HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

Exact Sciences (Abbott) Breach Exposes 10.9 M Patient & Provider Records

In July 2026, ShinyHunters published data stolen from Exact Sciences, affecting over 10 million email addresses and personal health records. The breach highlights the need for robust privacy controls and audit‑ready evidence under SOC 2.

LiveThreat™ Intelligence · 📅 August 07, 2026· 📰 haveibeenpwned.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
3 recommended
📰
Source
haveibeenpwned.com

Exact Sciences (Abbott) Breach Exposes 10.9 M Patient & Provider Records

What Happened — In July 2026, the ShinyHunters extortion group claimed to have stolen data from Exact Sciences’ cancer‑diagnostics business and published it. The leak contains 10,869,543 unique email addresses plus names, addresses, phone numbers, dates of birth, genders and personal health information. Abbott Laboratories, the current owner, issued a public notice confirming the exposure and promised further details after its investigation.

Why It Matters for Compliance & Audit Readiness

  • The incident is a textbook example of a PHI breach that SOC 2 CC6.1 (Privacy) and HIPAA‑aligned controls are designed to prevent, detect, and document.
  • Continuous evidence of data‑classification, access‑control, and breach‑response processes is essential to demonstrate a defensible audit trail.
  • Verisq’s CookiePLUS capability can automate consent management, DSAR handling, and privacy‑impact reporting, turning a reactive breach response into proactive compliance evidence.

Who Is Affected – Healthcare providers, diagnostic labs, and patients who used Exact Sciences’ Cologuard screening service.

Recommended Actions

  • Immediately map the exposed data elements to your SOC 2 privacy controls (CC6.1) and verify that classification, retention, and encryption policies are enforced.
  • Activate your breach‑response playbook, capture all notification evidence, and log remediation steps in a tamper‑evident audit repository.
  • Review consent and DSAR processes; consider a privacy‑automation platform to streamline future requests.

Source: Have I Been Pwned – Exact Sciences breach

Technical Notes

  • Attack vector: “pay‑or‑leak” extortion after unknown initial compromise (likely credential theft or insider access).
  • Data types: email, name, address, phone, DOB, gender, and personal health records.
  • No CVE; the breach is a data‑exfiltration incident rather than a software flaw.
📰 Original Source
https://haveibeenpwned.com/Breach/ExactSciences

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · PrivacyOps · CookiePLUS

A privacy incident is a question about your consent record.

CookiePLUS and Verisq AI Trust Operations keep consent, DSAR, and data-handling evidence continuously ready — so a data-exposure event finds you prepared, not scrambling.

See how Verisq AI Trust Operations handles privacy →