Exact Sciences (Abbott) Breach Exposes 10.9 M Patient & Provider Records
What Happened — In July 2026, the ShinyHunters extortion group claimed to have stolen data from Exact Sciences’ cancer‑diagnostics business and published it. The leak contains 10,869,543 unique email addresses plus names, addresses, phone numbers, dates of birth, genders and personal health information. Abbott Laboratories, the current owner, issued a public notice confirming the exposure and promised further details after its investigation.
Why It Matters for Compliance & Audit Readiness
- The incident is a textbook example of a PHI breach that SOC 2 CC6.1 (Privacy) and HIPAA‑aligned controls are designed to prevent, detect, and document.
- Continuous evidence of data‑classification, access‑control, and breach‑response processes is essential to demonstrate a defensible audit trail.
- Verisq’s CookiePLUS capability can automate consent management, DSAR handling, and privacy‑impact reporting, turning a reactive breach response into proactive compliance evidence.
Who Is Affected – Healthcare providers, diagnostic labs, and patients who used Exact Sciences’ Cologuard screening service.
Recommended Actions
- Immediately map the exposed data elements to your SOC 2 privacy controls (CC6.1) and verify that classification, retention, and encryption policies are enforced.
- Activate your breach‑response playbook, capture all notification evidence, and log remediation steps in a tamper‑evident audit repository.
- Review consent and DSAR processes; consider a privacy‑automation platform to streamline future requests.
Source: Have I Been Pwned – Exact Sciences breach
Technical Notes
- Attack vector: “pay‑or‑leak” extortion after unknown initial compromise (likely credential theft or insider access).
- Data types: email, name, address, phone, DOB, gender, and personal health records.
- No CVE; the breach is a data‑exfiltration incident rather than a software flaw.