TECH Signal 381
ShinyHunters called cancer diagnostics biz and tricked staffers into giving them access. Now they've dumped 10.9M email addresses
ShinyHunters extorted Abbott's cancer diagnostics division after a vishing attack gave them access, then dumped stolen data, including 10.9 million email addresses and personal health information, when the company declined to pay.
The breach demonstrates that voice-based social engineering remains an effective entry point into environments with significant data stores, including regulated health information. The public data dump means affected individuals' health details are now circulating in the wild regardless of whatever incident response Abbott mounts. For teams operating healthcare or similarly regulated systems, this underscores that perimeter controls do not compensate for staff who can be persuaded to hand over credentials over the phone.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
ShinyHunters gained initial access through a vishing attack against Abbott's cancer diagnostics staff, not through a technical vulnerability or malware.
The leaked data includes names, dates of birth, Social Security numbers, doctor-patient conversation notes, prescription details, and medical-order records alongside 10.9 million email addresses.
Abbott stated the intrusion affected only a limited number of internal systems and did not disrupt products, manufacturing, laboratory operations, or patient services.
THE CLUSTER