Abbott Laboratories is the latest household-name healthcare company to learn that a single phone call can undo years of security investment. On August 7, 2026, The Register reported that the extortion group ShinyHunters had dumped data stolen from Abbott’s Cancer Diagnostics business, after the company apparently declined to pay a ransom. The leak, according to the outlet, contains 10.9 million unique email addresses along with personal and health information tied to Abbott’s cancer diagnostics operations, which include the Exact Sciences business Abbott acquired earlier in 2026.
The intrusion did not start with malware, a zero-day, or a phishing email. Abbott’s own statement on the incident, published July 16, 2026, says the breach traces back to a vishing attack, plain voice phishing, and explicitly notes “this was a vishing attack; not an encryption malware event.” That single sentence captures where enterprise security has drifted in 2026: attackers increasingly skip the network perimeter altogether and go straight for the person answering the phone at the help desk...
