Abbott Laboratories Investigates Two Separate Cyber Incidents

Healthcare companies hold sensitive patient data, and simultaneous incidents at a major diagnostics provider raise questions about system isolation and response protocols.

Abstract illustration representing cybersecurity layers and network vulnerabilities
AI-generated illustration · Sylvaris

Two separate incidents under review

Abbott Laboratories confirmed unauthorized access to internal legacy systems within its Cancer Diagnostics division, specifically affecting Exact Sciences systems. The company is investigating a second, separate claim involving its LabCentral portal.

Attackers allegedly stole company data and have made extortion demands. Abbott has not disclosed the scope of data potentially compromised or whether patient information was accessed.

Legacy systems and modern threats

The incident highlights ongoing security challenges with legacy infrastructure in healthcare organizations. Older systems often lack the security controls built into modern platforms, yet continue operating because they support critical functions.

Abbott acquired Exact Sciences' cancer diagnostics business in recent years. Post-acquisition integration often creates security gaps as companies merge different technology stacks and access controls.

What happens next

Abbott is working with cybersecurity specialists to determine the full extent of both incidents. The company will likely face regulatory scrutiny if patient data was compromised, particularly under healthcare privacy regulations.

The separate nature of the two incidents suggests either coordinated attacks or that multiple threat actors have identified vulnerabilities in Abbott's systems. Either scenario points to broader security architecture concerns.

sources
more in Security
Upbound breach enabled $13 million in fraudulent Acima leases Stolen customer data was directly weaponized to create fraudulent financial contracts, demonstrating how breach data enables immediate financial crime. Fake job interview delivers malware through Git hooks in take-home coding projects Attackers are weaponizing the technical interview process itself, embedding malicious Git hooks in legitimate-looking coding assignments to compromise developer workstations. South Korea National Diplomatic Academy breach exposes global diplomat data after ten-month intrusion A prolonged breach of diplomatic training infrastructure exposed sensitive personnel data of current and former foreign service officers worldwide, demonstrating the targeting of government educational systems.