Home › Intelligence › Brief
BREACH BRIEF🟠 High Breach

Abbott Laboratories Faces Unauthorized SSO Access and Extortion Threat After Vishing Attack on Cancer Diagnostics Systems

Abbott Laboratories confirmed that a vishing attack compromised a Microsoft Entra SSO account, giving attackers unauthorized access to legacy Exact Sciences systems in its Cancer Diagnostics division and a claim of breach of the LabCentral portal. The incident highlights the need for robust SOC 2 access‑control practices and continuous audit evidence.

LiveThreat™ Intelligence · 📅 July 18, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
4 recommended
📰
Source
bleepingcomputer.com

Abbott Laboratories Investigates Unauthorized Access to Cancer‑Diagnostics Legacy Systems and LabCentral Portal Amid ShinyHunters Extortion Threat

What Happened — Abbott confirmed that a vishing (voice‑phishing) attack in mid‑June compromised a Microsoft Entra single‑sign‑on (SSO) account. The attackers used the stolen credentials to gain unauthorized access to a limited set of internal legacy Exact Sciences systems in the Cancer Diagnostics business and allegedly to the LabCentral portal. The ShinyHunters extortion gang posted a threat to publish the data unless a ransom was paid.

Why It Matters for Compliance & Audit Readiness

  • The incident is a textbook example of a SOC 2 Access Controls failure: compromised identity credentials allowed lateral movement into SaaS environments.
  • Continuous monitoring of privileged‑access logs and evidence of MFA enforcement are core audit artifacts that can demonstrate due diligence.
  • Mapping the breach to SOC 2 CC6.1 (Logical Access) and CC6.2 (User Management) helps turn the incident into actionable evidence for a readiness review.

Who Is Affected – Health‑life sector (medical‑device and diagnostics manufacturers), specifically Abbott’s Cancer Diagnostics division and any third‑party SaaS providers linked to the compromised accounts (Salesforce, Microsoft 365, Google Workspace, SAP, etc.).

Recommended Actions

  • Immediately enforce MFA on all SSO accounts and review conditional‑access policies.
  • Conduct a forensic review of access logs for the compromised accounts and document findings as audit evidence.
  • Update security‑awareness training to include vishing detection and SSO hygiene.
  • Map the incident to SOC 2 access‑control criteria and capture remediation steps in your continuous‑compliance platform.

Source: BleepingComputer

Technical Notes – Attack vector: vishing → compromised Microsoft Entra SSO account. Data reportedly accessed/exfiltrated includes internal documents, contracts, and customer information from Microsoft Entra, ServiceNow, SharePoint, Databricks, and Coupa. No confirmed impact on manufacturing or patient care. Source: same article

📰 Original Source
https://www.bleepingcomputer.com/news/security/abbott-laboratories-probes-two-cyber-incidents-amid-extortion-claims/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your trust posture defensible.

See where you'd stand with Verisq AI Trust Operations →