August 7, 2026: Have I Been Pwned loaded the published Exact Sciences corpus — 10,869,543 unique email addresses for customers, patients and healthcare providers, with names, addresses, phone numbers, dates of birth, genders and personal health data. The dump follows Abbott’s confirmation that attackers got into legacy Exact Sciences systems inside its Cancer Diagnostics business, and an August 5 company update that some of those files contain PHI.
If you ever ordered a Cologuard kit, had an Oncotype test, or work in a clinic that sends specimens to Exact Sciences, this is the breach to treat as real — not a leak-site rumour.
What happened
In mid-July 2026 the ShinyHunters extortion crew listed Abbott-owned Exact Sciences on its pay-or-leak site and claimed a mid-June vishing campaign had opened a path into Microsoft Entra and connected systems. Abbott did not endorse the actor’s volume claims, but it did something more important: it confirmed the intrusion.
On July 16, 2026 Abbott said unauthorized parties had accessed a limited number of internal systems in its Cancer Diagnostics business only — legacy Exact Sciences environments kept separate from the rest of Abbott — with no impact on manufacturing, lab operations, product availability or the ability to serve patients. The company said it had brought in outside forensics and notified law enforcement, and that it did not expect a material financial hit.
ShinyHunters extended its deadline and, according to HIBP’s later load notes, published data from the cancer-diagnostics business. On August 5 Abbott updated the same statement: some of the impacted files contain personal information and/or personal health information, the company was still analysing who is affected, and individual notifications would follow. It also clarified the attack type: vishing, not ransomware encryption. Customers were told they could stay connected to Abbott products.
Two days later, on August 7, Troy Hunt’s Have I Been Pwned service indexed the published set at 10.87 million unique emails and classified the breach as sensitive because of the health data.
Timeline
- Mid-June 2026 (actor claim) — ShinyHunters says employees were voice-phished into handing over access that reached Entra SSO and related apps.
- ~July 15, 2026 — HIBP breach date for the published corpus.
- July 16–17 — Abbott confirms unauthorized access to Cancer Diagnostics / legacy Exact Sciences systems; BleepingComputer covers the ShinyHunters listing.
- August 5 — Abbott confirms some files contain PI/PHI; notifications pending; reiterates vishing, not encrypting malware.
- August 7 — HIBP loads 10,869,543 unique emails with health-related fields.
What was exposed
HIBP’s field list is the cleanest public inventory so far:
- Email addresses (10.87 million unique)
- Names
- Physical addresses
- Phone numbers
- Dates of birth
- Genders
- Personal health data
Abbott’s August 5 wording matches that picture without yet publishing a patient census of its own: some impacted files contain personal information and/or personal health information. The company still has not said how many individuals will receive letters, which patient products are in scope, or whether Social Security numbers appear in any subset. Until those notices land, assume the HIBP field list is the floor, not the ceiling of what a determined attacker can do with the dump.
What was not claimed
Abbott has been consistent on operational impact: Cancer Diagnostics manufacturing and labs kept running, other Abbott businesses were not in the same blast radius, and products were not held hostage by encryption. That distinction matters. This is a data-theft and extortion story, not a hospital ransomware downtime story. It does not mean the privacy harm is small — a 10-million-row health-adjacent dump is the opposite of small — but it does mean the attack path and the remediation look different from a locked-up electronic health record.
Separately, Abbott has treated a ShadowByt3$ claim against a LabCentral portal as a different matter, describing that material as publicly available technical reference documents. Do not conflate the two.
How the attack worked
Abbott’s own update calls it a vishing attack. ShinyHunters’ public narrative (reported by BleepingComputer and not independently confirmed in full by Abbott) is the familiar 2026 playbook: phone calls that impersonate IT or helpdesk, pressure to approve MFA or hand over session access, then movement from identity into collaboration and business apps. The company has not published a technical root-cause advisory with IOCs for the public. What is confirmed is enough for defenders: voice social engineering against employees with privileged or broadly permissioned accounts remains the opening move that turns “limited systems” into millions of rows.
If you run a lab, diagnostics vendor or health-tech SaaS, the practical reading is blunt. MFA prompts over the phone are not a support channel. Helpdesk callbacks must use numbers from a directory you already trust. Session tokens for Entra, ServiceNow, SharePoint and data platforms should be treated as crown jewels, because that is where clinical and customer extracts live.
Who is at risk
Patients and customers whose emails appear in Exact Sciences or Abbott Cancer Diagnostics systems — including people who only ever completed a screening kit or received a results portal login — should assume their contact details and some health-related fields may be in the published set. Check Have I Been Pwned with the email you used for the product.
Healthcare providers and clinic staff are explicitly in HIBP’s description. Referring physicians, nurse navigators and billing contacts often sit in the same CRM and order systems as patients. That makes provider-targeted phishing (“verify this Cologuard order”, “patient results ready”) especially believable.
Household members who share an email or whose address was on a kit shipment can be pulled into scams even if they never took a test.
Anyone who reused passwords between a diagnostics portal and other sites should rotate those credentials from a clean device. HIBP’s published classes do not list passwords, but password reuse is still the cheapest mistake to fix this week.
Why this Exact Sciences data breach matters
Cancer-diagnostics companies sit on a rare combination: identity data good enough for credit and medical fraud, plus clinical context that makes phishing nearly impossible to distinguish from a real lab message. A Cologuard reminder that quotes your real name and mailing address does not need your Social Security number to work.
The scale also matters for secondary crime. Ten million emails with health tags are feedstock for sextortion, fake insurance “appeals”, and long-tail Medicare or private-insurance social engineering. ShinyHunters’ business model is to publish when payment fails; the publication is the product. HIBP loading the set means the dump is now in the circulating corpus that credential-stuffing and phishing crews mine for months.
Abbott’s ownership of Exact Sciences adds a second layer. Attackers did not need to crack every Abbott plant. They needed the legacy island that still held Cancer Diagnostics customer and patient files. “Limited systems” and “10.87 million emails” can both be true when the island is large.
What Abbott and regulators have said
Abbott’s public line, through August 5, is investigation-plus-PHI-acknowledgement without a finished count. That is normal for a complex forensics review and frustrating for patients waiting on letters. US state breach statutes and HIPAA’s breach-notification rule will drive individual notices once Abbott finishes classifying the files. Class-action filings already appeared in July around the ShinyHunters listing; expect those complaints to amend as HIBP’s field list and any state AG letters become exhibits.
There is still no public HHS OCR breach-portal entry with an Exact Sciences headcount at the time of writing. The HIBP load is the best attested scale available today.
What you should do
- Check Have I Been Pwned with every email you used for Exact Sciences, Cologuard, Oncotype or clinic portals tied to those products.
- Watch for medical-identity phishing — messages about “lab results”, “specimen problems”, “insurance denial” or “schedule your follow-up” that ask you to log in or pay a fee. Open the official app or type the URL yourself.
- Treat provider emails as high risk if you work in a clinic that ordered Exact Sciences tests. Verify order changes by phone using a number from your own directory.
- Place a credit freeze at Equifax, Experian and TransUnion if you ever submitted SSN or government ID with Exact Sciences paperwork, or if your state notice later says identifiers were involved. Freezes are free and reversible.
- Read Explanation of Benefits statements for care you did not receive. Medical identity theft often shows up as claims, not as bank withdrawals.
- Rotate reused passwords and turn on phishing-resistant MFA (passkeys or hardware keys) on email and health portals.
- Keep Abbott’s notice and any future letter. Dated vendor communication is what supports disputes with insurers and credit bureaus.
- Employees at diagnostics vendors: run a fresh vishing drill. The confirmed root cause class here is voice social engineering, not a zero-day on a CT scanner.
Industry context
ShinyHunters’ 2025–2026 pattern has been identity-first intrusion into large enterprises, then extortion against the business unit that holds the densest personal data. Exact Sciences sits beside other health and benefits victims in that campaign style — including earlier ShinyHunters-linked loads such as DentaQuest on HIBP — even when the initial access story differs. The common thread is not ransomware encryption; it is publishable rows.
For health-tech M&A, the lesson is ugly and specific. Acquiring a diagnostics brand does not retire its identity perimeter. Legacy SSO trusts, lingering admin accounts and “temporary” data warehouses become the attacker’s preferred beachhead precisely because the parent company’s newer plants look harder.
Cologuard, Oncotype and the clinic mailbox
Exact Sciences is not an obscure lab brand in US primary care. Cologuard made at-home colorectal screening a consumer conversation; Oncotype assays sit inside oncology pathways where results change treatment plans. That product mix means the company’s address books include asymptomatic screening customers, cancer patients, and the clinicians who ordered the tests. A single CRM export can therefore feed three phishing dialects at once: “your kit never arrived,” “your results need a callback,” and “please re-authorize this specimen.”
Clinic inboxes are part of the blast radius. Staff who never took a test still appear as ordering providers, shipping contacts or portal users. Attackers who buy or scrape the published set will not limit themselves to patient Gmail accounts. They will spoof Exact Sciences, Abbott, or a local gastroenterology group and aim at the people who can approve orders or release records.
If you run a practice that ordered Exact Sciences tests in 2024–2026, brief the front desk now. The tell is urgency plus a login link. Real results workflows do not ask patients or staff to “verify identity” through a fresh domain registered last week.
What “personal health data” can mean in practice
HIBP’s category is deliberately broad. It can cover test order metadata, product enrolment flags, clinical notes excerpts, insurance-related fields or other health-adjacent attributes that rode along in the same files Abbott is still classifying. Abbott has not published a data dictionary for the public. Patients should not invent a diagnosis list from the HIBP label — and should also not assume the dump is “emails only.” The company’s own August 5 sentence put personal health information in scope.
That ambiguity is temporary. State notification letters, if and when they arrive, usually list the data elements more precisely than a first corporate blog post. Until then, defensive behaviour should assume contact details plus health context are enough to craft a convincing medical scam.
Comparing this to other 2026 health breaches
Not every healthcare incident this year looks like Exact Sciences. Some are ransomware that takes hospitals offline. Some are clearinghouse or billing vendors with multi-million Social Security number counts. Exact Sciences is closer to the Salesforce/extortion and cloud-identity pattern: steal the rows, threaten publication, then publish. The operational impact Abbott denies is real in the sense that labs kept running; the privacy impact HIBP just quantified is also real. Holding both ideas at once is how you brief a board without lying to patients.
It is also why checking Have I Been Pwned is useful here in a way it is not for every hospital ransomware event. When a crew publishes, HIBP can often say whether your email is in the set. When a hospital encrypts and quietly pays, you may wait months for a letter and never get a free lookup.
For security teams reading this as a post-mortem prompt
Three controls would have changed the odds of this becoming a 10-million-row publication even if vishing still succeeded against one employee. First, stricter step-up authentication for exporting customer or patient lists — not just for logging into email. Second, egress detection on bulk downloads from the legacy Exact Sciences data stores Abbott has now spent weeks reviewing. Third, a hard separation between “can open a ticket” and “can pull health-adjacent tables,” so a compromised helpdesk-adjacent session does not equal a warehouse dump.
None of those controls are exotic. They are the boring ones that fail open when a newly acquired brand is left on its old identity stack because migration is expensive. Exact Sciences is the case study for why that debt comes due in public.
Patients cannot deploy those controls. They can only check HIBP, freeze credit when identifiers are implicated, and refuse medical phishing. The rest is on Abbott’s remediation programme and on every other diagnostics firm watching this week’s headlines.
Canonical record
Exact Sciences / Abbott Cancer Diagnostics 2026 on BreachHistory — company-confirmed intrusion; HIBP 10,869,543 unique emails with personal health data; Abbott Aug 5 PHI update.
Sources: Abbott statement (updated Aug 5, 2026), Have I Been Pwned, BleepingComputer.
Published 2026-08-07. Will update when Abbott publishes an individual-notification count or HHS OCR posts an attested figure.