack.mitre.org/techniques/T1566/004/) [2](#source-2)

## Response

Abbott said it would provide more information after review and make any required notifications to affected individuals. Abbott said the incident did not affect operations, products or availability, manufacturing, lab operations, or patient service. Abbott took immediate response steps and engaged third-party cybersecurity experts and law enforcement. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [2](#source-2)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/exact-sciences-legacy-systems-vishing-data-incident-2026/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### Exact Sciences breach record

advisory · Have I Been Pwned · Aug 7, 2026

<https://haveibeenpwned.com/api/v3/breach/ExactSciences>

<a id="source-2"></a>

### Abbott statement on cyber incident in Cancer Diagnostics business

advisory · Abbott Laboratories · Jul 16, 2026

<https://www.abbott.com/en-us/corpnewsroom/diagnostics-testing/abbott-statement-on-cyber-incident-in-cancer-diagnostics-business>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Resulted In · 100% confidence · current**  
   July 2026 Exact Sciences legacy-systems incident: Abbott said it would provide more information after review and make any required notifications to affected individuals.
2. **Resulted In · 100% confidence · current**  
   July 2026 Exact Sciences legacy-systems incident: Abbott said the incident did not affect operations, products or availability, manufacturing, lab operations, or patient service.
3. **Resulted In · 100% confidence · current**  
   July 2026 Exact Sciences legacy-systems incident: Abbott took immediate response steps and engaged third-party cybersecurity experts and law enforcement.
4. **Exposed Data Category · 100% confidence · current**  
   Exact Sciences personal and health-information corpus: Names
5. **Exposed Record Count · 100% confidence · current**  
   Exact Sciences personal and health-information corpus: 10,869,543 record
6. **Resulted In · 100% confidence · current**  
   July 2026 Exact Sciences legacy-systems incident: Abbott identified the incident as a vishing attack and explicitly said it was not an encryption-malware event.
7. **Affected Organization · 100% confidence · current**  
   July 2026 Exact Sciences legacy-systems incident: Exact Sciences Corporation
8. **Exposed Data Category · 100% confidence · current**  
   Exact Sciences personal and health-information corpus: Clinical information
9. **Exposed Data Category · 100% confidence · current**  
   Exact Sciences personal and health-information corpus: Contact information
10. **Disclosed At · 100% confidence · current**  
   July 2026 Exact Sciences legacy-systems incident: 2026-07-16
11. **Resulted In · 100% confidence · current**  
   July 2026 Exact Sciences legacy-systems incident: Exact Sciences personal and health-information corpus
12. **Used Attack Technique · 95% confidence · current**  
   July 2026 Exact Sciences legacy-systems incident: https://attack.mitre.org/techniques/T1566/004/
13. **Exposed Data Category · 100% confidence · current**  
   Exact Sciences personal and health-information corpus: Dates of birth
14. **Affected Organization · 100% confidence · current**  
   July 2026 Exact Sciences legacy-systems incident: Abbott Laboratories
15. **Occurred At · 80% confidence · current**  
   July 2026 Exact Sciences legacy-systems incident: 2026-07-15
16. **Resulted In · 100% confidence · current**  
   July 2026 Exact Sciences legacy-systems incident: Unauthorized access affected a limited number of legacy Exact Sciences internal systems; Abbott said those systems were separate and no other Abbott business, site, or system was affected.
17. **Exposed Data Category · 100% confidence · current**  
   Exact Sciences personal and health-information corpus: Gender information

</details>
