An Exact Sciences data leak indexed by leaksear.ch contains 1,458,549 records from legacy cancer diagnostics systems, including patient registry clinical fields and employee account data, with a listed breach date of July 15, 2026 (leaksear.ch metadata). Abbott, which completed its acquisition of Exact Sciences on March 23, 2026, has confirmed unauthorized access to a limited number of internal systems in its Cancer Diagnostics business, while public reporting tied the extortion claim to ShinyHunters (abbott.mediaroom.com, www.abbott.com, www.bleepingcomputer.com).
What happened
Abbott's public statement says the cyber incident involved unauthorized access to a limited number of internal systems in the Cancer Diagnostics business only. The company said the incident did not affect business operations, product availability, manufacturing or lab operations, patient service, or other Abbott businesses, sites, or systems, and that the legacy Exact Sciences systems are separate from Abbott's (www.abbott.com).
BleepingComputer reported on July 17, 2026 that ShinyHunters had added Abbott to its data leak site and threatened publication after July 18 unless the company negotiated, with the deadline later extended to July 21. The outlet also reported ShinyHunters claims of a mid-June vishing attack against Abbott employees, compromise of a Microsoft Entra SSO account, and exfiltration from several internal services, but stated it had not independently verified the data theft claims (www.bleepingcomputer.com).
HIPAA Journal wrote that Abbott had confirmed unauthorized access to certain legacy cancer diagnostics systems but had not confirmed the extent to which patient data was compromised. A separate LabCentral portal claim described in the same public reporting is not the dataset covered here; this article concerns the legacy Exact Sciences cancer diagnostics records identified in the leaksear.ch metadata (www.hipaajournal.com, www.bleepingcomputer.com) (leaksear.ch metadata).
What data was exposed
The leaksear.ch indexing metadata lists searchable fields for name, email address, phone number, username, date of birth, physical address, and country (leaksear.ch metadata).
Additional stored fields, which are not listed as direct search pivots, include employee and account context such as account status, alternate email, Entra ID, ServiceNow username, employee number, department, title, manager, office location, last login, password-last-set and password-expiration timing fields, user type, and worker type (leaksear.ch metadata).
The metadata also lists patient registry and clinical fields, including gender, race, Hispanic ethnicity flag, marital status, living or deceased status, patient age fields, patient identifiers, hashed patient MRN values, product and specimen information, procedure codes and descriptions, surgery dates and sites, tumor types, nodal statuses, recurrence scores, DCIS scores, smoking status, and death or deceased date fields. Raw passwords and payment card fields are not included in the supplied field inventory (leaksear.ch metadata).
Why this matters
The exposed field mix combines contact details, dates of birth, and cancer-care context, which can give attackers credible material for phishing, medical identity theft, insurance fraud, and fake breach or legal-notice lures (leaksear.ch metadata). Employee directory and account attributes may also support help-desk impersonation or credential-reset social engineering, a relevant risk because ShinyHunters claimed in public reporting that vishing and SSO compromise were involved, though BleepingComputer said those data-theft claims were not independently verified (www.bleepingcomputer.com) (leaksear.ch metadata). People who received services from, worked for, or otherwise had information stored by Exact Sciences should check whether their data appears in this leak before responding to unexpected outreach.
Check your exposure
Vetted researchers and incident-response teams can request access or sign in if they already have access to check this dataset. Searchable pivots for this leak include address, country, date of birth, email, name, phone, and username.
Sources
- Abbott Mediaroom: Abbott completes acquisition of Exact Sciences
- Abbott Newsroom: Abbott statement on cyber incident in Cancer Diagnostics business
- BleepingComputer: Abbott probes two cyber incidents amid extortion claims
- HIPAA Journal: Abbott Investigating Cyberattack Claims From Two Threat Actors
- HookPhish: Ransomware Group shinyhunters Hits: Abbott owned Exact Sciences Corporation
- ClassAction.org: Exact Sciences Data Breach? Attorneys Investigate Hackers' Reports