HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

Abbott Laboratories Faces Unauthorized SSO Access and Extortion Threat After Vishing Attack on Cancer Diagnostics Systems

Abbott Laboratories confirmed that a vishing attack compromised a Microsoft Entra SSO account, giving attackers unauthorized access to legacy Exact Sciences systems in its Cancer Diagnostics division and a claim of breach of the LabCentral portal. The incident highlights the need for robust SOC 2 access‑control practices and continuous audit evidence.

LiveThreat™ Intelligence · 📅 July 18, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
4 recommended
📰
Source
bleepingcomputer.com

Abbott Laboratories Investigates Unauthorized Access to Cancer‑Diagnostics Legacy Systems and LabCentral Portal Amid ShinyHunters Extortion Threat

What Happened — Abbott confirmed that a vishing (voice‑phishing) attack in mid‑June compromised a Microsoft Entra single‑sign‑on (SSO) account. The attackers used the stolen credentials to gain unauthorized access to a limited set of internal legacy Exact Sciences systems in the Cancer Diagnostics business and allegedly to the LabCentral portal. The ShinyHunters extortion gang posted a threat to publish the data unless a ransom was paid.

Why It Matters for Compliance & Audit Readiness

  • The incident is a textbook example of a SOC 2 Access Controls failure: compromised identity credentials allowed lateral movement into SaaS environments.
  • Continuous monitoring of privileged‑access logs and evidence of MFA enforcement are core audit artifacts that can demonstrate due diligence.
  • Mapping the breach to SOC 2 CC6.1 (Logical Access) and CC6.2 (User Management) helps turn the incident into actionable evidence for a readiness review.

Who Is Affected – Health‑life sector (medical‑device and diagnostics manufacturers), specifically Abbott’s Cancer Diagnostics division and any third‑party SaaS providers linked to the compromised accounts (Salesforce, Microsoft 365, Google Workspace, SAP, etc.).

Recommended Actions

  • Immediately enforce MFA on all SSO accounts and review conditional‑access policies.
  • Conduct a forensic review of access logs for the compromised accounts and document findings as audit evidence.
  • Update security‑awareness training to include vishing detection and SSO hygiene.
  • Map the incident to SOC 2 access‑control criteria and capture remediation steps in your continuous‑compliance platform.

Source: BleepingComputer

Technical Notes – Attack vector: vishing → compromised Microsoft Entra SSO account. Data reportedly accessed/exfiltrated includes internal documents, contracts, and customer information from Microsoft Entra, ServiceNow, SharePoint, Databricks, and Coupa. No confirmed impact on manufacturing or patient care. Source: same article

📰 Original Source
https://www.bleepingcomputer.com/news/security/abbott-laboratories-probes-two-cyber-incidents-amid-extortion-claims/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your SOC 2 posture defensible.

See where you'd stand with Verisq AI Trust Operations →